WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,701–1,750 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 35 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Keep Backup Daily Plugin keep-backup-daily Information Disclosure Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_process No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-75133 VulnCheck
8.1 High ProfilePress Plugin wp-user-avatar Remote Code Execution ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE No login needed < 4.17.2 Fixed in 4.17.2 CVE-2026-66047 VulnCheck
10.0 Critical WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Arbitrary File Upload No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2026-82970 Patchstack
5.3 Medium bbPress Plugin bbpress Broken Access Control No login needed ≤ 2.6.14 CVE-2026-74010 Patchstack
5.3 Medium Icollect Plugin Broken Access Control Unauthenticated User and Term Creation via Unrestricted Method Dispatch No login needed ≤ 1.0.0 CVE-2026-77013 WPScan
6.6 Medium Really Simple Security Plugin really-simple-ssl Remote Code Execution Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_plugin < 9.8.0 Fixed in 9.8.0 CVE-2026-81766 WPScan
8.8 High Groundhogg Plugin Cross-Site Scripting Unauthenticated Stored XSS via Web Form Dropdown/Radio Field No login needed < 4.5.13 Fixed in 4.5.13 CVE-2026-81660 WPScan
3.5 Low MW WP Form Plugin mw-wp-form Cross-Site Scripting Editor+ Stored XSS via Inquiry Data List < 5.1.6 Fixed in 5.1.6 CVE-2026-78364 WPScan
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored XSS via 'comment' Parameter No login needed < 5.118.0 Fixed in 5.118.0 CVE-2026-76585 WPScan
6.6 Medium WPvivid Backup & Migration Plugin Path Traversal Admin+ Arbitrary File Write via Zip Slip in Backup Restore < 0.9.133 Fixed in 0.9.133 CVE-2026-19722 WPScan
7.1 High Geotargeting WP Plugin Cross-Site Scripting Reflected XSS No login needed < 3.5.6.2 Fixed in 3.5.6.2 CVE-2026-14307 WPScan
6.8 Medium SOGO Add Script to Individual Pages Header Footer Plugin Cross-Site Scripting Contributor+ Stored XSS via Post Metabox ≤ 3.9 CVE-2026-14835 WPScan
9.8 Critical MyHome Core Plugin Authentication Bypass Authentication Bypass to Account Takeover via Activation Token No login needed ≤ 4.4.5 CVE-2026-15980 Wordfence
9.8 Critical Custom User Registration Fields for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout No login needed ≤ 2.2.3 CVE-2026-15369 Wordfence
7.5 High SAML Single Sign On Plugin miniorange-saml-20-single-sign-on Authentication Bypass Unauthenticated Authentication Bypass via X.509 Certificate Poisoning No login needed ≤ 5.4.6 CVE-2026-75807 Wordfence
9.8 Critical Sigma Forms Pro Plugin Arbitrary File Upload Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field No login needed ≤ 1.4.5 CVE-2026-14494 Wordfence
4.3 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Subscriber+ Arbitrary Membership Plan Deletion < 3.29.11 Fixed in 3.29.11 CVE-2026-81346 WPScan
4.7 Medium MasterStudy LMS Plugin Open Redirect Unauthenticated Open Redirect No login needed < 3.7.43 Fixed in 3.7.43 CVE-2026-81342 WPScan
2.7 Low MasterStudy LMS Plugin Information Disclosure Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR < 3.7.42 Fixed in 3.7.42 CVE-2026-81200 WPScan
4.8 Medium MasterStudy LMS Plugin Price Manipulation Unauthenticated Payment Bypass via PayPal IPN No login needed < 3.7.40 Fixed in 3.7.40 CVE-2026-81026 WPScan
4.1 Medium WP Ultimate CSV Importer Plugin wp-ultimate-csv-importer SQL Injection Admin+ SQLi via AIOSEO Import Fields < 9.0 Fixed in 9.0 CVE-2026-80488 WPScan
4.3 Medium Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Broken Access Control Cross-Customer Subscription Cancellation via IDOR < 8.5.5 Fixed in 8.5.5 CVE-2026-80311 WPScan
4.9 Medium Rank Math SEO Plugin seo-by-rank-math Broken Access Control Editor+ Core Settings Modification via fix-site-seo Ability 1.0.271 – < 1.0.277 Fixed in 1.0.277 CVE-2026-77786 WPScan
2.7 Low Amelia Plugin Broken Access Control Amelia Customer+ Appointment Status Update and Self-Approval 1.2.32 – < 2.4.9 Fixed in 2.4.9 CVE-2026-77704 WPScan
9.3 Critical Icollect Plugin Path Traversal Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password No login needed ≤ 1.0.0 CVE-2026-77012 WPScan
6.5 Medium HEL Online Classroom: AI-powered Online Classrooms Plugin Information Disclosure Unauthenticated Moderator Join URL Disclosure and Class Access Code Bypass No login needed ≤ 1.0.3 CVE-2026-77010 WPScan
6.5 Medium HEL Online Classroom: AI-powered Online Classrooms Plugin Broken Access Control Unauthenticated Plugin Settings Update No login needed ≤ 1.0.3 CVE-2026-77008 WPScan
7.5 High HEL Online Classroom: AI-powered Online Classrooms Plugin Information Disclosure Unauthenticated BigBlueButton API Secret Disclosure No login needed ≤ 1.0.3 CVE-2026-77007 WPScan
7.5 High BookingPress Plugin Price Manipulation Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation No login needed 1.5.6 – < 1.6.3 Fixed in 1.6.3 CVE-2026-76586 WPScan
8.2 High Profile Builder Plugin Authentication Bypass Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass No login needed 3.8.1 – < 4.0.1 Fixed in 4.0.1 CVE-2026-76548 WPScan
6.6 Medium Profile Builder Plugin PHP Object Injection Admin+ PHP Object Injection via Import/Export 3.3.4 – < 4.0.1 Fixed in 4.0.1 CVE-2026-76547 WPScan
6.8 Medium Profile Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via Format Date Shortcode 3.3.4 – < 4.0.1 Fixed in 4.0.1 CVE-2026-76546 WPScan
5.3 Medium CatFolders Document Gallery Pro Plugin Broken Access Control Unauthenticated Missing Authorization via download-all No login needed 2.0.6 – < 2.0.7 Fixed in 2.0.7 CVE-2026-19430 WPScan
6.5 Medium MStore API Plugin mstore-api Price Manipulation Subscriber+ Arbitrary Order Payment Bypass via Wallet < 4.21.1 Fixed in 4.21.1 CVE-2026-18234 WPScan
6.5 Medium MStore API Plugin mstore-api Broken Access Control Subscriber+ Arbitrary Order Completion < 4.21.1 Fixed in 4.21.1 CVE-2026-18233 WPScan
5.4 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery Arbitrary Plugin Option Update via CSRF No login needed < 4.17 Fixed in 4.17 CVE-2026-17522 WPScan
4.8 Medium Newsletters Plugin newsletters-lite Other Unauthenticated API Access via Predictable API Key No login needed < 4.17 Fixed in 4.17 CVE-2026-17520 WPScan
9.1 Critical Total Processing Card Payments for WooCommerce Plugin Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed ≤ 7.3 CVE-2026-16947 WPScan
7.7 High SmartAIPress Plugin Server-Side Request Forgery Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_image ≤ 1.2.0 CVE-2026-16600 WPScan
9.8 Critical Uix UserCenter Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2026-16259 WPScan
8.6 High Rest Routes Plugin SQL Injection Unauthenticated SQLi via custom-tables/tables/{table_name} No login needed ≤ 5.5.5 CVE-2026-16061 WPScan
9.8 Critical Simple User Registration Plugin Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed ≤ 6.9 CVE-2026-10522 WPScan
5.3 Medium Forminator Plugin forminator Other Other vulnerability Type No login needed ≤ 1.57.1 Fixed in 1.57.2 CVE-2026-82220 Patchstack
7.5 High Simple Payment Plugin simple-payment Broken Access Control No login needed ≤ 2.5.2 Fixed in 2.5.3 CVE-2026-81767 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Broken Access Control ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-81761 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.14.2 Fixed in 3.8.14.3 CVE-2026-81760 Patchstack
5.4 Medium WpEvently Plugin mage-eventpress Broken Access Control ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-81759 Patchstack
7.2 High Rank Math SEO Plugin seo-by-rank-math Remote Code Execution ≤ 1.0.276 Fixed in 1.0.277 CVE-2026-81757 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.9 Fixed in 2.6.0 CVE-2026-81299 Patchstack
7.5 High Smush Image Compression and Optimization Plugin wp-smushit Denial of Service Denial of Service Attack No login needed ≤ 4.2.0 Fixed in 4.3.0 CVE-2026-81285 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only