WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical Newspapers X Theme newspapers-x Other Backdoor No login needed 1.0.46 – 1.0.48 Fixed in 1.0.49 CVE-2026-81779 Patchstack
9.8 Critical Tickera Plugin tickera-event-ticketing-system PHP Object Injection No login needed ≤ 3.6.0.2 Fixed in 3.6.0.3 CVE-2026-82226 Patchstack
10.0 Critical Hash Form Plugin hash-form Arbitrary File Upload No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-81780 Patchstack
9.3 Critical Throws SPAM Away Plugin throws-spam-away SQL Injection No login needed ≤ 3.8.2 Fixed in 3.9 CVE-2026-81763 Patchstack
9.3 Critical Smart Marketing SMS and Newsletters Forms Plugin smart-marketing-for-wp SQL Injection No login needed ≤ 5.1.24 Fixed in 5.1.25 CVE-2026-81756 Patchstack
9.3 Critical WP Data Access Plugin wp-data-access SQL Injection No login needed ≤ 5.5.81 Fixed in 5.5.82 CVE-2026-81293 Patchstack
10.0 Critical WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Arbitrary File Upload No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2026-82970 Patchstack
9.8 Critical MyHome Core Plugin Authentication Bypass Authentication Bypass to Account Takeover via Activation Token No login needed ≤ 4.4.5 CVE-2026-15980 Wordfence
9.8 Critical Custom User Registration Fields for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout No login needed ≤ 2.2.3 CVE-2026-15369 Wordfence
9.8 Critical Sigma Forms Pro Plugin Arbitrary File Upload Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field No login needed ≤ 1.4.5 CVE-2026-14494 Wordfence
9.3 Critical Icollect Plugin Path Traversal Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password No login needed ≤ 1.0.0 CVE-2026-77012 WPScan
9.1 Critical Total Processing Card Payments for WooCommerce Plugin Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed ≤ 7.3 CVE-2026-16947 WPScan
9.8 Critical Uix UserCenter Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2026-16259 WPScan
9.8 Critical Simple User Registration Plugin Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed ≤ 6.9 CVE-2026-10522 WPScan
10.0 Critical GiveWP Plugin give Remote Code Execution No login needed ≤ 4.16.7.1 Fixed in 4.16.7.2 CVE-2026-82222 Patchstack
9.8 Critical WPMU DEV Dashboard Plugin Authentication Bypass Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion No login needed ≤ 5.0.1 CVE-2026-76581 Wordfence
9.8 Critical Tutor LMS Plugin tutor Content Injection Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing No login needed 2.1.3 – < 4.0.6 Fixed in 4.0.6 CVE-2026-19092 WPScan
9.8 Critical Hash Form Plugin hash-form PHP Object Injection No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-78292 Patchstack
9.3 Critical Beautiful Taxonomy Filters Plugin beautiful-taxonomy-filters SQL Injection No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2026-78288 Patchstack
9.8 Critical Geo Controller Plugin cf-geoplugin PHP Object Injection No login needed ≤ 8.9.8 Fixed in 8.9.9 CVE-2026-78286 Patchstack
9.1 Critical Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Upload ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78274 Patchstack
9.3 Critical Epayco Plugin epayco-gateway SQL Injection No login needed ≤ 8.4.6 Fixed in 8.4.7 CVE-2026-78260 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type Privilege Escalation Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation No login needed ≤ 2.0.63 CVE-2026-32566 Patchstack
9.3 Critical Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro SQL Injection No login needed ≤ 11.17 Fixed in 11.18 CVE-2026-32479 Patchstack
9.6 Critical Workeera Remote Tech Job Board Plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment < 1.0.6 Fixed in 1.0.6 CVE-2026-77016 WPScan
9.8 Critical ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce Plugin erp Arbitrary File Upload Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment No login needed ≤ 1.17.8 CVE-2026-18080 Wordfence
9.8 Critical Avada Theme Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary File Write No login needed ≤ 3.16, ≤ 7.16 CVE-2026-18431 Wordfence
9.8 Critical TranslatePress – Multilingual Plugin translatepress-multilingual Privilege Escalation Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure No login needed ≤ 3.3.1 CVE-2026-19632 Wordfence
9.8 Critical TranslatePress Plugin translatepress-multilingual Privilege Escalation No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-78267 Patchstack
9.8 Critical The Events Calendar Plugin the-events-calendar PHP Object Injection No login needed ≤ 6.17.2 Fixed in 6.17.3 CVE-2026-78265 Patchstack
9.8 Critical WP Project Manager Plugin wedevs-project-manager PHP Object Injection No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-78262 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type PHP Object Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection No login needed ≤ 2.0.63 CVE-2026-32563 Patchstack
9.9 Critical UltimateAI Plugin ultimate_ai Arbitrary File Upload ≤ 3.1.0 CVE-2026-32559 Patchstack
9.3 Critical Boost Plugin boost SQL Injection No login needed ≤ 2.0.4 CVE-2026-32555 Patchstack
9.3 Critical WooBeWoo Product Filter Pro Plugin woofilter-pro SQL Injection No login needed ≤ 3.1.8 CVE-2026-32554 Patchstack
9.8 Critical FreightCo Theme freightco PHP Object Injection No login needed ≤ 1.1.15 CVE-2026-66650 Patchstack
9.8 Critical Jawn Theme jawn Privilege Escalation No login needed ≤ 1.4.2 CVE-2026-66648 Patchstack
9.8 Critical WP Cafe Pro Plugin wpcafe-pro Local File Inclusion No login needed < 3.0.15 Fixed in 3.0.15 CVE-2026-66587 Patchstack
9.8 Critical Affiliate Pro - Affiliate Program for WooCommerce & Plugin wp-wc-affiliate-program Privilege Escalation Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation No login needed ≤ 8.9.1 CVE-2026-32558 Patchstack
9.3 Critical Woo Essential Plugin woo-essential SQL Injection No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-32551 Patchstack
9.8 Critical Digits Plugin digits Privilege Escalation No login needed ≤ 9.2 CVE-2026-28165 Patchstack
9.8 Critical RestrictMate Plugin restrictmate Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed < 1.3.0 Fixed in 1.3.0 CVE-2026-13598 WPScan
9.8 Critical WS Form LITE Plugin ws-form PHP Object Injection Unauthenticated PHP Object Injection via Form Submission No login needed ≤ 1.10.80 CVE-2026-4703 Wordfence
9.8 Critical Mailgun Plugin mailgun Server-Side Request Forgery Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys No login needed ≤ 2.2.0 CVE-2026-78003 Wordfence
9.8 Critical SmilePass Selfie Login Plugin Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 1.0.2 CVE-2026-77002 WPScan
9.8 Critical Social Login & Sharing buttons with Analytics By SoClever Plugin Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 1.2.0 CVE-2026-77001 WPScan
9.8 Critical WP Social Media Login Plugin Privilege Escalation Unauthenticated Account Takeover via Twitter Login Flow No login needed ≤ 1.0.6 CVE-2026-77000 WPScan
9.8 Critical Automation Web Platform Plugin automation-web-platform Authentication Bypass Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure No login needed ≤ 4.8.6 CVE-2026-77264 Wordfence
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
9.9 Critical Warehouse Cargo Theme warehouse-cargo Arbitrary File Upload ≤ 2.6.9 CVE-2026-74018 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only