WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,501–1,550 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Hustle Plugin wordpress-popup Information Disclosure Sensitive Data Exposure No login needed ≤ 7.8.9.2 Fixed in 7.8.9.3 CVE-2026-24998 Patchstack
5.3 Medium Wired Impact Volunteer Management Plugin wired-impact-volunteer-management Broken Access Control No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2026-24997 Patchstack
4.3 Medium WPElemento Importer Plugin wpelemento-importer Broken Access Control ≤ 0.6.4 Fixed in 0.6.5 CVE-2026-24996 Patchstack
4.3 Medium Latest Post Shortcode Plugin latest-post-shortcode Broken Access Control ≤ 14.2.0 Fixed in 14.2.1 CVE-2026-24995 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.5.7.2 Fixed in 3.5.7.3 CVE-2026-24994 Patchstack
5.3 Medium Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2026-24992 Patchstack
5.3 Medium Extensions For CF7 Plugin extensions-for-cf7 Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-24991 Patchstack
5.4 Medium WP Docs Plugin wp-docs Broken Access Control ≤ 2.2.8 Fixed in 2.2.9 CVE-2026-24990 Patchstack
6.5 Medium The Events Calendar Shortcode & Block Plugin the-events-calendar-shortcode Cross-Site Scripting ≤ 3.1.1 Fixed in 3.1.2 CVE-2026-24988 Patchstack
5.4 Medium Simple Membership WP user Import Plugin simple-membership-wp-user-import Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-24986 Patchstack
4.3 Medium WP Forms Signature Contract Add-On Plugin wp-forms-signature-contract-add-on Broken Access Control Broken Access Control to Notice Dismissal ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-24985 Patchstack
6.5 Medium Visual Link Preview Plugin visual-link-preview Broken Access Control ≤ 2.2.9 Fixed in 2.3.0 CVE-2026-24984 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control No login needed ≤ 2.19.17 Fixed in 2.19.18 CVE-2026-24982 Patchstack
5.3 Medium Amelia Plugin ameliabooking Broken Access Control No login needed ≤ 1.2.38 Fixed in 2.0 CVE-2026-24967 Patchstack
4.3 Medium Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-24966 Patchstack
4.3 Medium Contest Gallery Plugin contest-gallery Broken Access Control ≤ 28.1.1 Fixed in 28.1.2 CVE-2026-24965 Patchstack
4.3 Medium Sigmize Plugin sigmize Cross-Site Request Forgery No login needed ≤ 0.0.9 Fixed in 0.0.10 CVE-2026-24962 Patchstack
5.4 Medium Grand Blog Theme grandblog Server-Side Request Forgery No login needed ≤ 3.1.5 Fixed in 3.1.5 CVE-2026-24961 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.12.2 Fixed in 2.7.12.3 CVE-2026-24958 Patchstack
6.5 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control ≤ 3.2.20 Fixed in 3.2.21 CVE-2026-24957 Patchstack
6.5 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Scripting ≤ 3.14.1 Fixed in 3.14.2 CVE-2026-24952 Patchstack
4.3 Medium myCred Plugin mycred Broken Access Control ≤ 2.9.7.3 Fixed in 2.9.7.4 CVE-2026-24951 Patchstack
4.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control ≤ 1.5.6.3 Fixed in 1.5.6.3 CVE-2026-24947 Patchstack
5.3 Medium Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Broken Access Control No login needed ≤ 3.5.34 Fixed in 3.5.35 CVE-2026-24945 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-24942 Patchstack
4.3 Medium Travelfic Toolkit Plugin travelfic-toolkit Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-24940 Patchstack
4.3 Medium Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control ≤ 2.13.6 Fixed in 2.13.7 CVE-2026-24939 Patchstack
5.9 Medium Better Search Plugin better-search Cross-Site Scripting ≤ 4.2.1 Fixed in 4.2.2 CVE-2026-24938 Patchstack
6.4 Medium Stripe Green Downloads Plugin Cross-Site Scripting Stripe Green Downloads Wordpress Plugin 2.03 Persistent XSS via Settings 2.03 CVE-2022-50797 VulnCheck
5.3 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 9.1.8 CVE-2025-15510 Wordfence
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.14 CVE-2025-14283 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed ≤ 2.5.2 CVE-2025-13205 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
6.4 Medium LeadBI Plugin leadbi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_id' Shortcode Attribute ≤ 1.7 CVE-2026-1189 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed ≤ 2.5.2 CVE-2025-13139 Wordfence
4.3 Medium Sugar Calendar (Lite) Plugin sugar-calendar-lite Broken Access Control ≤ 3.9.1 Fixed in 3.10.0 CVE-2026-24636 Patchstack
5.3 Medium Ultimate Reviews Plugin ultimate-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.16 Fixed in 3.2.17 CVE-2026-24634 Patchstack
5.3 Medium Add Expires Headers & Optimized Minify Plugin add-expires-headers Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.3.0 CVE-2026-24633 Patchstack
5.9 Medium Delay Redirects Plugin delay-redirects Cross-Site Scripting ≤ 1.0.0 CVE-2026-24632 Patchstack
5.4 Medium Rosebud Theme rosebud Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4 CVE-2026-24631 Patchstack
6.5 Medium Stylish Cost Calculator Plugin stylish-cost-calculator Cross-Site Scripting ≤ 8.2.9 CVE-2026-24630 Patchstack
5.9 Medium Web Accessibility with Max Access Plugin accessibility-toolbar Cross-Site Scripting ≤ 2.1.0 CVE-2026-24629 Patchstack
4.3 Medium Trusona Plugin trusona Broken Access Control ≤ 2.0.0 CVE-2026-24627 Patchstack
5.9 Medium Logo Slider Plugin logo-slider-wp Cross-Site Scripting ≤ 5.1.1 CVE-2026-24626 Patchstack
5.3 Medium File Uploads Addon for WooCommerce Plugin woo-addon-uploads Arbitrary File Upload Broken Access Control No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2026-24625 Patchstack
5.4 Medium Suggestion Toolkit Plugin suggestion-toolkit Broken Access Control ≤ 5.0 CVE-2026-24622 Patchstack
5.9 Medium Terms descriptions Plugin terms-descriptions Cross-Site Scripting ≤ 3.4.9 Fixed in 3.4.10 CVE-2026-24621 Patchstack
5.9 Medium Landing Page Builder Plugin page-builder-add Cross-Site Scripting ≤ 1.5.3.4 Fixed in 1.5.3.5 CVE-2026-24620 Patchstack
5.3 Medium PopCash.Net Code Integration Tool Plugin popcashnet-code-integration-tool Broken Access Control No login needed ≤ 1.8 Fixed in 2.0 CVE-2026-24619 Patchstack
6.5 Medium Easy Modal Plugin easy-modal Cross-Site Scripting ≤ 2.1.0 CVE-2026-24617 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only