WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,451–1,500 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder Plugin popup-maker Broken Access Control Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation ≤ 1.22.0 CVE-2026-8848 Wordfence
7.2 High Connect Contact Form 7 and Mailchimp Plugin contact-form-7-mailchimp-extension Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values No login needed ≤ 0.9.78.06 CVE-2026-15000 Wordfence
7.5 High Everest Forms Plugin everest-forms Information Disclosure Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts No login needed < 3.5.0 Fixed in 3.5.0 CVE-2026-11571 WPScan
8.8 High Divi Form Builder Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form ≤ 5.1.8 CVE-2026-5523 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field No login needed ≤ 1.8.8 CVE-2026-6820 Wordfence
7.5 High LatePoint - Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass No login needed ≤ 5.4.0 CVE-2026-5356 Wordfence
8.1 High WCFM - WooCommerce Multivendor Membership Plugin wc-multivendor-membership Broken Access Control WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite ≤ 2.11.10 CVE-2026-3688 Wordfence
7.5 High My Calendar Plugin my-calendar SQL Injection Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters No login needed ≤ 3.7.8 CVE-2026-6854 Wordfence
7.5 High Tainacan Plugin tainacan SQL Injection Unauthenticated SQL Injection via 'geoquery' REST API Parameter No login needed ≤ 1.0.3 CVE-2026-6230 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter No login needed ≤ 1.8.8 CVE-2026-6818 Wordfence
8.1 High BookingPress Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.1.28 CVE-2026-12378 WPScan
8.8 High WHMCS Bridge Plugin whmcs-bridge Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'ccce' Parameter ≤ 6.9 CVE-2026-14489 Wordfence
7.5 High Eventer Plugin SQL Injection Unauthenticated SQL Injection via 'code' Parameter No login needed ≤ 4.4.2 CVE-2026-9700 Wordfence
8.8 High DoLogin Security Plugin dologin Authentication Bypass Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token ≤ 4.3 CVE-2026-14495 Wordfence
8.8 High 多说社会化评论框 Plugin duoshuo Privilege Escalation Unauthenticated Privilege Escalation via api.php 'option'/'value' Parameters ≤ 1.2 CVE-2026-14482 Wordfence
7.5 High Jssor Slider by jssor.com Plugin jssor-slider Path Traversal Unauthenticated Arbitrary File Read via 'url' Parameter No login needed ≤ 3.1.24 CVE-2026-14244 Wordfence
8.8 High Widget Logic Visual Plugin widget-logic-visual Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter ≤ 1.52 CVE-2026-14158 Wordfence
7.5 High Backstage Plugin backstage Privilege Escalation Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities No login needed ≤ 1.4.2 CVE-2026-9842 Wordfence
7.5 High AMP for WP Plugin accelerated-mobile-pages Remote Code Execution Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload ≤ 1.1.12 CVE-2026-6101 Wordfence
8.7 High Frontend File Manager Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal No login needed ≤ 23.6 CVE-2026-12277 WPScan
8.1 High Admin and Site Enhancements Plugin Privilege Escalation Unauthenticated Administrator-Role Restoration via reset-for Parameter No login needed 7.6.3 – < 8.8.4 Fixed in 8.8.4 CVE-2026-12083 WPScan
8.8 High FileOrganizer Plugin fileorganizer Arbitrary File Upload Authenticated Arbitrary File Upload via elFinder File Operations < 1.2.0 Fixed in 1.2.0 CVE-2026-11962 WPScan
8.8 High Simple Membership Plugin simple-membership Cross-Site Scripting Unauthenticated Stored XSS via Stripe Webhook API Version No login needed < 4.7.5 Fixed in 4.7.5 CVE-2026-11855 WPScan
8.0 High Ultimate Member Plugin ultimate-member Cross-Site Scripting Subscriber+ Stored XSS via Custom Textarea Profile Fields < 2.12.0 Fixed in 2.12.0 CVE-2026-11766 WPScan
8.8 High AllCoach Plugin allcoach Privilege Escalation Unauthenticated Account Takeover < 1.0.2 Fixed in 1.0.2 CVE-2026-10830 WPScan
7.5 High WANotifier Plugin notifier Local File Inclusion Subscriber+ LFI < 2.6 Fixed in 2.6 CVE-2024-6228 WPScan
7.2 High Comments Plugin wpdiscuz Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'Website' Field No login needed ≤ 7.6.56 CVE-2026-9148 Wordfence
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter No login needed ≤ 9.2.2 CVE-2026-13040 Wordfence
7.5 High AR for WooCommerce Plugin ar-for-woocommerce Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter No login needed ≤ 8.40 CVE-2026-14352 Wordfence
7.5 High AR Plugin ar-for-wordpress Path Traversal Unauthenticated Arbitrary File Read via 'file' Parameter No login needed ≤ 8.40 CVE-2026-14327 Wordfence
8.1 High TinyPNG Plugin tiny-compress-images Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta ≤ 3.6.13 CVE-2026-7311 Wordfence
7.1 High Slider Revolution Plugin revslider Cross-Site Scripting No login needed 7.0.0 – 7.0.16 Fixed in 7.1.0 CVE-2026-57678 Patchstack
8.8 High Themify Popup Plugin themify-popup PHP Object Injection ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-56037 Patchstack
8.8 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Request Forgery File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.6 CVE-2026-57766 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.9.0 CVE-2026-57765 Patchstack
7.1 High SEOWP Theme seowp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.12.2 CVE-2026-57761 Patchstack
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-57759 Patchstack
7.1 High Permalink Manager for WooCommerce Plugin permalink-manager-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.8.2 CVE-2026-57758 Patchstack
7.1 High pCloud WP Backup Plugin pcloud-wp-backup Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2026-57757 Patchstack
8.5 High nicen-localize-image Plugin nicen-localize-image SQL Injection ≤ 1.4.9 CVE-2026-57756 Patchstack
8.5 High iNET Webkit Plugin inet-webkit SQL Injection 1.2.4 CVE-2026-57752 Patchstack
8.1 High Heateor Social Login Plugin heateor-social-login Cross-Site Request Forgery No login needed ≤ 1.1.39 CVE-2026-57751 Patchstack
7.5 High SportsPress Pro Plugin sportspress-pro Local File Inclusion ≤ 2.7.29 CVE-2026-57749 Patchstack
7.5 High Shopify Plugin shopify-plugin Local File Inclusion ≤ 1.0.0 CVE-2026-57748 Patchstack
7.1 High Booked Plugin booked Broken Access Control ≤ 3.0.0 CVE-2026-57746 Patchstack
8.2 High POS Entegratör Plugin pos-entegrator Broken Access Control No login needed ≤ 3.7.103 Fixed in 3.8.0 CVE-2026-57688 Patchstack
8.5 High Custom Field Template Plugin custom-field-template SQL Injection ≤ 2.7.8 Fixed in 2.8 CVE-2026-57687 Patchstack
7.1 High WowAddons Plugin product-addons Cross-Site Scripting No login needed ≤ 1.6.14 Fixed in 1.6.15 CVE-2026-57686 Patchstack
7.1 High Simple Link Directory Plugin qc-simple-link-directory Cross-Site Scripting No login needed ≤ 15.0.5 Fixed in 15.0.6 CVE-2026-57682 Patchstack
7.1 High WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting No login needed ≤ 9.2.02.004 Fixed in 9.2.03.001 CVE-2026-57675 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only