WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,551–1,600 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 32 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium LiveJournal Shortcode Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 1.1.1 CVE-2024-3773 WPScan
3.3 Low Weaver Show Posts Plugin show-posts PHP Object Injection Admin+ PHP Object Injection < 1.8.1 Fixed in 1.8.1 CVE-2023-3360 WPScan
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Multiple Widgets 1.6.0 – < 1.7.4 Fixed in 1.7.4 CVE-2026-83547 WPScan
5.3 Medium WP Express Checkout Plugin Price Manipulation Unauthenticated Payment Bypass via wpec_process_payment No login needed < 2.4.9 Fixed in 2.4.9 CVE-2026-83533 WPScan
6.8 Medium All in One SEO Plugin all-in-one-seo-pack Cross-Site Scripting Contributor+ Stored XSS via ai-assistant Block < 5.0.0.1 Fixed in 5.0.0.1 CVE-2026-82884 WPScan
4.8 Medium Brave Popup Builder Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via UTM Parameter No login needed < 0.8.8 Fixed in 0.8.8 CVE-2026-81571 WPScan
5.4 Medium Simple Membership MailChimp Integration Plugin simple-membership-mailchimp-integration Cross-Site Request Forgery API Key Update via CSRF No login needed < 1.9.8 Fixed in 1.9.8 CVE-2026-8151 WPScan
5.3 Medium Restrict User Access Plugin restrict-user-access Broken Access Control Unauthenticated Content Protection Bypass via REST API Route Normalization No login needed 2.6 – < 2.8.1 Fixed in 2.8.1 CVE-2026-78153 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Unauthenticated Payment Bypass via Zero Quantity No login needed 6.0.0.0 – < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77794 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Unauthenticated Payment Bypass via Omitted Price Field No login needed < 6.0.9.9 Fixed in 6.0.9.9 CVE-2026-77793 WPScan
9.9 Critical WatchMan-Site7 Plugin Remote Code Execution Subscriber+ RCE via Debug Console 3.1.1 – 4.2.0 CVE-2026-77009 WPScan
10.0 Critical Embed HTML5 Game Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.3 CVE-2026-4357 WPScan
3.5 Low GutenKit Plugin gutenkit-blocks-addon Content Injection Contributor+ Stored CSS Injection < 2.5.1 Fixed in 2.5.1 CVE-2026-19698 WPScan
6.5 Medium CM HIPAA Forms Plugin Broken Access Control Unauthenticated Authorization Bypass No login needed < 3.2.0 Fixed in 3.2.0 CVE-2026-2688 WPScan
5.3 Medium WP User Frontend Plugin Broken Access Control Unauthenticated Post Creation via Subscription-Gated Form No login needed < 4.3.11 Fixed in 4.3.11 CVE-2026-17563 WPScan
3.8 Low Timetics Plugin timetics Broken Access Control Staff+ Cross-Staff Appointment Modification via IDOR ≤ 1.0.61 CVE-2026-14326 WPScan
6.6 Medium Yoast SEO Premium Plugin Remote Code Execution Author+ Arbitrary .htaccess Directive Injection to RCE < 27.6.1 Fixed in 27.6.1 CVE-2026-10821 WPScan
3.5 Low Icegram Express Plugin Cross-Site Scripting Admin+ Stored XSS < 5.8.6 Fixed in 5.8.6 CVE-2025-15692 WPScan
5.4 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 6.1.3 Fixed in 6.1.5 CVE-2026-84217 Patchstack
5.3 Medium Rentsyst Plugin rentsyst Broken Access Control No login needed ≤ 2.1.5 CVE-2026-84835 Patchstack
5.4 Medium Grand Tour Theme grandtour Cross-Site Request Forgery No login needed ≤ 5.5.1 CVE-2026-66652 Patchstack
5.3 Medium WP Go Maps Plugin wp-google-maps Denial of Service Denial of Service Attack No login needed ≤ 10.1.08 Fixed in 10.1.09 CVE-2026-84780 Patchstack
5.3 Medium Really Simple SSL Plugin really-simple-ssl Denial of Service Denial of Service Attack No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84775 Patchstack
5.5 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery ≤ 2.4.14 Fixed in 2.4.14.1 CVE-2026-84772 Patchstack
5.3 Medium PublishPress Permissions Plugin press-permit-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-84771 Patchstack
8.8 High Mang Board WP Plugin mangboard Cross-Site Request Forgery No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2026-84770 Patchstack
8.8 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Request Forgery No login needed ≤ 1.6.12.23 Fixed in 1.6.12.24 CVE-2026-84764 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2026-84760 Patchstack
7.1 High Activity Log Plugin aryo-activity-log Cross-Site Request Forgery No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-84759 Patchstack
6.5 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting ≤ 3.8.2 Fixed in 3.8.3 CVE-2026-83562 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Broken Access Control No login needed ≤ 4.1.22 Fixed in 4.1.23 CVE-2026-82223 Patchstack
7.1 High Estatik Plugin estatik Cross-Site Scripting No login needed ≤ 4.3.4 CVE-2026-81775 Patchstack
7.5 High WooCommerce Product Attachment Plugin woo-product-attachment Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-81774 Patchstack
8.8 High Ninja Forms - Layout & Styles Plugin ninja-forms-style PHP Object Injection Layout & Styles plugin <= 3.0.31 - PHP Object Injection No login needed ≤ 3.0.31 CVE-2026-81772 Patchstack
7.1 High TrustedSite Plugin trustedsite Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2026-81771 Patchstack
7.1 High Interactive Geo Maps Plugin interactive-geo-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.30 CVE-2026-81770 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.1 CVE-2026-81769 Patchstack
9.8 Critical Authorizer Plugin authorizer Privilege Escalation No login needed ≤ 3.15.1 Fixed in 3.15.2 CVE-2026-81294 Patchstack
7.1 High MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting No login needed ≤ 5.13.1 Fixed in 5.14 CVE-2026-81289 Patchstack
7.1 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Cross-Site Scripting No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-81288 Patchstack
9.3 Critical WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2026-81286 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-84781 Patchstack
8.8 High WP User Frontend Plugin wp-user-frontend PHP Object Injection ≤ 4.3.10 Fixed in 4.3.11 CVE-2026-81283 Patchstack
7.2 High Broken Link Checker Plugin broken-link-checker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log No login needed ≤ 2.4.13 CVE-2026-75528 Wordfence
6.4 Medium Easy Waveform Player Plugin easy-waveform-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_easywaveformplayer Function ≤ 1.2.2 CVE-2025-7963 Wordfence
7.1 High Login With Ajax Plugin login-with-ajax Cross-Site Scripting No login needed ≤ 4.5.1 CVE-2026-82883 Patchstack
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter ≤ 4.27.5 CVE-2026-3850 Wordfence
8.1 High OAuth Single Sign On Plugin miniorange-login-with-eve-online-google-facebook Privilege Escalation Unauthenticated Account Takeover via Unverified Steam OpenID Assertion No login needed 6.25.0 – < 7.0.1 Fixed in 7.0.1 CVE-2026-82183 WPScan
4.1 Medium WPvivid Backup & Migration Plugin SQL Injection Admin+ SQLi via Upload Cleaner Isolation < 0.9.133 Fixed in 0.9.133 CVE-2026-82182 WPScan
8.8 High Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Unauthenticated Stored XSS via Chat Message Linkification No login needed < 20260827 Fixed in 20260827 CVE-2026-81807 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only