WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,801–1,850 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 37 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Music Player for WooCommerce Plugin music-player-for-woocommerce Cross-Site Scripting No login needed ≤ 1.8.9 Fixed in 1.9.0 CVE-2026-78283 Patchstack
7.1 High CP Media Player Plugin audio-and-video-player Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-78281 Patchstack
7.2 High Fluent Boards Pro Plugin fluent-boards-pro PHP Object Injection ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78276 Patchstack
6.8 Medium Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Deletion ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78275 Patchstack
9.1 Critical Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Upload ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78274 Patchstack
6.5 Medium Fluent Boards Pro Plugin fluent-boards-pro Cross-Site Scripting ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78273 Patchstack
7.2 High FluentCRM Pro Plugin fluentcampaign-pro Privilege Escalation ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78271 Patchstack
7.1 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.2 CVE-2026-78261 Patchstack
9.3 Critical Epayco Plugin epayco-gateway SQL Injection No login needed ≤ 8.4.6 Fixed in 8.4.7 CVE-2026-78260 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type Privilege Escalation Custom Post Types Plugin for WordPress plugin <= 2.0.63 - Privilege Escalation No login needed ≤ 2.0.63 CVE-2026-32566 Patchstack
8.5 High ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type SQL Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection ≤ 2.0.63 CVE-2026-32564 Patchstack
8.5 High Kadence Shop Kit Plugin kadence-shop-kit SQL Injection ≤ 3.0.6 Fixed in 3.0.6.1 CVE-2026-32550 Patchstack
9.3 Critical Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro SQL Injection No login needed ≤ 11.17 Fixed in 11.18 CVE-2026-32479 Patchstack
8.6 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Broken Access Control No login needed ≤ 0.4.62 Fixed in 0.4.63 CVE-2026-27330 Patchstack
5.4 Medium Push Notification for Post and BuddyPress Plugin push-notification-for-post-and-buddypress Broken Access Control ≤ 3.20 Fixed in 3.21 CVE-2026-81279 Patchstack
8.8 High 12 Step Meeting List Plugin 12-step-meeting-list Cross-Site Scripting Unauthenticated Stored XSS via Geocode Event Log No login needed 3.17 – < 3.19.17 Fixed in 3.19.17 CVE-2026-78333 WPScan
4.3 Medium Notifima Plugin woocommerce-product-stock-alert Broken Access Control Subscriber+ Stock Alert Unsubscription via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-78139 WPScan
4.3 Medium Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Information Disclosure Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html < 2.21.0 Fixed in 2.21.0 CVE-2026-78138 WPScan
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce Plugin Price Manipulation Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart No login needed < 2.1.2 Fixed in 2.1.2 CVE-2026-78137 WPScan
5.3 Medium LearnPress – Sepay Payment Plugin learnpress-sepay-payment Information Disclosure Sepay Payment < 4.0.3 - Unauthenticated Order Status Disclosure No login needed < 4.0.3 Fixed in 4.0.3 CVE-2026-78125 WPScan
8.8 High Workeera Remote Tech Job Board Plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload via Candidate Profile Mass Assignment < 1.0.6 Fixed in 1.0.6 CVE-2026-77018 WPScan
7.7 High Workeera Remote Tech Job Board Plugin Path Traversal Subscriber+ Arbitrary File Read via Candidate Profile Mass Assignment < 1.0.6 Fixed in 1.0.6 CVE-2026-77017 WPScan
9.6 Critical Workeera Remote Tech Job Board Plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Candidate Profile Mass Assignment < 1.0.6 Fixed in 1.0.6 CVE-2026-77016 WPScan
5.9 Medium UpdraftPlus Plugin Cross-Site Request Forgery Backup Restoration via CSRF No login needed < 1.26.7 Fixed in 1.26.7 CVE-2026-76549 WPScan
7.5 High WP OAuth Server Plugin Information Disclosure Unauthenticated OAuth Token and User Data Disclosure via Debug Log File No login needed < 6.3.1 Fixed in 6.3.1 CVE-2026-19715 WPScan
4.4 Medium JetBackup Plugin backup Broken Access Control Admin+ Multisite Network Backup Download 3.1.18.8 – < 3.1.23.5 Fixed in 3.1.23.5 CVE-2026-19454 WPScan
6.6 Medium Defender Security Plugin defender-security Remote Code Execution Admin+ Network-Wide RCE via Hub Connector on Multisite 5.0.0 – < 6.2.0 Fixed in 6.2.0 CVE-2026-19225 WPScan
7.2 High Smush Plugin wp-smushit Remote Code Execution Admin+ Network-Wide RCE via Hub Connector on Multisite 3.22.1 – < 4.3.2 Fixed in 4.3.2 CVE-2026-19223 WPScan
4.3 Medium ShopApper Plugin Broken Access Control Subscriber+ Arbitrary Product Stock Update ≤ 0.4.62 CVE-2026-16569 WPScan
4.3 Medium ShopApper Plugin Information Disclosure Subscriber+ Customer Data Disclosure via IDOR ≤ 0.4.62 CVE-2026-16568 WPScan
5.3 Medium Document Embedder Plugin document-emberdder Broken Access Control Unauthenticated Private Document Download via Token Oracle No login needed < 2.3.1 Fixed in 2.3.1 CVE-2026-16567 WPScan
3.5 Low CMP - Coming Soon & Maintenance Plugin Cross-Site Scripting Coming Soon & Maintenance < 4.1.18 - Editor+ Stored XSS via niteoCS_socialmedia < 4.1.18 Fixed in 4.1.18 CVE-2026-13416 WPScan
7.2 High CMP - Coming Soon & Maintenance Plugin Privilege Escalation Coming Soon & Maintenance < 4.1.18 - Editor+ Privilege Escalation via cmp_ajax_import_settings < 4.1.18 Fixed in 4.1.18 CVE-2026-13415 WPScan
4.8 Medium CMP - Coming Soon & Maintenance Plugin Broken Access Control Coming Soon & Maintenance < 4.1.18 - Unauthenticated Maintenance Mode Disable via cmp_disable_comingsoon_ajax No login needed < 4.1.18 Fixed in 4.1.18 CVE-2026-13414 WPScan
7.5 High Formidable Charts Plugin Path Traversal Unauthenticated Arbitrary File Read via 'frm_graph' Parameter No login needed ≤ 2.0.1 CVE-2026-15990 Wordfence
8.1 High Classified Listing - Mobile Number Verification Plugin Authentication Bypass Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login No login needed ≤ 1.6.0 CVE-2026-15985 Wordfence
9.8 Critical ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce Plugin erp Arbitrary File Upload Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment No login needed ≤ 1.17.8 CVE-2026-18080 Wordfence
5.3 Medium WP Data Access – No-Code App Builder with Tables, Forms, Charts & Maps Plugin wp-data-access Broken Access Control No-Code App Builder with Tables, Forms, Charts & Maps <= 5.5.68 - Unauthenticated Insecure Direct Object Reference to Data Access No login needed ≤ 5.5.68 CVE-2026-3235 Wordfence
6.4 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Data URI ≤ 12.8.9 CVE-2026-5092 Wordfence
6.4 Medium Reviews and Rating – Google Reviews Plugin g-business-reviews-rating Cross-Site Scripting Google Reviews <= 5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 5.10 CVE-2026-2388 Wordfence
8.8 High Mang Board WP Plugin mangboard Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Forged Authentication Cookie ≤ 2.3.7 CVE-2026-75977 Wordfence
7.5 High WooCommerce Lottery Plugin woocommerce-lottery SQL Injection Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters No login needed ≤ 2.2.9 CVE-2026-18884 Wordfence
6.4 Medium Betheme Theme betheme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon_box_2' Shortcode ≤ 28.4 CVE-2026-6178 Wordfence
9.8 Critical Avada Theme Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary File Write No login needed ≤ 3.16, ≤ 7.16 CVE-2026-18431 Wordfence
7.2 High Formidable Forms Plugin formidable Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'frm_user_id' Parameter No login needed ≤ 6.33.1 CVE-2026-18331 Wordfence
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks ≤ 4.0.2 CVE-2026-3002 Wordfence
6.5 Medium Noptin Plugin Information Disclosure Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Page No login needed 4.0.0 – < 4.3.3 Fixed in 4.3.3 CVE-2026-78146 WPScan
5.5 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager SQL Injection Admin+ SQLi via 'rm_sortby' Parameter < 6.0.9.4 Fixed in 6.0.9.4 CVE-2026-77790 WPScan
4.3 Medium Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Broken Access Control Cross-Customer Subscription Modification via IDOR < 8.5.1 Fixed in 8.5.1 CVE-2026-77789 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only