WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,701–1,750 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Keep Backup Daily | Information Disclosure Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_process No login needed |
< 2.1.4 Fixed in 2.1.4 |
CVE-2026-75133 |
VulnCheck | |
| 8.1 High | ProfilePress | Remote Code Execution ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE No login needed |
< 4.17.2 Fixed in 4.17.2 |
CVE-2026-66047 |
VulnCheck | |
| 10.0 Critical | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent | Arbitrary File Upload No login needed |
≤ 4.4.1 Fixed in 4.4.2 |
CVE-2026-82970 |
Patchstack | |
| 5.3 Medium | bbPress | Broken Access Control No login needed |
≤ 2.6.14 |
CVE-2026-74010 |
Patchstack | |
| 5.3 Medium | Icollect | Broken Access Control Unauthenticated User and Term Creation via Unrestricted Method Dispatch No login needed |
≤ 1.0.0 |
CVE-2026-77013 |
WPScan | |
| 6.6 Medium | Really Simple Security | Remote Code Execution Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_plugin |
< 9.8.0 Fixed in 9.8.0 |
CVE-2026-81766 |
WPScan | |
| 8.8 High | Groundhogg | Cross-Site Scripting Unauthenticated Stored XSS via Web Form Dropdown/Radio Field No login needed |
< 4.5.13 Fixed in 4.5.13 |
CVE-2026-81660 |
WPScan | |
| 3.5 Low | MW WP Form | Cross-Site Scripting Editor+ Stored XSS via Inquiry Data List |
< 5.1.6 Fixed in 5.1.6 |
CVE-2026-78364 |
WPScan | |
| 8.8 High | Customer Reviews for WooCommerce | Cross-Site Scripting Unauthenticated Stored XSS via 'comment' Parameter No login needed |
< 5.118.0 Fixed in 5.118.0 |
CVE-2026-76585 |
WPScan | |
| 6.6 Medium | WPvivid Backup & Migration | Path Traversal Admin+ Arbitrary File Write via Zip Slip in Backup Restore |
< 0.9.133 Fixed in 0.9.133 |
CVE-2026-19722 |
WPScan | |
| 7.1 High | Geotargeting WP | Cross-Site Scripting Reflected XSS No login needed |
< 3.5.6.2 Fixed in 3.5.6.2 |
CVE-2026-14307 |
WPScan | |
| 6.8 Medium | SOGO Add Script to Individual Pages Header Footer | Cross-Site Scripting Contributor+ Stored XSS via Post Metabox |
≤ 3.9 |
CVE-2026-14835 |
WPScan | |
| 9.8 Critical | MyHome Core | Authentication Bypass Authentication Bypass to Account Takeover via Activation Token No login needed |
≤ 4.4.5 |
CVE-2026-15980 |
Wordfence | |
| 9.8 Critical | Custom User Registration Fields for WooCommerce | Privilege Escalation Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout No login needed |
≤ 2.2.3 |
CVE-2026-15369 |
Wordfence | |
| 7.5 High | SAML Single Sign On | Authentication Bypass Unauthenticated Authentication Bypass via X.509 Certificate Poisoning No login needed |
≤ 5.4.6 |
CVE-2026-75807 |
Wordfence | |
| 9.8 Critical | Sigma Forms Pro | Arbitrary File Upload Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field No login needed |
≤ 1.4.5 |
CVE-2026-14494 |
Wordfence | |
| 4.3 Medium | Frontend Admin by DynamiApps | Broken Access Control Subscriber+ Arbitrary Membership Plan Deletion |
< 3.29.11 Fixed in 3.29.11 |
CVE-2026-81346 |
WPScan | |
| 4.7 Medium | MasterStudy LMS | Open Redirect Unauthenticated Open Redirect No login needed |
< 3.7.43 Fixed in 3.7.43 |
CVE-2026-81342 |
WPScan | |
| 2.7 Low | MasterStudy LMS | Information Disclosure Instructor+ Cross-Tenant Order Billing PII Disclosure via IDOR |
< 3.7.42 Fixed in 3.7.42 |
CVE-2026-81200 |
WPScan | |
| 4.8 Medium | MasterStudy LMS | Price Manipulation Unauthenticated Payment Bypass via PayPal IPN No login needed |
< 3.7.40 Fixed in 3.7.40 |
CVE-2026-81026 |
WPScan | |
| 4.1 Medium | WP Ultimate CSV Importer | SQL Injection Admin+ SQLi via AIOSEO Import Fields |
< 9.0 Fixed in 9.0 |
CVE-2026-80488 |
WPScan | |
| 4.3 Medium | Stripe Payment Forms by WP Full Pay | Broken Access Control Cross-Customer Subscription Cancellation via IDOR |
< 8.5.5 Fixed in 8.5.5 |
CVE-2026-80311 |
WPScan | |
| 4.9 Medium | Rank Math SEO | Broken Access Control Editor+ Core Settings Modification via fix-site-seo Ability |
1.0.271 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77786 |
WPScan | |
| 2.7 Low | Amelia | Broken Access Control Amelia Customer+ Appointment Status Update and Self-Approval |
1.2.32 – < 2.4.9 Fixed in 2.4.9 |
CVE-2026-77704 |
WPScan | |
| 9.3 Critical | Icollect | Path Traversal Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password No login needed |
≤ 1.0.0 |
CVE-2026-77012 |
WPScan | |
| 6.5 Medium | HEL Online Classroom: AI-powered Online Classrooms | Information Disclosure Unauthenticated Moderator Join URL Disclosure and Class Access Code Bypass No login needed |
≤ 1.0.3 |
CVE-2026-77010 |
WPScan | |
| 6.5 Medium | HEL Online Classroom: AI-powered Online Classrooms | Broken Access Control Unauthenticated Plugin Settings Update No login needed |
≤ 1.0.3 |
CVE-2026-77008 |
WPScan | |
| 7.5 High | HEL Online Classroom: AI-powered Online Classrooms | Information Disclosure Unauthenticated BigBlueButton API Secret Disclosure No login needed |
≤ 1.0.3 |
CVE-2026-77007 |
WPScan | |
| 7.5 High | BookingPress | Price Manipulation Unauthenticated Booking Price Manipulation via PayPal Payment Confirmation No login needed |
1.5.6 – < 1.6.3 Fixed in 1.6.3 |
CVE-2026-76586 |
WPScan | |
| 8.2 High | Profile Builder | Authentication Bypass Unauthenticated Unpublished Content and Media Modification via Front-End Upload Auth Bypass No login needed |
3.8.1 – < 4.0.1 Fixed in 4.0.1 |
CVE-2026-76548 |
WPScan | |
| 6.6 Medium | Profile Builder | PHP Object Injection Admin+ PHP Object Injection via Import/Export |
3.3.4 – < 4.0.1 Fixed in 4.0.1 |
CVE-2026-76547 |
WPScan | |
| 6.8 Medium | Profile Builder | Cross-Site Scripting Contributor+ Stored XSS via Format Date Shortcode |
3.3.4 – < 4.0.1 Fixed in 4.0.1 |
CVE-2026-76546 |
WPScan | |
| 5.3 Medium | CatFolders Document Gallery Pro | Broken Access Control Unauthenticated Missing Authorization via download-all No login needed |
2.0.6 – < 2.0.7 Fixed in 2.0.7 |
CVE-2026-19430 |
WPScan | |
| 6.5 Medium | MStore API | Price Manipulation Subscriber+ Arbitrary Order Payment Bypass via Wallet |
< 4.21.1 Fixed in 4.21.1 |
CVE-2026-18234 |
WPScan | |
| 6.5 Medium | MStore API | Broken Access Control Subscriber+ Arbitrary Order Completion |
< 4.21.1 Fixed in 4.21.1 |
CVE-2026-18233 |
WPScan | |
| 5.4 Medium | Newsletters | Cross-Site Request Forgery Arbitrary Plugin Option Update via CSRF No login needed |
< 4.17 Fixed in 4.17 |
CVE-2026-17522 |
WPScan | |
| 4.8 Medium | Newsletters | Other Unauthenticated API Access via Predictable API Key No login needed |
< 4.17 Fixed in 4.17 |
CVE-2026-17520 |
WPScan | |
| 9.1 Critical | Total Processing Card Payments for WooCommerce | Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed |
≤ 7.3 |
CVE-2026-16947 |
WPScan | |
| 7.7 High | SmartAIPress | Server-Side Request Forgery Subscriber+ Server-Side Request Forgery via smartaipress_openai_upload_and_set_featured_image |
≤ 1.2.0 |
CVE-2026-16600 |
WPScan | |
| 9.8 Critical | Uix UserCenter | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.0.3 |
CVE-2026-16259 |
WPScan | |
| 8.6 High | Rest Routes | SQL Injection Unauthenticated SQLi via custom-tables/tables/{table_name} No login needed |
≤ 5.5.5 |
CVE-2026-16061 |
WPScan | |
| 9.8 Critical | Simple User Registration | Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed |
≤ 6.9 |
CVE-2026-10522 |
WPScan | |
| 5.3 Medium | Forminator | Other Other vulnerability Type No login needed |
≤ 1.57.1 Fixed in 1.57.2 |
CVE-2026-82220 |
Patchstack | |
| 7.5 High | Simple Payment | Broken Access Control No login needed |
≤ 2.5.2 Fixed in 2.5.3 |
CVE-2026-81767 |
Patchstack | |
| 4.3 Medium | WpEvently | Broken Access Control |
≤ 5.5.0 Fixed in 5.6.0 |
CVE-2026-81761 |
Patchstack | |
| 7.1 High | JetEngine | Cross-Site Scripting No login needed |
≤ 3.8.14.2 Fixed in 3.8.14.3 |
CVE-2026-81760 |
Patchstack | |
| 5.4 Medium | WpEvently | Broken Access Control |
≤ 5.5.0 Fixed in 5.6.0 |
CVE-2026-81759 |
Patchstack | |
| 7.2 High | Rank Math SEO | Remote Code Execution |
≤ 1.0.276 Fixed in 1.0.277 |
CVE-2026-81757 |
Patchstack | |
| 4.3 Medium | WP Job Portal | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 2.5.9 Fixed in 2.6.0 |
CVE-2026-81299 |
Patchstack | |
| 7.5 High | Smush Image Compression and Optimization | Denial of Service Denial of Service Attack No login needed |
≤ 4.2.0 Fixed in 4.3.0 |
CVE-2026-81285 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.