WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,651–1,700 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 34 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter No login needed ≤ 2.12.1 CVE-2026-19914 Wordfence
6.4 Medium Live Composer Plugin live-composer-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode ≤ 2.1.19 CVE-2026-16786 Wordfence
5.3 Medium KiviCare – Clinic & Patient Management System (EHR) Plugin kivicare-clinic-management-system Information Disclosure Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data Disclosure No login needed < 4.5.5 Fixed in 4.5.5 CVE-2026-13611 WPScan
4.8 Medium MW WP Form Plugin mw-wp-form Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Completion Message Merge Tags No login needed < 5.1.5 Fixed in 5.1.5 CVE-2026-78363 WPScan
6.5 Medium WP Fastest Cache Plugin wp-fastest-cache Other Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters No login needed 0.8.7.7 – < 1.5.1 Fixed in 1.5.1 CVE-2026-74916 WPScan
6.4 Medium Blocksy Companion Plugin blocksy-companion Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) ≤ 2.1.51 CVE-2026-18488 Wordfence
6.4 Medium BetterDocs Plugin betterdocs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content ≤ 4.8.1 CVE-2026-75980 Wordfence
6.1 Medium User Profile Builder Plugin profile-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'email' Parameter No login needed ≤ 4.0.0 CVE-2026-75964 Wordfence
6.5 Medium Charitable Plugin charitable SQL Injection Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attribute ≤ 1.8.12.1 CVE-2026-77189 Wordfence
5.3 Medium Cozy Blocks Plugin cozy-addons Broken Access Control Missing Authorization to Unauthenticated Unpublished Product Information Disclosure via 'wishlistData' Parameter No login needed ≤ 2.2.17 CVE-2026-19948 Wordfence
4.9 Medium LearnPress Plugin learnpress SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 4.4.4 CVE-2026-77823 Wordfence
7.2 High Affiliate Super Assistent Plugin amazonsimpleadmin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function No login needed ≤ 1.10.2 CVE-2026-19573 Wordfence
6.4 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute ≤ 3.29.11 CVE-2026-12747 Wordfence
6.4 Medium Live Composer Plugin live-composer-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode ≤ 2.1.19 CVE-2026-16787 Wordfence
6.4 Medium Live Composer Plugin live-composer-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute ≤ 2.1.19 CVE-2026-13203 Wordfence
4.9 Medium Photo Gallery by Ays Plugin gallery-photo-gallery SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 6.8.2 CVE-2026-76006 Wordfence
6.4 Medium User Profile Builder Plugin profile-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'date' Shortcode Attribute ≤ 4.0.0 CVE-2026-75965 Wordfence
7.5 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag No login needed ≤ 3.29.12 CVE-2026-19952 Wordfence
8.8 High Support Genix Plugin support-genix-lite Authentication Bypass Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token ≤ 1.4.52 CVE-2026-19806 Wordfence
6.5 Medium Persistent Login Plugin wp-persistent-login SQL Injection Authenticated (Subscriber+) SQL Injection via 'wppl_device_id' Cookie ≤ 3.1.0 CVE-2026-18752 Wordfence
4.9 Medium Shopping Cart & eCommerce Store Plugin wp-easycart SQL Injection Authenticated (Administrator+) SQL Injection via 'product_order' Parameter ≤ 5.9.2 CVE-2026-17589 Wordfence
7.2 High Master Addons for Elementor Plugin master-addons Broken Access Control Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction ≤ 3.1.9 CVE-2026-75921 Wordfence
7.2 High Listdom: AI-powered Business Directory with Classifieds Ads Listings Plugin listdom Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter No login needed ≤ 5.8.1 CVE-2026-19796 Wordfence
9.8 Critical WPLP Cookie Consent Plugin gdpr-cookie-consent Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint No login needed ≤ 4.4.1 CVE-2026-75865 Wordfence
10.0 Critical Newspapers X Theme newspapers-x Other Backdoor No login needed 1.0.46 – 1.0.48 Fixed in 1.0.49 CVE-2026-81779 Patchstack
5.4 Medium Post SMTP Plugin post-smtp Broken Access Control Settings Change 4.0.0 – beta.1 Fixed in 4.0.1 CVE-2026-81278 Patchstack
7.1 High WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting No login needed ≤ 7.8.2 Fixed in 7.9.0 CVE-2026-82229 Patchstack
8.1 High SiteGround Security Plugin sg-security Authentication Bypass WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-82228 Patchstack
9.8 Critical Tickera Plugin tickera-event-ticketing-system PHP Object Injection No login needed ≤ 3.6.0.2 Fixed in 3.6.0.3 CVE-2026-82226 Patchstack
7.4 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82225 Patchstack
7.1 High SliceWP Plugin slicewp Cross-Site Scripting No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2026-82224 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82221 Patchstack
10.0 Critical Hash Form Plugin hash-form Arbitrary File Upload No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-81780 Patchstack
6.5 Medium Kalles Addons Plugin kalles-addons Cross-Site Scripting ≤ 1.0.6 CVE-2026-81778 Patchstack
7.1 High Super Store Finder Plugin superstorefinder-wp Cross-Site Scripting No login needed ≤ 7.10 Fixed in 7.11 CVE-2026-81768 Patchstack
7.1 High Tailored Tools Plugin tailored-tools Cross-Site Scripting No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2026-81765 Patchstack
7.1 High Email Essentials Plugin email-essentials Cross-Site Scripting No login needed ≤ 6.0.6 Fixed in 6.0.7 CVE-2026-81764 Patchstack
9.3 Critical Throws SPAM Away Plugin throws-spam-away SQL Injection No login needed ≤ 3.8.2 Fixed in 3.9 CVE-2026-81763 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-81762 Patchstack
6.3 Medium OwnerRez API Plugin ownerrez Broken Access Control ≤ 1.2.6 Fixed in 1.3.0 CVE-2026-81758 Patchstack
9.3 Critical Smart Marketing SMS and Newsletters Forms Plugin smart-marketing-for-wp SQL Injection No login needed ≤ 5.1.24 Fixed in 5.1.25 CVE-2026-81756 Patchstack
7.1 High LeadConnector Plugin leadconnector Cross-Site Scripting No login needed ≤ 4.0.5 Fixed in 4.0.6 CVE-2026-81298 Patchstack
7.5 High Fluent Forms Pro Add On Pack Plugin fluentformpro Privilege Escalation ≤ 6.2.12 Fixed in 6.2.13 CVE-2026-81297 Patchstack
7.5 High Fluent Forms Pro Add On Pack Plugin fluentformpro Broken Access Control No login needed ≤ 6.2.12 Fixed in 6.2.13 CVE-2026-81296 Patchstack
9.3 Critical WP Data Access Plugin wp-data-access SQL Injection No login needed ≤ 5.5.81 Fixed in 5.5.82 CVE-2026-81293 Patchstack
7.1 High Uncode Theme uncode Cross-Site Scripting No login needed ≤ 2.12.7 Fixed in 2.12.8 CVE-2026-81291 Patchstack
7.1 High Email Subscribers & Newsletters Plugin email-subscribers Cross-Site Scripting No login needed ≤ 5.9.33 Fixed in 5.9.34 CVE-2026-81290 Patchstack
8.5 High Charitable Plugin charitable SQL Injection ≤ 1.8.12.1 Fixed in 1.8.12.2 CVE-2026-81287 Patchstack
5.4 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Server-Side Request Forgery No login needed ≤ 8.15.0 CVE-2026-82852 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Information Disclosure Sensitive Data Exposure ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-81280 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only