WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1,551–1,600 of 9,010 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter No login needed |
≤ 9.2.2 |
CVE-2026-12142 |
Wordfence | |
| 8.8 High | RegistrationMagic | Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter |
≤ 6.0.9.1 |
CVE-2026-12158 |
Wordfence | |
| 8.8 High | Dokan Pro | Privilege Escalation Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint |
≤ 5.0.4 |
CVE-2026-12224 |
Wordfence | |
| 7.2 High | WebAuthn Provider for Two Factor | Authentication Bypass WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass |
< 2.5.6 Fixed in 2.5.6 |
CVE-2026-11883 |
WPScan | |
| 8.1 High | Advanced Form Integration | Privilege Escalation Unauthenticated Privilege Escalation via Breakdance Form Role Mapping No login needed |
< 2.1.1 Fixed in 2.1.1 |
CVE-2026-11794 |
WPScan | |
| 7.5 High | Product Configurator for WooCommerce | Information Disclosure Unauthenticated Private/Draft Product Data Disclosure via pc_get_data No login needed |
< 1.7.3 Fixed in 1.7.3 |
CVE-2026-11568 |
WPScan | |
| 8.1 High | Royal MCP | Broken Access Control Subscriber+ Insufficient Authorization in MCP Tools |
< 1.4.26 Fixed in 1.4.26 |
CVE-2026-10750 |
WPScan | |
| 7.5 High | Ninja Forms | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint No login needed |
≤ 3.14.1 |
CVE-2026-1239 |
Wordfence | |
| 7.5 High | BookingPress Appointment Booking Pro | SQL Injection Unauthenticated SQL Injection via 'store_service_date' Parameter No login needed |
≤ 5.7.1 |
CVE-2026-11823 |
Wordfence | |
| 7.2 High | Custom Payment Gateways for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter No login needed |
≤ 2.1.0 |
CVE-2026-7517 |
Wordfence | |
| 7.5 High | Video Gallery | Information Disclosure Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter |
≤ 4.0.3 |
CVE-2026-12923 |
Wordfence | |
| 7.5 High | Visualizer | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint No login needed |
≤ 4.0.3 |
CVE-2026-13468 |
Wordfence | |
| 7.2 High | WPBot | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter No login needed |
≤ 8.4.9 |
CVE-2026-13731 |
Wordfence | |
| 7.2 High | Webmention | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties No login needed |
≤ 5.8.0 |
CVE-2026-10513 |
Wordfence | |
| 7.2 High | Ajax Load More - Filters | Cross-Site Scripting Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field No login needed |
≤ 3.4.1 |
CVE-2026-8141 |
Wordfence | |
| 8.0 High | Export User Data | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field |
≤ 2.2.6 |
CVE-2026-12240 |
Wordfence | |
| 8.6 High | WP Support Plus Responsive Ticket System | SQL Injection Unauthenticated SQL Injection via filter[elements] Array Keys No login needed |
≤ 9.1.2 |
CVE-2026-11590 |
WPScan | |
| 8.8 High | WP Support Plus Responsive Ticket System | Cross-Site Scripting Unauthenticated Stored XSS via File Upload No login needed |
≤ 9.1.2 |
CVE-2026-11589 |
WPScan | |
| 7.1 High | ARForms | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 7.1.2 Fixed in 7.2 |
CVE-2026-57338 |
Patchstack | |
| 7.1 High | Landing Page Builder | Cross-Site Scripting No login needed |
≤ 1.5.3.5 Fixed in 1.5.3.6 |
CVE-2026-57337 |
Patchstack | |
| 7.1 High | Jobify | Cross-Site Scripting No login needed |
≤ 4.3.2 Fixed in 4.3.3 |
CVE-2026-57336 |
Patchstack | |
| 7.1 High | Link Whisper Free | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.9.4 Fixed in 0.9.5 |
CVE-2026-57333 |
Patchstack | |
| 7.1 High | Wallet System for WooCommerce | Broken Access Control |
≤ 2.7.6 Fixed in 2.7.7 |
CVE-2026-57332 |
Patchstack | |
| 7.1 High | BEAR | Cross-Site Scripting No login needed |
≤ 1.1.8 Fixed in 1.1.9 |
CVE-2026-57320 |
Patchstack | |
| 7.1 High | Embed Privacy | Arbitrary File Deletion |
≤ 1.12.3 Fixed in 1.12.4 |
CVE-2026-57346 |
Patchstack | |
| 7.5 High | APCu Manager | Cross-Site Scripting Unauthenticated Stored XSS via Cache Key Pollution No login needed |
< 4.5.0 Fixed in 4.5.0 |
CVE-2026-10083 |
WPScan | |
| 8.1 High | Frontend File Manager | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 23.6 |
CVE-2026-8095 |
Wordfence | |
| 8.1 High | ProfilePress | Broken Access Control Subscriber+ Subscription Cancellation via IDOR |
< 4.16.17 Fixed in 4.16.17 |
CVE-2026-10820 |
WPScan | |
| 8.5 High | Groundhogg | SQL Injection |
≤ 4.5 Fixed in 4.5.1 |
CVE-2026-57667 |
Patchstack | |
| 8.5 High | Recipe Maker For Your Food Blog from Zip Recipes | SQL Injection |
≤ 8.2.7 Fixed in 8.2.8 |
CVE-2026-57663 |
Patchstack | |
| 8.5 High | Contest Gallery | SQL Injection |
≤ 30.0.0 Fixed in 30.0.1 |
CVE-2026-57662 |
Patchstack | |
| 8.8 High | Paid Memberships Pro - Add Member From Admin | Cross-Site Request Forgery Add Member From Admin plugin <= 0.7.2 - Cross Site Request Forgery (CSRF) No login needed |
≤ 0.7.2 Fixed in 0.7.3 |
CVE-2026-57659 |
Patchstack | |
| 8.2 High | Child Theme Wizard | Cross-Site Request Forgery No login needed |
≤ 1.4 Fixed in 1.5 |
CVE-2026-57655 |
Patchstack | |
| 8.5 High | WP Job Portal | SQL Injection |
≤ 2.5.2 Fixed in 2.5.3 |
CVE-2026-57653 |
Patchstack | |
| 7.5 High | Panorama Viewer – 360 Degree Image + Video Viewer | Local File Inclusion |
≤ 1.6.1 Fixed in 1.7.0 |
CVE-2026-57647 |
Patchstack | |
| 8.1 High | Newsletters | Broken Access Control No login needed |
≤ 4.13 Fixed in 4.14 |
CVE-2026-57645 |
Patchstack | |
| 8.5 High | Restaurant Menu by MotoPress | SQL Injection |
≤ 2.4.10 Fixed in 2.4.11 |
CVE-2026-57644 |
Patchstack | |
| 8.5 High | WP Post Author | SQL Injection |
≤ 3.9.1 Fixed in 3.10.0 |
CVE-2026-57643 |
Patchstack | |
| 8.5 High | Gallery | SQL Injection |
≤ 4.7.8 Fixed in 4.7.9 |
CVE-2026-57642 |
Patchstack | |
| 8.5 High | wpForo Forum | SQL Injection |
≤ 3.0.9 Fixed in 3.1.0 |
CVE-2026-57636 |
Patchstack | |
| 7.6 High | Popup box | SQL Injection |
≤ 6.0.1 Fixed in 6.0.2 |
CVE-2026-57631 |
Patchstack | |
| 7.6 High | WP All Import | SQL Injection |
≤ 4.0.1 Fixed in 4.1.0 |
CVE-2026-57628 |
Patchstack | |
| 7.1 High | NanoMag | Cross-Site Scripting No login needed |
≤ 1.8 Fixed in 1.9 |
CVE-2026-57325 |
Patchstack | |
| 7.1 High | weMail | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.2 Fixed in 2.1.3 |
CVE-2026-57322 |
Patchstack | |
| 7.1 High | H5P | Arbitrary File Deletion |
≤ 1.17.7 Fixed in 1.17.8 |
CVE-2026-57321 |
Patchstack | |
| 7.1 High | FOX | Cross-Site Scripting No login needed |
≤ 1.4.8 Fixed in 1.4.9 |
CVE-2026-57319 |
Patchstack | |
| 7.1 High | Simply Schedule Appointments | Cross-Site Scripting No login needed |
≤ 1.6.12.2 Fixed in 1.6.12.4 |
CVE-2026-57317 |
Patchstack | |
| 8.5 High | Blocksy Companion Pro | Remote Code Execution |
≤ 2.1.45 Fixed in 2.1.46 |
CVE-2026-57315 |
Patchstack | |
| 7.1 High | SureCart | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.3.2 Fixed in 4.3.3 |
CVE-2026-57314 |
Patchstack | |
| 7.1 High | Everest Forms | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.4.8 Fixed in 3.5.0 |
CVE-2026-57312 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.