WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,551–1,600 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 32 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High MailerPress Plugin mailerpress Privilege Escalation ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-57410 Patchstack
7.1 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57409 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2026-57408 Patchstack
7.2 High PDF Generator Plugin pdf-generator-for-wp Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-57407 Patchstack
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-57406 Patchstack
7.1 High Open Shop Plugin open-shop Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2026-57405 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2026-57404 Patchstack
7.1 High GD Security Headers Plugin gd-security-headers Cross-Site Scripting No login needed ≤ 1.8 Fixed in 1.9 CVE-2026-57403 Patchstack
6.5 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Cross-Site Scripting ≤ 1.0.51 Fixed in 1.0.52 CVE-2026-57402 Patchstack
9.9 Critical SureDash Plugin suredash Arbitrary File Deletion ≤ 1.8.0 Fixed in 1.8.1 CVE-2026-57401 Patchstack
6.5 Medium Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-57400 Patchstack
7.1 High Proxy & VPN Blocker Plugin proxy-vpn-blocker Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2026-57399 Patchstack
7.1 High Real Estate Manager Pro Plugin real-estate-manager-pro Cross-Site Scripting No login needed ≤ 12.8.3 Fixed in 12.8.4 CVE-2026-57398 Patchstack
7.1 High Free Gifts for WooCommerce Plugin free-gifts-for-woocommerce Cross-Site Scripting No login needed ≤ 13.1.0 Fixed in 13.3.0 CVE-2026-57396 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57395 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting No login needed ≤ 4.14 Fixed in 4.15 CVE-2026-57394 Patchstack
6.5 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-57393 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57392 Patchstack
6.5 Medium Loops & Logic Plugin tangible-loops-and-logic Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-57391 Patchstack
6.5 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Broken Access Control No login needed ≤ 1.2.167 Fixed in 1.2.168 CVE-2026-57390 Patchstack
8.6 High Groundhogg Plugin groundhogg Arbitrary File Deletion No login needed ≤ 4.4.1 Fixed in 4.5 CVE-2026-57389 Patchstack
7.1 High Hydra Booking Plugin hydra-booking Cross-Site Scripting No login needed ≤ 1.1.44 Fixed in 1.1.45 CVE-2026-57388 Patchstack
7.1 High picu Plugin picu Cross-Site Scripting No login needed ≤ 3.5.1 Fixed in 3.6.1 CVE-2026-57387 Patchstack
8.8 High aBlocks Plugin ablocks Privilege Escalation ≤ 2.9.1 Fixed in 2.9.1 CVE-2026-57386 Patchstack
8.5 High Vitepos Plugin vitepos-lite SQL Injection ≤ 3.4.2 Fixed in 3.4.3 CVE-2026-57385 Patchstack
7.1 High JobSearch Plugin wp-jobsearch Cross-Site Scripting No login needed ≤ 3.2.9 Fixed in 3.3.0 CVE-2026-57383 Patchstack
7.1 High Simple File List Plugin simple-file-list Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.3.8 Fixed in 6.3.9 CVE-2026-57382 Patchstack
7.1 High PropertyHive Plugin propertyhive Cross-Site Scripting No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2026-57381 Patchstack
7.1 High Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting No login needed ≤ 5.1 Fixed in 5.2 CVE-2026-57380 Patchstack
7.1 High FormyChat Plugin social-contact-form Cross-Site Scripting No login needed ≤ 2.15.3 Fixed in 2.15.4 CVE-2026-57379 Patchstack
7.5 High Advanced Forms Plugin advanced-forms Broken Access Control No login needed ≤ 1.9.3.7 Fixed in 1.9.3.8 CVE-2026-57378 Patchstack
6.5 Medium WowAddons Plugin product-addons Broken Access Control No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2026-57377 Patchstack
7.1 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-57376 Patchstack
6.5 Medium MStore API Plugin mstore-api Broken Access Control No login needed ≤ 4.18.4 Fixed in 4.19.0 CVE-2026-57375 Patchstack
7.2 High WPJAM Basic Plugin wpjam-basic Server-Side Request Forgery No login needed ≤ 7.0 Fixed in 7.0.1 CVE-2026-57372 Patchstack
8.8 High WPJAM Basic Plugin wpjam-basic PHP Object Injection ≤ 7.0 Fixed in 7.0.1 CVE-2026-57371 Patchstack
7.1 High Themify Builder Plugin themify-builder Cross-Site Scripting No login needed ≤ 7.7.4 Fixed in 7.7.5 CVE-2026-57369 Patchstack
7.1 High Jobmonster Theme noo-jobmonster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.5 Fixed in 4.8.5.1 CVE-2026-57368 Patchstack
6.5 Medium reCAPTCHA (v2 & v3) for Asgaros Forum Plugin recaptcha-for-asgaros-forum Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57365 Patchstack
6.5 Medium Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More Plugin better-payment Other Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-57364 Patchstack
7.1 High ChatBot Plugin chatbot Cross-Site Scripting No login needed ≤ 8.3.7 Fixed in 8.3.8 CVE-2026-57363 Patchstack
8.1 High SureCart Plugin surecart Privilege Escalation Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook No login needed ≤ 4.2.3 CVE-2026-7655 Wordfence
9.8 Critical OAuth Single Sign On - SSO (OAuth Client) Plugin miniorange-oauth-oidc-single-sign-on Authentication Bypass SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication No login needed ≤ 38.5.8 Fixed in 38.5.8.1 CVE-2026-57807 Patchstack
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms Price Manipulation Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation No login needed ≤ 2.2.1 CVE-2026-15288 Wordfence
6.5 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 4.6.18 CVE-2026-15287 Wordfence
4.3 Medium CrawlWP SEO Plugin mihdan-index-now Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2026-59520 Patchstack
5.3 Medium FormLayer Plugin formlayer Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-59519 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.9.9 Fixed in 2.8.0 CVE-2026-59511 Patchstack
7.5 High AR Plugin ar-for-wordpress Path Traversal Unauthenticated Arbitrary File Read via 'file' Parameter No login needed ≤ 8.40 CVE-2026-14327 Wordfence
5.3 Medium Sendcloud Shipping Plugin sendcloud-connected-shipping Broken Access Control No login needed ≤ 1.0.29 CVE-2026-57760 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only