WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,601–1,650 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 33 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Contact Form to Any API Plugin contact-form-to-any-api Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta ≤ 3.0.6 CVE-2026-15735 Wordfence
6.4 Medium Newsletters Plugin newsletters-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute ≤ 4.15 CVE-2026-12938 Wordfence
4.9 Medium SpeedyCache Plugin speedycache Path Traversal Authenticated (Administrator+) Arbitrary File Read ≤ 1.3.8 CVE-2026-5114 Wordfence
4.1 Medium Media Cleaner: Clean your WordPress! Plugin media-cleaner Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 7.0.3 CVE-2026-4912 Wordfence
6.5 Medium Plugin Organizer Plugin plugin-organizer SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 10.2.4 CVE-2026-15304 Wordfence
6.4 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute ≤ 2.2.11 CVE-2026-15393 Wordfence
6.4 Medium Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Plugin Cross-Site Scripting Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.8.1 CVE-2026-15016 Wordfence
5.3 Medium StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action No login needed ≤ 2.1.0 CVE-2026-13110 Wordfence
4.9 Medium Tutor LMS Plugin tutor SQL Injection Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter ≤ 4.0.1 CVE-2026-15444 Wordfence
5.3 Medium StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action No login needed ≤ 2.1.0 CVE-2026-15411 Wordfence
5.3 Medium WPBot Plugin chatbot Information Disclosure Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action No login needed ≤ 8.5.9 CVE-2026-16773 Wordfence
5.3 Medium WPBot Plugin chatbot Broken Access Control Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action No login needed ≤ 8.5.9 CVE-2026-16774 Wordfence
5.0 Medium Shortcodify Plugin shortcodify Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute ≤ 1.4.3 CVE-2026-11598 Wordfence
6.5 Medium Taskbuilder Plugin taskbuilder SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 5.0.9 CVE-2026-15267 Wordfence
6.4 Medium GamiPress Plugin gamipress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute ≤ 7.9.9.1 CVE-2026-15730 Wordfence
4.4 Medium SMS Alert Plugin sms-alert SQL Injection Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings ≤ 3.9.7 CVE-2026-15673 Wordfence
4.9 Medium SMS Alert Plugin sms-alert SQL Injection Authenticated (Administrator+) SQL Injection via 'id' Parameter ≤ 3.9.7 CVE-2026-15671 Wordfence
4.9 Medium SMS Alert Plugin sms-alert SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 3.9.7 CVE-2026-15670 Wordfence
4.2 Medium FluentCart Plugin Broken Access Control Subscriber+ Subscription Payment-Method Tampering via IDOR < 1.4.0 Fixed in 1.4.0 CVE-2026-14926 WPScan
4.9 Medium ShopLentor Plugin woolentor-addons SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 3.4.5 CVE-2026-16811 Wordfence
4.3 Medium Advanced Form Integration Plugin advanced-form-integration Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function ≤ 2.6.0 CVE-2026-16587 Wordfence
4.3 Medium ShopLentor Plugin woolentor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter ≤ 3.4.5 CVE-2026-16797 Wordfence
4.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed ≤ 4.3.7 CVE-2026-15136 Wordfence
5.3 Medium Demi Plugin demi-backup-migration Information Disclosure Unauthenticated Information Exposure to Arbitrary Directory Copy No login needed ≤ 0.0.8 CVE-2026-15012 Wordfence
5.3 Medium PDFDraft Plugin pdfdraft Broken Access Control Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter No login needed ≤ 1.1.0 CVE-2026-12124 Wordfence
6.5 Medium Chaty Pro Plugin chaty-pro SQL Injection Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter ≤ 3.5.5 CVE-2026-6251 Wordfence
6.5 Medium Anti Spam and list cleaner – AcyChecker Plugin acychecker Cross-Site Scripting AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) ≤ 1.8.1 Fixed in 2.0.0 CVE-2026-65448 Patchstack
6.5 Medium Ad Invalid Click Protector (AICP) Plugin ad-invalid-click-protector Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-65445 Patchstack
5.3 Medium Gillion Theme gillion Broken Access Control No login needed ≤ 4.13 Fixed in 4.14 CVE-2026-66477 Patchstack
4.9 Medium Easy Digital Downloads Plugin easy-digital-downloads Arbitrary File Deletion ≤ 3.6.9 CVE-2026-66476 Patchstack
5.9 Medium Checkout Field Editor for WooCommerce – Checkout Manager Plugin checkout-field-editor-and-manager-for-woocommerce Cross-Site Scripting Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) ≤ 3.0.5 CVE-2026-66475 Patchstack
4.3 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Request Forgery HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2026-66474 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-66448 Patchstack
6.5 Medium Open User Map Plugin open-user-map Cross-Site Scripting ≤ 1.4.46 Fixed in 1.4.47 CVE-2026-66445 Patchstack
5.4 Medium YayPricing Plugin yaypricing Broken Access Control ≤ 3.5.6 Fixed in 3.5.7 CVE-2026-66442 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-66438 Patchstack
4.9 Medium Feedzy Plugin feedzy-rss-feeds Server-Side Request Forgery ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-66437 Patchstack
6.5 Medium Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting ≤ 3.33 Fixed in 3.34 CVE-2026-66434 Patchstack
6.5 Medium Location Weather Plugin location-weather Cross-Site Scripting ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-66433 Patchstack
4.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery No login needed ≤ 18.4 Fixed in 18.5 CVE-2026-66428 Patchstack
5.0 Medium Visual Composer Website Builder Plugin visualcomposer Broken Access Control ≤ 45.15.0 Fixed in 45.16.0 CVE-2026-65568 Patchstack
5.3 Medium Event Tickets Plugin event-tickets Broken Access Control No login needed ≤ 5.29.0.1 Fixed in 5.29.1 CVE-2026-65567 Patchstack
5.3 Medium MapPress Maps Plugin mappress-google-maps-for-wordpress Information Disclosure Sensitive Data Exposure No login needed ≤ 2.97.6 Fixed in 2.97.7 CVE-2026-65564 Patchstack
5.9 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-65563 Patchstack
6.5 Medium BetterDocs Plugin betterdocs Cross-Site Scripting ≤ 4.6.2 Fixed in 4.7.0 CVE-2026-65562 Patchstack
6.5 Medium WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting ≤ 7.8.0 Fixed in 7.8.1 CVE-2026-65561 Patchstack
5.4 Medium AffiliateX Plugin affiliatex Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2026-65558 Patchstack
5.9 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Scripting ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-65557 Patchstack
6.8 Medium Kirki Plugin kirki Arbitrary File Deletion ≤ 6.0.13 Fixed in 6.0.14 CVE-2026-65436 Patchstack
6.5 Medium Thrive Leads Version Plugin thrive-leads Broken Access Control No login needed ≤ 10.9.2 Fixed in 10.9.2.1 CVE-2026-65435 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only