WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 101–150 of 2,150 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 10.0 Critical | Newspapers X | Other Backdoor No login needed |
1.0.46 – 1.0.48 Fixed in 1.0.49 |
CVE-2026-81779 |
Patchstack | |
| 9.8 Critical | Tickera | PHP Object Injection No login needed |
≤ 3.6.0.2 Fixed in 3.6.0.3 |
CVE-2026-82226 |
Patchstack | |
| 10.0 Critical | Hash Form | Arbitrary File Upload No login needed |
≤ 1.4.2 Fixed in 1.4.3 |
CVE-2026-81780 |
Patchstack | |
| 9.3 Critical | Throws SPAM Away | SQL Injection No login needed |
≤ 3.8.2 Fixed in 3.9 |
CVE-2026-81763 |
Patchstack | |
| 9.3 Critical | Smart Marketing SMS and Newsletters Forms | SQL Injection No login needed |
≤ 5.1.24 Fixed in 5.1.25 |
CVE-2026-81756 |
Patchstack | |
| 9.3 Critical | WP Data Access | SQL Injection No login needed |
≤ 5.5.81 Fixed in 5.5.82 |
CVE-2026-81293 |
Patchstack | |
| 10.0 Critical | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent | Arbitrary File Upload No login needed |
≤ 4.4.1 Fixed in 4.4.2 |
CVE-2026-82970 |
Patchstack | |
| 9.8 Critical | MyHome Core | Authentication Bypass Authentication Bypass to Account Takeover via Activation Token No login needed |
≤ 4.4.5 |
CVE-2026-15980 |
Wordfence | |
| 9.8 Critical | Custom User Registration Fields for WooCommerce | Privilege Escalation Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout No login needed |
≤ 2.2.3 |
CVE-2026-15369 |
Wordfence | |
| 9.8 Critical | Sigma Forms Pro | Arbitrary File Upload Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field No login needed |
≤ 1.4.5 |
CVE-2026-14494 |
Wordfence | |
| 9.3 Critical | Icollect | Path Traversal Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password No login needed |
≤ 1.0.0 |
CVE-2026-77012 |
WPScan | |
| 9.1 Critical | Total Processing Card Payments for WooCommerce | Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed |
≤ 7.3 |
CVE-2026-16947 |
WPScan | |
| 9.8 Critical | Uix UserCenter | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.0.3 |
CVE-2026-16259 |
WPScan | |
| 9.8 Critical | Simple User Registration | Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed |
≤ 6.9 |
CVE-2026-10522 |
WPScan | |
| 10.0 Critical | GiveWP | Remote Code Execution No login needed |
≤ 4.16.7.1 Fixed in 4.16.7.2 |
CVE-2026-82222 |
Patchstack | |
| 9.8 Critical | WPMU DEV Dashboard | Authentication Bypass Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion No login needed |
≤ 5.0.1 |
CVE-2026-76581 |
Wordfence | |
| 9.8 Critical | Tutor LMS | Content Injection Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing No login needed |
2.1.3 – < 4.0.6 Fixed in 4.0.6 |
CVE-2026-19092 |
WPScan | |
| 9.8 Critical | Hash Form | PHP Object Injection No login needed |
≤ 1.4.1 Fixed in 1.4.2 |
CVE-2026-78292 |
Patchstack | |
| 9.3 Critical | Beautiful Taxonomy Filters | SQL Injection No login needed |
≤ 2.4.6 Fixed in 2.4.7 |
CVE-2026-78288 |
Patchstack | |
| 9.8 Critical | Geo Controller | PHP Object Injection No login needed |
≤ 8.9.8 Fixed in 8.9.9 |
CVE-2026-78286 |
Patchstack | |
| 9.1 Critical | Fluent Boards Pro | Arbitrary File Upload |
≤ 2.0.11 Fixed in 2.0.12 |
CVE-2026-78274 |
Patchstack | |
| 9.3 Critical | Epayco | SQL Injection No login needed |
≤ 8.4.6 Fixed in 8.4.7 |
CVE-2026-78260 |
Patchstack | |
| 9.8 Critical | ACPT (Pro) - Custom Post Types | Privilege Escalation Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation No login needed |
≤ 2.0.63 |
CVE-2026-32566 |
Patchstack | |
| 9.3 Critical | Visitor Traffic Real Time Statistics Pro | SQL Injection No login needed |
≤ 11.17 Fixed in 11.18 |
CVE-2026-32479 |
Patchstack | |
| 9.6 Critical | Workeera Remote Tech Job Board | Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment |
< 1.0.6 Fixed in 1.0.6 |
CVE-2026-77016 |
WPScan | |
| 9.8 Critical | ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce | Arbitrary File Upload Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment No login needed |
≤ 1.17.8 |
CVE-2026-18080 |
Wordfence | |
| 9.8 Critical | Avada | Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary File Write No login needed |
≤ 3.16, ≤ 7.16 |
CVE-2026-18431 |
Wordfence | |
| 9.8 Critical | TranslatePress – Multilingual | Privilege Escalation Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure No login needed |
≤ 3.3.1 |
CVE-2026-19632 |
Wordfence | |
| 9.8 Critical | TranslatePress | Privilege Escalation No login needed |
≤ 3.3.2 Fixed in 3.3.3 |
CVE-2026-78267 |
Patchstack | |
| 9.8 Critical | The Events Calendar | PHP Object Injection No login needed |
≤ 6.17.2 Fixed in 6.17.3 |
CVE-2026-78265 |
Patchstack | |
| 9.8 Critical | WP Project Manager | PHP Object Injection No login needed |
≤ 4.0.6 Fixed in 4.0.7 |
CVE-2026-78262 |
Patchstack | |
| 9.8 Critical | ACPT (Pro) - Custom Post Types | PHP Object Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection No login needed |
≤ 2.0.63 |
CVE-2026-32563 |
Patchstack | |
| 9.9 Critical | UltimateAI | Arbitrary File Upload |
≤ 3.1.0 |
CVE-2026-32559 |
Patchstack | |
| 9.3 Critical | Boost | SQL Injection No login needed |
≤ 2.0.4 |
CVE-2026-32555 |
Patchstack | |
| 9.3 Critical | WooBeWoo Product Filter Pro | SQL Injection No login needed |
≤ 3.1.8 |
CVE-2026-32554 |
Patchstack | |
| 9.8 Critical | FreightCo | PHP Object Injection No login needed |
≤ 1.1.15 |
CVE-2026-66650 |
Patchstack | |
| 9.8 Critical | Jawn | Privilege Escalation No login needed |
≤ 1.4.2 |
CVE-2026-66648 |
Patchstack | |
| 9.8 Critical | WP Cafe Pro | Local File Inclusion No login needed |
< 3.0.15 Fixed in 3.0.15 |
CVE-2026-66587 |
Patchstack | |
| 9.8 Critical | Affiliate Pro - Affiliate Program for WooCommerce & | Privilege Escalation Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation No login needed |
≤ 8.9.1 |
CVE-2026-32558 |
Patchstack | |
| 9.3 Critical | Woo Essential | SQL Injection No login needed |
≤ 4.3.0 Fixed in 4.3.1 |
CVE-2026-32551 |
Patchstack | |
| 9.8 Critical | Digits | Privilege Escalation No login needed |
≤ 9.2 |
CVE-2026-28165 |
Patchstack | |
| 9.8 Critical | RestrictMate | Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed |
< 1.3.0 Fixed in 1.3.0 |
CVE-2026-13598 |
WPScan | |
| 9.8 Critical | WS Form LITE | PHP Object Injection Unauthenticated PHP Object Injection via Form Submission No login needed |
≤ 1.10.80 |
CVE-2026-4703 |
Wordfence | |
| 9.8 Critical | Mailgun | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys No login needed |
≤ 2.2.0 |
CVE-2026-78003 |
Wordfence | |
| 9.8 Critical | SmilePass Selfie Login | Authentication Bypass Unauthenticated Authentication Bypass No login needed |
≤ 1.0.2 |
CVE-2026-77002 |
WPScan | |
| 9.8 Critical | Social Login & Sharing buttons with Analytics By SoClever | Authentication Bypass Unauthenticated Authentication Bypass No login needed |
≤ 1.2.0 |
CVE-2026-77001 |
WPScan | |
| 9.8 Critical | WP Social Media Login | Privilege Escalation Unauthenticated Account Takeover via Twitter Login Flow No login needed |
≤ 1.0.6 |
CVE-2026-77000 |
WPScan | |
| 9.8 Critical | Automation Web Platform | Authentication Bypass Unauthenticated Authentication Bypass via 'otp_transient' Token Disclosure No login needed |
≤ 4.8.6 |
CVE-2026-77264 |
Wordfence | |
| 9.6 Critical | Easy Elementor Addons | Cross-Site Request Forgery No login needed |
≤ 2.3.7 Fixed in 2.3.8 |
CVE-2026-28164 |
Patchstack | |
| 9.9 Critical | Warehouse Cargo | Arbitrary File Upload |
≤ 2.6.9 |
CVE-2026-74018 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.