WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 101–150 of 328 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.8 Low Amelia Pro Plugin Information Disclosure Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR 9.0 – < 9.7 Fixed in 9.7 CVE-2026-14211 WPScan
2.2 Low LearnPress Plugin learnpress Server-Side Request Forgery Instructor+ Server-Side Request Forgery via openai_apply_image_feature < 4.4.4 Fixed in 4.4.4 CVE-2026-12971 WPScan
3.7 Low Restore PayPal Standard for WooCommerce Plugin Price Manipulation Payment Bypass via PDT Underpayment No login needed ≤ 3.1.0 CVE-2026-17016 WPScan
3.8 Low Nexter Blocks Plugin the-plus-addons-for-block-editor Content Injection Contributor+ Stored CSS Injection < 5.0.2 Fixed in 5.0.2 CVE-2026-17011 WPScan
2.7 Low Slim SEO Plugin slim-seo Information Disclosure Contributor+ Arbitrary Post Meta Disclosure < 4.9.11 Fixed in 4.9.11 CVE-2026-16957 WPScan
2.7 Low Content Protector (Passster) Plugin Information Disclosure Contributor+ Protected Content Disclosure via Core REST API < 4.3.7 Fixed in 4.3.7 CVE-2025-15674 WPScan
2.7 Low Easy Appointments Plugin easy-appointments Other Contributor+ Shortcode Allowlist Bypass < 3.12.28 Fixed in 3.12.28 CVE-2026-14225 WPScan
3.7 Low DHL for WooCommerce Plugin Information Disclosure Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory No login needed < 4.0.1 Fixed in 4.0.1 CVE-2026-16993 WPScan
3.5 Low GeoDirectory Plugin geodirectory Cross-Site Scripting Editor+ Stored XSS via Place Categories < 2.8.110 Fixed in 2.8.110 CVE-2025-15677 WPScan
2.7 Low MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16746 WPScan
2.7 Low Brizy - Page Builder Plugin Broken Access Control Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR < 2.8.19 Fixed in 2.8.19 CVE-2026-16070 WPScan
3.5 Low Brizy - Page Builder Plugin Cross-Site Scripting Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset < 2.8.19 Fixed in 2.8.19 CVE-2026-16068 WPScan
3.7 Low MonsterInsights Plugin google-analytics-for-wordpress Authentication Bypass Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-11366 WPScan
2.7 Low TaxoPress Plugin Information Disclosure Contributor+ Private Post Disclosure via IDOR < 3.51.0 Fixed in 3.51.0 CVE-2026-15231 WPScan
2.7 Low Classified Listing Plugin classified-listing Information Disclosure Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search < 5.4.4 Fixed in 5.4.4 CVE-2026-16276 WPScan
2.7 Low Classified Listing Plugin classified-listing Information Disclosure Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts < 5.4.4 Fixed in 5.4.4 CVE-2026-16274 WPScan
2.7 Low Simple Restrict Plugin simple-restrict Information Disclosure Contributor+ Restricted Content Disclosure via REST API < 1.2.9 Fixed in 1.2.9 CVE-2026-15939 WPScan
2.2 Low Event Tickets Plugin Broken Access Control Contributor+ Seating Layout and Ticket Inventory Modification via IDOR < 5.29.0.1 Fixed in 5.29.0.1 CVE-2026-14823 WPScan
2.7 Low Amelia Plugin Authentication Bypass Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment < 2.4.4 Fixed in 2.4.4 CVE-2026-14214 WPScan
2.7 Low Brizy – Page Builder Plugin brizy Information Disclosure Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info < 2.8.18 Fixed in 2.8.18 CVE-2026-14195 WPScan
3.7 Low Builderall Plugin Broken Access Control Unauthenticated OAuth Access Token Poisoning via Public REST Routes No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-11882 WPScan
3.5 Low Spectra (Ultimate Addons for Gutenberg) Plugin Content Injection Contributor+ Stored CSS Injection via Block Attributes < 2.20.0 Fixed in 2.20.0 CVE-2026-10827 WPScan
3.8 Low Fluent Support Plugin fluent-support Broken Access Control Agent+ Arbitrary Ticket Customer Reassignment via IDOR < 2.3.1 Fixed in 2.3.1 CVE-2026-14197 WPScan
3.7 Low Support Genix Lite Plugin Broken Access Control Unauthenticated Ticket Attachment Download via Missing Authorization No login needed < 1.4.48 Fixed in 1.4.48 CVE-2026-14862 WPScan
3.5 Low ElementsKit Lite Plugin Cross-Site Scripting Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13393 WPScan
3.7 Low WP Go Maps Plugin wp-google-maps SQL Injection Unauthenticated SQL Injection via Markers REST filter No login needed < 10.1.04 Fixed in 10.1.04 CVE-2026-15381 WPScan
3.7 Low FluentCart Plugin Information Disclosure Unauthenticated Order PII Disclosure via Print Routes No login needed < 1.5.3 Fixed in 1.5.3 CVE-2026-14927 WPScan
3.7 Low Paid Member Subscriptions Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via Residual Export Files No login needed < 3.0.7 Fixed in 3.0.7 CVE-2026-14849 WPScan
3.7 Low Bit Form Plugin bit-form Broken Access Control Unauthenticated Inactive Form Submission No login needed < 3.1.2 Fixed in 3.1.2 CVE-2026-15054 WPScan
3.8 Low Easy Appointments Plugin easy-appointments Broken Access Control Contributor+ Connection Deletion via Missing Authorization < 3.12.28 Fixed in 3.12.28 CVE-2026-14222 WPScan
3.8 Low Easy Appointments Plugin easy-appointments Information Disclosure Contributor+ Appointment Data Disclosure & Modification via Missing Authorization ≤ 4.0 CVE-2026-14221 WPScan
2.7 Low Easy Appointments Plugin easy-appointments Information Disclosure Contributor+ Customer Data Disclosure < 3.12.28 Fixed in 3.12.28 CVE-2026-14188 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Template Deletion < 11.1.5 Fixed in 11.1.5 CVE-2026-14821 WPScan
3.5 Low Event Tickets Plugin Cross-Site Scripting Editor+ Stored XSS via Ticket Move < 5.28.4 Fixed in 5.28.4 CVE-2026-14819 WPScan
3.8 Low WPBot AI ChatBot Plugin SQL Injection Admin+ Second-Order SQL Injection via qc_bot_str_fields < 8.5.2 Fixed in 8.5.2 CVE-2026-14189 WPScan
3.8 Low ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Premium License Tampering via Missing Authorization < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12690 WPScan
2.7 Low All in One SEO Plugin all-in-one-seo-pack Broken Access Control Contributor+ Incorrect Authorization via AI Integration < 4.9.9 Fixed in 4.9.9 CVE-2026-10755 WPScan
2.7 Low RTMKit Addons for Elementor Plugin Broken Access Control Author+ Site-Wide Theme Builder Template Creation and Activation < 2.0.9 Fixed in 2.0.9 CVE-2026-12907 WPScan
2.7 Low RTMKit Addons for Elementor Plugin Information Disclosure Contributor+ Private Post Title Disclosure < 2.0.9 Fixed in 2.0.9 CVE-2026-12906 WPScan
2.7 Low User Profile Picture Plugin metronet-profile-picture Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.6.3 Fixed in 2.6.4 CVE-2026-61971 Patchstack
2.7 Low Adminify Plugin adminify Information Disclosure Contributor+ Sensitive Information Disclosure via Global Search AJAX < 4.2.10 Fixed in 4.2.10 CVE-2026-11781 WPScan
2.7 Low Fluent Forms Plugin fluentform Broken Access Control Form Manager+ Cross-Form Submission Entry Deletion via IDOR < 6.2.5 Fixed in 6.2.5 CVE-2026-11578 WPScan
3.1 Low Fluent Forms Plugin fluentform Broken Access Control Subscriber+ Subscription Cancellation via IDOR < 6.2.1 Fixed in 6.2.1 CVE-2026-11880 WPScan
2.7 Low Site Kit by Google Plugin google-site-kit Broken Access Control Editor+ Email Reporting Settings Update < 1.176.0 Fixed in 1.176.0 CVE-2026-10753 WPScan
2.7 Low UsersWP Plugin userswp Broken Access Control Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter ≤ 1.2.63 CVE-2026-12102 Wordfence
3.4 Low Agile Store Locator Plugin agile-store-locator Path Traversal Admin+ Arbitrary File Read via Path Traversal < 1.6.9 Fixed in 1.6.9 CVE-2026-9062 WPScan
3.5 Low Agile Store Locator Plugin agile-store-locator Cross-Site Scripting Admin+ Stored XSS via logo_name < 1.6.9 Fixed in 1.6.9 CVE-2026-9061 WPScan
3.5 Low Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter < 5.1.5 Fixed in 5.1.5 CVE-2026-9269 WPScan
3.5 Low Agile Store Locator Plugin agile-store-locator Cross-Site Scripting Admin+ Stored XSS via map_style < 1.6.6 Fixed in 1.6.6 CVE-2026-9060 WPScan
3.5 Low Lazy Blocks Plugin Cross-Site Scripting Admin+ Stored XSS via Custom Block Frontend HTML < 4.3.0 Fixed in 4.3.0 CVE-2026-8981 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only