WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,551–1,600 of 17,674 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Mailgun | Broken Access Control Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX No login needed |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14834 |
WPScan | |
| 6.8 Medium | Lightbox with PhotoSwipe | Cross-Site Scripting Author+ Stored XSS via data-lbwps-caption Attribute |
< 5.9.0 Fixed in 5.9.0 |
CVE-2026-14833 |
WPScan | |
| 6.5 Medium | Check & Log Email | SQL Injection Admin+ SQL Injection via d and s Parameters |
< 2.0.15 Fixed in 2.0.15 |
CVE-2026-14554 |
WPScan | |
| 5.3 Medium | GiveWP | Broken Access Control Unauthenticated Payment Gateway Restriction Bypass No login needed |
< 4.16.3 Fixed in 4.16.3 |
CVE-2026-14317 |
WPScan | |
| 4.3 Medium | FuseWP | Cross-Site Request Forgery Cross-Site Request Forgery to Sync Rule Status Toggle No login needed |
≤ 1.1.24.2 |
CVE-2026-5582 |
Wordfence | |
| 5.4 Medium | Tutor LMS | Information Disclosure Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection |
< 4.0.0 Fixed in 4.0.0 |
CVE-2026-14310 |
WPScan | |
| 5.3 Medium | WP Delicious | Authentication Bypass Unauthenticated Arbitrary Post Meta Update via recipe_likes No login needed |
< 1.10.2 Fixed in 1.10.2 |
CVE-2026-14305 |
WPScan | |
| 5.3 Medium | Essential Addons for Elementor - Lite | Information Disclosure Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table No login needed |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13345 |
WPScan | |
| 4.8 Medium | Essential Addons for Elementor - Lite | Cross-Site Scripting Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13344 |
WPScan | |
| 6.1 Medium | Animation Addons for Elementor | Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed |
< 2.7.0 Fixed in 2.7.0 |
CVE-2026-13330 |
WPScan | |
| 4.3 Medium | WP Travel | Information Disclosure Subscriber+ Booking PII Disclosure via IDOR |
< 11.8.1 Fixed in 11.8.1 |
CVE-2026-13145 |
WPScan | |
| 5.3 Medium | WP Travel | Price Manipulation Unauthenticated Payment Bypass via Forged PayPal IPN No login needed |
< 11.8.1 Fixed in 11.8.1 |
CVE-2026-13143 |
WPScan | |
| 6.1 Medium | Fluent Forms | Cross-Site Scripting Contributor+ Stored XSS via Date/Time Field No login needed |
< 6.2.6 Fixed in 6.2.6 |
CVE-2026-11881 |
WPScan | |
| 5.4 Medium | Hide My WP Ghost | Authentication Bypass IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass |
< 7.0.05 Fixed in 7.0.05 |
CVE-2026-11870 |
WPScan | |
| 6.5 Medium | Frontend Admin by DynamiApps | Broken Access Control Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization |
< 3.29.7 Fixed in 3.29.7 |
CVE-2026-11867 |
WPScan | |
| 6.5 Medium | Ultimate Addons for WPBakery Page Builder | Path Traversal Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts No login needed |
< 3.21.4 Fixed in 3.21.4 |
CVE-2026-15382 |
WPScan | |
| 5.3 Medium | RegistrationMagic | Broken Access Control Unauthenticated Form Submission and User Profile Modification No login needed |
< 6.0.9.4 Fixed in 6.0.9.4 |
CVE-2026-15257 |
WPScan | |
| 5.3 Medium | RegistrationMagic | Information Disclosure Unauthenticated Form Submission Disclosure via IDOR No login needed |
< 6.0.9.4 Fixed in 6.0.9.4 |
CVE-2026-15255 |
WPScan | |
| 5.4 Medium | Search Atlas SEO | Broken Access Control Subscriber+ Google Indexing API Access |
< 2.6.12 Fixed in 2.6.12 |
CVE-2026-15252 |
WPScan | |
| 5.9 Medium | Points and Rewards for WooCommerce | Broken Access Control Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR No login needed |
< 2.10.1 Fixed in 2.10.1 |
CVE-2026-11782 |
WPScan | |
| 5.3 Medium | LatePoint | Broken Access Control Unauthenticated Booking Object Mass Assignment via Public Booking Funnel No login needed |
< 5.6.8 Fixed in 5.6.8 |
CVE-2026-15250 |
WPScan | |
| 6.8 Medium | GiveWP | Cross-Site Scripting GiveWP Worker+ Stored XSS via Donation Form Template Settings |
< 4.16.3 Fixed in 4.16.3 |
CVE-2026-14318 |
WPScan | |
| 4.3 Medium | LifterLMS | Information Disclosure Subscriber+ Sensitive Information Disclosure via select2_query_posts |
< 10.0.10 Fixed in 10.0.10 |
CVE-2026-14231 |
WPScan | |
| 6.1 Medium | LifterLMS | Cross-Site Scripting Instructor+ Stored XSS via Featured Pricing Information No login needed |
9.2.3 – < 10.0.10 Fixed in 10.0.10 |
CVE-2026-14207 |
WPScan | |
| 4.3 Medium | Hotel Booking Lite | Information Disclosure Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action |
< 6.0.4 Fixed in 6.0.4 |
CVE-2026-15235 |
WPScan | |
| 6.8 Medium | WP Hotel Booking | SQL Injection Hotel Manager+ SQL Injection via Booking List Search |
< 2.3.2 Fixed in 2.3.2 |
CVE-2026-15153 |
WPScan | |
| 6.5 Medium | Sync Post With Other Site | Broken Access Control Contributor+ Arbitrary Page Creation/Modification |
< 1.9.3 Fixed in 1.9.3 |
CVE-2026-14923 |
WPScan | |
| 6.1 Medium | WP Real IP-based Access Control | Cross-Site Scripting Unauthenticated Stored XSS via acl_ctrl_addr No login needed |
≤ 1.3.1 |
CVE-2026-14592 |
WPScan | |
| 4.3 Medium | Easy Appointments | Information Disclosure Subscriber+ Sensitive Information Disclosure via REST Appointments Listing |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14226 |
WPScan | |
| 4.3 Medium | Easy Appointments | Information Disclosure Subscriber+ Customer PII Disclosure via IDOR |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14223 |
WPScan | |
| 6.5 Medium | Improved Save Button | SQL Injection Authenticated (Author+) Second-Order SQL Injection via 'meta_key' Parameter |
≤ 1.2.1 |
CVE-2026-16092 |
Wordfence | |
| 5.3 Medium | Persian Elementor (المنتور فارسی) | Price Manipulation Unauthenticated Price Manipulation via ZarinPal Widget No login needed |
≤ 2.8.1 |
CVE-2026-1982 |
Wordfence | |
| 6.4 Medium | Booking System Trafft | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
<= 1.0.17 |
CVE-2026-8791 |
Wordfence | |
| 4.9 Medium | WP CTA | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
2.1.2 |
CVE-2026-6089 |
Wordfence | |
| 6.4 Medium | WPC Badge Management for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Attribute |
≤ 3.1.6 |
CVE-2026-7436 |
Wordfence | |
| 6.5 Medium | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Broken Access Control for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion |
≤ 3.7.23 |
CVE-2026-5060 |
Wordfence | |
| 5.3 Medium | Klubraum Membership Request | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update No login needed |
≤ 1.1.0 |
CVE-2026-4604 |
Wordfence | |
| 4.9 Medium | WP-Lister Lite for eBay | SQL Injection Authenticated (Shop Manager+) SQL Injection via 'orderby' Parameter |
≤ 3.8.8 |
CVE-2026-11973 |
Wordfence | |
| 4.3 Medium | Facturación Electrónica Costa Rica | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 2.0.2 |
CVE-2026-9720 |
Wordfence | |
| 6.4 Medium | Link Library | Cross-Site Scripting Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Libra… No login needed |
< 7.9.4 Fixed in 7.9.4 |
CVE-2026-18197 |
tenable | |
| 5.4 Medium | Easy Appointments | Broken Access Control Subscriber+ Cross-User Appointment Data Modification via IDOR |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14224 |
WPScan | |
| 5.3 Medium | PayU CommercePro | Broken Access Control Unauthenticated Order Tampering No login needed |
< 3.9.0 Fixed in 3.9.0 |
CVE-2026-13692 |
WPScan | |
| 6.8 Medium | Photo Swipe | Cross-Site Scripting Author+ Stored XSS via title Attribute |
≤ 4.1.1.1 |
CVE-2026-13605 |
WPScan | |
| 5.3 Medium | ShinyStat Analytics | Information Disclosure Unauthenticated Non-Published Product Information Disclosure No login needed |
1.0.12 – < 1.0.17 Fixed in 1.0.17 |
CVE-2026-11351 |
WPScan | |
| 4.9 Medium | WP Photo Album Plus | SQL Injection Authenticated (Administrator+) SQL Injection via 'table' Parameter |
≤ 9.2.04.002 |
CVE-2026-15344 |
Wordfence | |
| 4.3 Medium | Survey Form Block | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export |
≤ 1.0.1 |
CVE-2026-5626 |
Wordfence | |
| 6.4 Medium | WowStore | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attribute |
≤ 4.4.24 |
CVE-2026-17162 |
Wordfence | |
| 6.4 Medium | WowStore | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attribute |
≤ 4.4.24 |
CVE-2026-17161 |
Wordfence | |
| 4.3 Medium | Event Booking Manager for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action |
≤ 5.3.7 |
CVE-2026-17166 |
Wordfence | |
| 6.4 Medium | Newsletters | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute |
≤ 4.15 |
CVE-2026-12939 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.