WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,651–1,700 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 34 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High MDTF Plugin wp-meta-data-filter-and-taxonomy-filter Local File Inclusion No login needed ≤ 1.3.8 Fixed in 1.3.9 CVE-2026-54845 Patchstack
7.5 High CheckView Automated Testing Plugin checkview Broken Access Control No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2026-54844 Patchstack
7.5 High Vitepos Plugin vitepos-lite Information Disclosure Sensitive Data Exposure No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2026-54841 Patchstack
8.5 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.6.8 Fixed in 2.6.9 CVE-2026-54838 Patchstack
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control No login needed ≤ 2.7.19 Fixed in 2.7.20 CVE-2026-54830 Patchstack
7.5 High Motors Plugin motors-car-dealership-classified-listings Broken Access Control No login needed ≤ 1.4.109 Fixed in 1.4.110 CVE-2026-54828 Patchstack
8.5 High SALESmanago & Leadoo Plugin salesmanago SQL Injection ≤ 3.11.2 Fixed in 3.11.3 CVE-2026-54822 Patchstack
7.4 High Visual Link Preview Plugin visual-link-preview Information Disclosure Sensitive Data Exposure ≤ 2.3.1 Fixed in 2.4.0 CVE-2026-54821 Patchstack
7.5 High MainWP Child Plugin mainwp-child Broken Access Control No login needed ≤ 6.1.1 Fixed in 6.1.2 CVE-2026-27366 Patchstack
7.5 High Tourfic Plugin tourfic SQL Injection Unauthenticated SQL Injection via 'post_id' Parameter No login needed ≤ 2.22.7 CVE-2026-12937 Wordfence
7.5 High InPost PL Plugin inpost-for-woocommerce Broken Access Control Unauthenticated WooCommerce Order Parcel-Locker Hijacking No login needed < 1.9.1 Fixed in 1.9.1 CVE-2026-9702 WPScan
8.8 High Email Address Encoder (Free Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.0.25, < 0.3.12 Fixed in 1.0.25 CVE-2026-5305 WPScan
7.5 High Dokan Pro Plugin SQL Injection Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters No login needed ≤ 5.0.4 CVE-2026-12077 Wordfence
8.8 High AdRotate Banner Manager Plugin adrotate Remote Code Execution Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute ≤ 5.17.7 CVE-2026-12242 Wordfence
7.6 High Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection ≤ 3.15.0.5 Fixed in 3.15.0.6 CVE-2026-56052 Patchstack
8.8 High Ultimate Member Plugin ultimate-member Privilege Escalation Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure ≤ 2.11.4 CVE-2026-7761 Wordfence
7.2 High Post Duplicator Plugin post-duplicator PHP Object Injection Contributor+ PHP Object Injection via customMetaData < 3.0.15 Fixed in 3.0.15 CVE-2026-10749 WPScan
7.5 High ShapedPlugin Multiple Pro Plugins Plugin Information Disclosure Backdoor via Compromised Vendor Update Server No login needed 4.0.1 – < 4.0.2, 3.2.4 – < 3.2.5, 3.5.2 – < 3.5.3 Fixed in 4.0.2 CVE-2026-10735 WPScan
7.7 High Themeco Cornerstone Plugin Information Disclosure Subscriber+ Arbitrary User Password Hash Disclosure 3.0.0 – < 7.8.8 Fixed in 7.8.8 CVE-2026-9710 WPScan
7.7 High Themeco Cornerstone Plugin Information Disclosure Subscriber+ Arbitrary User Meta Disclosure 3.0.0 – < 7.8.9 Fixed in 7.8.9 CVE-2026-9709 WPScan
7.5 High WP Forms Connector Plugin wp-forms-connector Broken Access Control Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint No login needed ≤ 1.8 CVE-2026-9178 Wordfence
7.2 High WP Meta SEO Plugin wp-meta-seo Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging No login needed ≤ 4.5.18 CVE-2026-9643 Wordfence
7.5 High ClearSale Total Plugin clearsale-total SQL Injection Unauthenticated SQL Injection No login needed <= 3.4.2 CVE-2026-8705 Wordfence
7.2 High Kargo Takip Plugin kargo-takip Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'api_url' Parameter No login needed ≤ 1.2 CVE-2026-12095 Wordfence
8.8 High Welcome Software Publishing Plugin newscred-publishing Privilege Escalation Authenticated (Subscriber+) Arbitrary Options Update to Privilege Escalation via 'nc.setOption' XML-RPC Method ≤ 0.0.31 CVE-2026-4297 Wordfence
7.2 High Cincopa video and media plug-in Plugin video-playlist-and-gallery-plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments No login needed ≤ 1.163 CVE-2026-10092 Wordfence
7.5 High WP Forms Connector Plugin wp-forms-connector SQL Injection Unauthenticated SQL Injection via 'order' Parameter No login needed ≤ 1.8 CVE-2026-9179 Wordfence
7.2 High Email JavaScript Cloak Plugin email-javascript-cloaker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.03 CVE-2026-10091 Wordfence
7.2 High URL Preview Plugin link-preview Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.0 CVE-2026-12100 Wordfence
7.2 High ARForms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'value' Parameter No login needed ≤ 7.1.3 CVE-2026-3652 Wordfence
7.5 High Frontend File Manager Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 23.6 CVE-2026-8379 WPScan
7.1 High Simple Basic Contact Form Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 20250114 CVE-2026-8172 WPScan
8.8 High Infility Global Plugin infility-global SQL Injection Subscriber+ SQL Injection via order Parameter < 2.15.19 Fixed in 2.15.19 CVE-2026-8163 WPScan
8.8 High Vitepos Plugin vitepos-lite Privilege Escalation Outlet Manager+ Privilege Escalation < 3.4.2 Fixed in 3.4.2 CVE-2026-8157 WPScan
7.1 High Transbank Webpay Plugin transbank-webpay-plus-rest Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.14.0 Fixed in 1.14.0 CVE-2026-6858 WPScan
7.1 High Ultimate WooCommerce Auction Pro Plugin Cross-Site Scripting Reflected XSS via uwa_manage_auctions No login needed ≤ 2.4.5 CVE-2026-4259 WPScan
7.5 High Simple File List Plugin simple-file-list Broken Access Control Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action No login needed ≤ 6.3.7 CVE-2026-11912 Wordfence
7.5 High Simple File List Plugin simple-file-list Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter No login needed ≤ 6.3.7 CVE-2026-11911 Wordfence
8.1 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value No login needed ≤ 1.5.1 CVE-2026-9843 Wordfence
8.5 High Media LIbrary Assistant Plugin media-library-assistant SQL Injection ≤ 3.35 Fixed in 3.36 CVE-2026-56012 Patchstack
7.2 High CF7 to Webhook Plugin cf7-to-zapier Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host No login needed ≤ 5.0.0 CVE-2026-11395 Wordfence
8.8 High Offload, AI & Optimize with Cloudflare Images Plugin cf-images Remote Code Execution Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action ≤ 1.10.2 CVE-2026-9860 Wordfence
8.8 High E2Pdf Plugin e2pdf Broken Access Control Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter ≤ 1.32.26 CVE-2026-12407 Wordfence
7.5 High Nexi XPay Plugin cartasi-x-pay Broken Access Control No login needed ≤ 8.3.1 Fixed in 8.3.2 CVE-2026-54810 Patchstack
7.3 High JobBank Plugin jobbank Broken Access Control No login needed ≤ 1.2.3 CVE-2025-69189 Patchstack
8.6 High JobCareer Theme jobcareer Arbitrary File Deletion No login needed ≤ 7.3 CVE-2025-69128 Patchstack
8.5 High SureDash Plugin suredash SQL Injection ≤ 1.8.0 Fixed in 1.8.1 CVE-2026-54813 Patchstack
8.1 High Motors Plugin motors-car-dealership-classified-listings Local File Inclusion No login needed ≤ 1.4.109 Fixed in 1.4.110 CVE-2026-54814 Patchstack
7.5 High Advanced Ads Plugin advanced-ads Remote Code Execution ≤ 2.0.21 Fixed in 2.0.22 CVE-2026-54816 Patchstack
8.5 High Slimstat Analytics Plugin wp-slimstat SQL Injection ≤ 5.4.11 Fixed in 5.4.12 CVE-2026-54818 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only