WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,501–1,550 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium Icegram Mailer Plugin icegram-mailer SQL Injection Authenticated (Administrator+) SQL Injection via 'fields' Parameter ≤ 1.0.12 CVE-2026-15951 Wordfence
4.9 Medium GSheetConnector Plugin cf7-google-sheets-connector SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 5.2.1 CVE-2026-16614 Wordfence
5.3 Medium Database Collation Fix Plugin database-collation-fix SQL Injection Unauthenticated SQL Injection via 'force-collation-algorithm' Parameter ≤ 1.2.10 CVE-2026-15018 Wordfence
5.3 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action() No login needed ≤ 1.9.0 CVE-2026-11995 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute ≤ 3.3.66 CVE-2026-16685 Wordfence
6.4 Medium GamiPress Plugin gamipress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via gamipress_achievement Shortcode ≤ 7.9.9.1 CVE-2026-16090 Wordfence
6.4 Medium Kadence Blocks Plugin kadence-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute ≤ 3.7.8 CVE-2026-18435 Wordfence
6.4 Medium Kadence Blocks Plugin kadence-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content ≤ 3.7.8.1 CVE-2026-18062 Wordfence
6.4 Medium Powerkit Plugin powerkit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'nav' Shortcode Attribute ≤ 3.1.0 CVE-2026-15645 Wordfence
6.4 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_color' Parameter ≤ 2.48 CVE-2026-15662 Wordfence
4.9 Medium Kirki Plugin kirki Path Traversal Authenticated (Editor+) Path Traversal to Arbitrary File Write (Zip Slip) ≤ 6.0.13 CVE-2026-15601 Wordfence
6.5 Medium Icegram Engage Plugin icegram SQL Injection Authenticated (Contributor+) Second-Order SQL Injection via 'messages[][id]' Parameter ≤ 3.1.42 CVE-2026-16087 Wordfence
6.4 Medium GenerateBlocks Plugin generateblocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes ≤ 2.3.0 CVE-2026-13458 Wordfence
4.3 Medium RealHomes Memberships Plugin inspiry-memberships Broken Access Control Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass via 'ims_add_paypal_recurring_membership' AJAX Action ≤ 3.0.9 CVE-2026-10782 Wordfence
6.4 Medium Easy Property Listings Plugin easy-property-listings Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'facebook' User Contact Method ≤ 3.5.24 CVE-2026-16684 Wordfence
4.3 Medium Jeg Kit for Elementor Plugin jeg-elementor-kit Information Disclosure Authenticated (Contributor+) Exposure of Sensitive Information via 'JkitDashboardOption' Inline Script ≤ 3.1.1 CVE-2026-2916 Wordfence
4.3 Medium Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross-Site Request Forgery to CSS Modification No login needed ≤ 3.1 CVE-2025-14469 Wordfence
5.3 Medium YOP Poll Plugin yop-poll Authentication Bypass Unauthenticated Vote Restriction Bypass via IP Header Spoofing No login needed 7.0.0 – < 7.0.6 Fixed in 7.0.6 CVE-2026-14840 WPScan
5.3 Medium Event Tickets Plugin Broken Access Control Unauthenticated PayPal Order Status Manipulation No login needed < 5.29.0.1 Fixed in 5.29.0.1 CVE-2026-14822 WPScan
6.5 Medium Authora - Easy Login with Mobile Number Plugin Privilege Escalation Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure No login needed < 1.7.7 Fixed in 1.7.7 CVE-2026-14561 WPScan
6.5 Medium Pixel Tag Manager for WooCommerce Plugin pixel-manager-for-woocommerce Broken Access Control Unauthenticated Forged Conversion Event Submission No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-14315 WPScan
5.4 Medium WordPress Download Manager Plugin Cross-Site Scripting Author+ Stored XSS via Package Title < 3.3.66 Fixed in 3.3.66 CVE-2026-14292 WPScan
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Podcast Contributor/Group/Role Creation and Deletion via CSRF No login needed < 4.5.3 Fixed in 4.5.3 CVE-2026-13729 WPScan
5.3 Medium Pixelavo Plugin pixelavo Server-Side Request Forgery Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX No login needed < 1.5.4 Fixed in 1.5.4 CVE-2026-13604 WPScan
6.5 Medium WC Buckaroo BPE Gateway Plugin Broken Access Control Subscriber+ Unauthorized Order Refund < 4.9.0 Fixed in 4.9.0 CVE-2026-13329 WPScan
5.4 Medium wpForo Forum Plugin wpforo Cross-Site Scripting Subscriber+ Stored XSS via Profile Location Field < 3.1.2 Fixed in 3.1.2 CVE-2026-12696 WPScan
5.4 Medium Admin Columns for ACF Fields Plugin admin-columns-for-acf-fields Cross-Site Scripting Contributor+ Stored XSS via ACF Field Value Column ≤ 0.3.2 CVE-2026-15262 WPScan
5.4 Medium Codeless Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode Attribute ≤ 1.1.4 CVE-2026-15234 WPScan
5.3 Medium Direct Payments for WooCommerce Plugin direct-payments-for-woocommerce Broken Access Control Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions No login needed < 2.5.3 Fixed in 2.5.3 CVE-2026-12966 WPScan
4.8 Medium Bit Form Plugin bit-form Cross-Site Scripting Admin+ Stored XSS via Conversational Form Progress Label < 3.1.4 Fixed in 3.1.4 CVE-2025-15669 WPScan
5.3 Medium Support Genix Lite Plugin Path Traversal Unauthenticated Arbitrary File Read via Path Traversal No login needed < 1.4.48 Fixed in 1.4.48 CVE-2026-15932 WPScan
4.9 Medium Pinpoint Booking System Plugin booking-system SQL Injection Authenticated (Administrator+) SQL Injection via 'field' Parameter ≤ 2.9.9.6.9 CVE-2026-15403 Wordfence
6.4 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _sp_form_code Post Meta ≤ 2.2.5 CVE-2026-13362 Wordfence
6.4 Medium SureForms Plugin sureforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute ≤ 2.8.1 CVE-2026-7623 Wordfence
4.3 Medium WP Maps Plugin wp-google-map-plugin Information Disclosure Sensitive Data Exposure ≤ 4.9.6 Fixed in 4.9.7 CVE-2026-28144 Patchstack
5.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control No login needed ≤ 3.7.39 Fixed in 3.7.40 CVE-2026-28145 Patchstack
5.3 Medium Fluent Forms Plugin fluentform Information Disclosure Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter No login needed ≤ 6.2.8 CVE-2026-17567 Wordfence
5.3 Medium MailPress Plugin mailerpress Broken Access Control Missing Authorization to Unauthenticated Contact Updates No login needed ≤ 1.5.0 CVE-2026-18437 Wordfence
5.3 Medium MailerPress Plugin mailerpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint No login needed ≤ 1.5.0 CVE-2026-18436 Wordfence
5.4 Medium wpForo Forum Plugin wpforo Broken Access Control Subscriber+ Cross-User AI Chat Message Deletion via IDOR < 3.1.2 Fixed in 3.1.2 CVE-2026-12697 WPScan
4.3 Medium Academy LMS Plugin academy Information Disclosure Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint ≤ 3.8.2 CVE-2026-12376 WPScan
5.4 Medium BuddyPress Plugin buddypress Information Disclosure Subscriber+ Private Messages Disclosure via IDOR < 14.5.0 Fixed in 14.5.0 CVE-2026-8155 WPScan
6.5 Medium JS Help Desk – AI-Powered Support & Ticketing System Plugin js-support-ticket Information Disclosure AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR < 3.1.5 Fixed in 3.1.5 CVE-2026-15209 WPScan
6.5 Medium JS Help Desk Plugin js-support-ticket Information Disclosure Contributor+ User Email Disclosure < 3.1.4 Fixed in 3.1.4 CVE-2026-14931 WPScan
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Subscriber+ Ticket Reply Modification via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-14929 WPScan
6.5 Medium JS Help Desk Plugin js-support-ticket Information Disclosure Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject < 3.1.4 Fixed in 3.1.4 CVE-2026-14928 WPScan
6.1 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via ult_buttons Shortcode No login needed < 3.21.5 Fixed in 3.21.5 CVE-2026-14921 WPScan
4.3 Medium Paid Member Subscriptions Plugin Information Disclosure Subscriber+ Payment Data Disclosure via IDOR < 3.0.7 Fixed in 3.0.7 CVE-2026-14847 WPScan
6.1 Medium NewStatPress Plugin Cross-Site Scripting Unauthenticated Stored XSS via Top Post Widget No login needed < 1.4.5 Fixed in 1.4.5 CVE-2026-14845 WPScan
5.3 Medium Events Made Easy Plugin events-made-easy Broken Access Control Unauthenticated Person Data Modification via IDOR No login needed < 3.1.4 Fixed in 3.1.4 CVE-2026-14843 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only