WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,501–1,550 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2026-85302 Patchstack
7.1 High Quick Event Manager Plugin quick-event-manager Cross-Site Scripting No login needed ≤ 9.17 CVE-2026-84848 Patchstack
7.5 High Quick Event Manager Plugin quick-event-manager Broken Access Control No login needed ≤ 9.17 CVE-2026-84847 Patchstack
7.1 High WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.22.3 CVE-2026-84836 Patchstack
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 3.2.0 CVE-2026-84834 Patchstack
9.8 Critical Bricksforge Plugin bricksforge Privilege Escalation No login needed ≤ 3.1.8.8 Fixed in 3.1.8.9 CVE-2026-84814 Patchstack
9.3 Critical GeoDirectory Plugin geodirectory SQL Injection No login needed ≤ 2.8.174 Fixed in 2.8.175 CVE-2026-84813 Patchstack
7.1 High BP Better Messages Plugin bp-better-messages Cross-Site Scripting No login needed ≤ 2.15.27 Fixed in 2.15.28 CVE-2026-84812 Patchstack
8.1 High Agentimus – AI SEO, llms.txt & MCP for AI Agents Plugin agentimus Broken Access Control AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Access Control ≤ 1.51.0 Fixed in 1.51.1 CVE-2026-84779 Patchstack
7.5 High Migrate Guru – Site Migration & Cloning Plugin migrate-guru Denial of Service Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack No login needed ≤ 6.65 Fixed in 6.72 CVE-2026-84778 Patchstack
7.4 High Really Simple SSL Plugin really-simple-ssl Authentication Bypass WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84777 Patchstack
7.5 High MalCare Security Plugin malcare-security Denial of Service Denial of Service Attack No login needed ≤ 6.69 Fixed in 6.72 CVE-2026-84776 Patchstack
6.1 Medium WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.11 Fixed in 14.16.12 CVE-2026-84774 Patchstack
7.2 High EWWW Image Optimizer Plugin ewww-image-optimizer Cross-Site Scripting No login needed ≤ 8.7.6 Fixed in 8.7.7 CVE-2026-84773 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84769 Patchstack
9.3 Critical VikAppointments Services Booking Calendar Plugin vikappointments SQL Injection No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2026-84768 Patchstack
5.3 Medium BookIt Plugin bookit Other Bypass Vulnerability No login needed ≤ 2.6.0.3 Fixed in 2.6.0.4 CVE-2026-84767 Patchstack
5.9 Medium FluentBooking Pro Plugin fluent-booking-pro Authentication Bypass Bypass Vulnerability No login needed ≤ 2.2.1 Fixed in 2.3.0 CVE-2026-84766 Patchstack
7.1 High Breadcrumb NavXT Plugin breadcrumb-navxt Cross-Site Scripting No login needed ≤ 7.5.1 Fixed in 7.5.2 CVE-2026-84765 Patchstack
7.1 High RTMKit Plugin rometheme-for-elementor Cross-Site Scripting No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84763 Patchstack
5.3 Medium WP EasyPay Plugin wp-easy-pay Other Bypass Vulnerability No login needed ≤ 4.5.3 Fixed in 4.5.4 CVE-2026-84762 Patchstack
7.2 High LiteSpeed Cache Plugin litespeed-cache Server-Side Request Forgery No login needed ≤ 7.9 Fixed in 7.9.1 CVE-2026-84761 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84758 Patchstack
8.2 High WP Compress Plugin wp-compress-image-optimizer Broken Access Control Settings Change No login needed ≤ 7.21.28 Fixed in 7.22.0 CVE-2026-84757 Patchstack
7.1 High WCFM Membership Plugin wc-multivendor-membership Privilege Escalation ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-84756 Patchstack
6.5 Medium Mail Mint Plugin mail-mint Broken Access Control No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84755 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control No login needed ≤ 3.12.13 Fixed in 3.13.0 CVE-2026-84754 Patchstack
9.8 Critical Mail Mint Plugin mail-mint PHP Object Injection No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84753 Patchstack
8.8 High RTMKit Plugin rometheme-for-elementor PHP Object Injection ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84752 Patchstack
9.8 Critical YITH Request a Quote for WooCommerce Premium Plugin yith-woocommerce-request-a-quote-premium Broken Access Control No login needed < 4.46.0 Fixed in 4.46.0 CVE-2026-84238 Patchstack
6.5 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.61 Fixed in 1.0.62 CVE-2026-84215 Patchstack
7.1 High WP QuickLaTeX Plugin wp-quicklatex Cross-Site Scripting No login needed ≤ 3.8.8 CVE-2026-81776 Patchstack
7.1 High Ninja Forms File Uploads Extension Plugin ninja-forms-uploads Arbitrary File Upload Cross Site Scripting (XSS) No login needed ≤ 3.3.26 CVE-2026-81773 Patchstack
7.1 High Calculation For Contact Form 7 Plugin calculation-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0 Fixed in 1.1 CVE-2026-81300 Patchstack
7.1 High Under Construction Plugin under-construction-page Cross-Site Scripting No login needed ≤ 5.82 Fixed in 5.83 CVE-2026-81295 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-81292 Patchstack
6.5 Medium Product Variations Swatches for WooCommerce Plugin product-variations-swatches-for-woocommerce Cross-Site Scripting ≤ 1.1.18 Fixed in 1.1.19 CVE-2026-81282 Patchstack
6.5 Medium Graphene Theme graphene Cross-Site Scripting ≤ 2.9.4 Fixed in 2.9.6 CVE-2026-81281 Patchstack
6.5 Medium Pre-Orders for WooCommerce Plugin pre-orders-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3 CVE-2026-84849 Patchstack
5.8 Medium Enfold Theme enfold Cross-Site Scripting No login needed ≤ 8.0 Fixed in 8.1 CVE-2026-84815 Patchstack
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter ≤ 4.27.6 CVE-2026-3852 Wordfence
6.4 Medium GutenKit Plugin gutenkit-blocks-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss' ≤ 2.4.4 CVE-2026-2573 Wordfence
6.4 Medium SEOWriting Plugin seowriting Cross-Site Scripting SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload ≤ 1.12.5 CVE-2026-75134 VulnCheck
5.4 Medium Ajaxify Comments Plugin wp-ajaxify-comments Other Unauthenticated HTTP Header Injection No login needed < 3.2 Fixed in 3.2 CVE-2026-2811 WPScan
9.8 Critical Developer Tools Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.1.3 CVE-2025-9314 WPScan
5.3 Medium Passster Plugin content-protector Broken Access Control Global Protection Bypass No login needed < 4.2.26 Fixed in 4.2.26 CVE-2025-15490 WPScan
5.3 Medium Wp Edit Password Protected Plugin Broken Access Control Protection Bypass via REST API No login needed < 1.3.5 Fixed in 1.3.5 CVE-2025-8945 WPScan
5.3 Medium Passster Plugin content-protector Broken Access Control Password Protection Bypass No login needed < 4.2.24 Fixed in 4.2.24 CVE-2025-15489 WPScan
8.2 High Auto x LINE Plugin Broken Access Control Unauthenticated REST API Endpoints Call No login needed ≤ 1.0.0 CVE-2025-15485 WPScan
5.3 Medium Notification Bar Plugin Information Disclosure Unauthenticated Subscriber Data Disclosure No login needed ≤ 1.1.8 CVE-2025-15481 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only