WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,851–1,900 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Stripe Payment Forms by WP Full Pay | Information Disclosure Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed Session No login needed |
< 8.5.1 Fixed in 8.5.1 |
CVE-2026-77758 |
WPScan | |
| 5.4 Medium | Directorist | Path Traversal Subscriber+ Arbitrary Image Move via REST v2 Listing Submission |
8.5 – < 8.9.3 Fixed in 8.9.3 |
CVE-2026-77757 |
WPScan | |
| 5.3 Medium | Kirki | Information Disclosure Unauthenticated User and Comment Author Email Disclosure via kirki_get_apis No login needed |
< 6.0.14 Fixed in 6.0.14 |
CVE-2026-77754 |
WPScan | |
| 6.5 Medium | Woo Refund And Exchange Lite | Information Disclosure Unauthenticated Guest Order Message Disclosure and Manipulation No login needed |
4.4.6 – < 4.6.4 Fixed in 4.6.4 |
CVE-2026-77695 |
WPScan | |
| 5.3 Medium | Eventin | Broken Access Control Unauthenticated Order Completion Without Payment via order_token No login needed |
< 4.1.19 Fixed in 4.1.19 |
CVE-2026-77694 |
WPScan | |
| 8.7 High | Order Tip for WooCommerce | Arbitrary File Deletion Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax |
< 1.6.0 Fixed in 1.6.0 |
CVE-2026-77693 |
WPScan | |
| 5.3 Medium | AI Engine | Broken Access Control Unauthenticated Arbitrary AI Query Execution via Editor Assistant No login needed |
3.4.0 – < 3.7.2 Fixed in 3.7.2 |
CVE-2026-75798 |
WPScan | |
| 7.7 High | AI Engine | Path Traversal Subscriber+ Arbitrary File Read via 'url' Parameter |
3.3.3 – < 3.7.2 Fixed in 3.7.2 |
CVE-2026-75797 |
WPScan | |
| 4.3 Medium | WP Project Manager | Information Disclosure Subscriber+ User Activity Feed Disclosure via IDOR |
2.2.0 – < 4.0.7 Fixed in 4.0.7 |
CVE-2026-74930 |
WPScan | |
| 5.4 Medium | WP Project Manager | Information Disclosure Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDOR |
< 4.0.7 Fixed in 4.0.7 |
CVE-2026-74929 |
WPScan | |
| 7.5 High | WP Project Manager | Broken Access Control Unauthenticated Subscriber Account Creation via Trello Import Routes No login needed |
2.1.0 – < 4.0.7 Fixed in 4.0.7 |
CVE-2026-74928 |
WPScan | |
| 7.2 High | Pods | Remote Code Execution Author+ RCE via Shortcode Display Callback |
3.1.0 – < 3.3.9.1 Fixed in 3.3.9.1 |
CVE-2026-74851 |
WPScan | |
| 8.1 High | BlogVault, MalCare and WP Remote | Authentication Bypass Unauthenticated Site Takeover via Connection Key Recovery No login needed |
5.16 – < 6.65 Fixed in 6.65 |
CVE-2026-19718 |
WPScan | |
| 6.8 Medium | Royal Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Image Accordion Widget Effect Settings |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-19226 |
WPScan | |
| 3.7 Low | Forminator Forms | Privilege Escalation Unauthenticated Multisite Site Creation and Privilege Escalation No login needed |
< 1.57.1 Fixed in 1.57.1 |
CVE-2026-19220 |
WPScan | |
| 5.3 Medium | Tutor LMS | SQL Injection Unauthenticated SQLi via 'offset' and 'item_per_page' Parameters No login needed |
4.0.0 – < 4.0.6 Fixed in 4.0.6 |
CVE-2026-19094 |
WPScan | |
| 5.3 Medium | Booking Package | Price Manipulation Unauthenticated Price Manipulation via Service and Option Cost Parameters No login needed |
< 1.7.25 Fixed in 1.7.25 |
CVE-2026-16986 |
WPScan | |
| 6.5 Medium | WP Legal Pages | Information Disclosure Unauthenticated API Secret Disclosure No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2026-16984 |
WPScan | |
| 5.3 Medium | WPCafe | Broken Access Control Unauthenticated Reservation Approval Bypass via Missing Authorization No login needed |
< 3.0.18 Fixed in 3.0.18 |
CVE-2026-14550 |
WPScan | |
| 6.5 Medium | Amelia | Authentication Bypass Unauthenticated Notification Queue Dispatch No login needed |
< 2.4.7 Fixed in 2.4.7 |
CVE-2026-14216 |
WPScan | |
| 4.7 Medium | Amelia Pro | Broken Access Control Provider+ Arbitrary Provider Password Update via IDOR |
9.0 – < 9.8 Fixed in 9.8 |
CVE-2026-14212 |
WPScan | |
| 5.3 Medium | Royal Elementor Addons | Information Disclosure Unauthenticated Taxonomy Term Disclosure No login needed |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-13406 |
WPScan | |
| 5.3 Medium | Royal Elementor Addons | Broken Access Control Unauthenticated Like Count and IP Meta Modification via wpr_likes_init No login needed |
< 1.7.1066 Fixed in 1.7.1066 |
CVE-2026-13404 |
WPScan | |
| 5.3 Medium | Eventin | Information Disclosure Unauthenticated Unpublished Content Disclosure No login needed |
< 4.1.22 Fixed in 4.1.22 |
CVE-2026-13172 |
WPScan | |
| 7.2 High | WP Fastest Cache | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via HTTP Host Header No login needed |
≤ 1.5.0 |
CVE-2026-19760 |
Wordfence | |
| 9.8 Critical | TranslatePress – Multilingual | Privilege Escalation Multilingual <= 3.3.1 - Unauthenticated Account Takeover via Password Reset Link Disclosure No login needed |
≤ 3.3.1 |
CVE-2026-19632 |
Wordfence | |
| 7.5 High | WP Fastest Cache | Cross-Site Scripting Unauthenticated Stored XSS via Host Header Cache Poisoning No login needed |
0.9.0.3 – < 1.5.1 Fixed in 1.5.1 |
CVE-2026-74932 |
WPScan | |
| 4.9 Medium | Media Sweep | SQL Injection Authenticated (Administrator+) SQL Injection via 'fields' Parameter |
≤ 1.1.3 |
CVE-2026-77824 |
Wordfence | |
| 6.4 Medium | Ultimate Member | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) |
≤ 2.12.1 |
CVE-2026-18547 |
Wordfence | |
| 7.2 High | ShopEngine Elementor WooCommerce Builder Addon | Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes |
≤ 4.9.4 |
CVE-2026-75971 |
Wordfence | |
| 8.8 High | All-in-One WP Migration and Backup | SQL Injection Unauthenticated Second-Order SQL Injection via Archive Restore to Remote Code Execution |
≤ 7.109 |
CVE-2026-19949 |
Wordfence | |
| 5.3 Medium | My Agile Privacy® | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification via map_missing_cookie_shield / map_check_consent_mode_status AJAX Actions No login needed |
≤ 3.3.6 |
CVE-2026-17587 |
Wordfence | |
| 4.3 Medium | Newsletters | Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary Modification via 'newsletters_mailinglistsroles' POST Parameter |
≤ 4.17 |
CVE-2026-75908 |
Wordfence | |
| 6.4 Medium | eCommerce Product Catalog | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute |
≤ 3.5.10 |
CVE-2026-76128 |
Wordfence | |
| 6.4 Medium | TranslatePress | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Approved Comment Body in Translation Editor |
≤ 3.2.6 |
CVE-2026-18512 |
Wordfence | |
| 7.2 High | Forminator Forms | Cross-Site Scripting Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter No login needed |
≤ 1.57.0 |
CVE-2026-18328 |
Wordfence | |
| 7.2 High | Forminator Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) No login needed |
≤ 1.57.0.2 |
CVE-2026-18323 |
Wordfence | |
| 6.4 Medium | MetForm | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_id' Widget Setting |
≤ 4.1.8 |
CVE-2026-18100 |
Wordfence | |
| 8.8 High | CM Map Locations | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via cmloc_route_image_upload AJAX Action |
≤ 2.1.8 |
CVE-2026-16601 |
Wordfence | |
| 8.1 High | MÃ¥ne | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 1.7 |
CVE-2026-78478 |
Wordfence | |
| 6.5 Medium | WP Project Manager Pro | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 4.0.1 |
CVE-2026-78470 |
Wordfence | |
| 6.4 Medium | tagDiv Composer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.4.5 |
CVE-2026-12561 |
Wordfence | |
| 6.4 Medium | Gutenverse | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute |
≤ 4.0.2 |
CVE-2026-19943 |
Wordfence | |
| 6.6 Medium | Events Manager | Local File Inclusion Authenticated (Administrator+) Local File Inclusion via 'dbem_data[updates]' Array Keys |
≤ 7.3.7.4 |
CVE-2026-14280 |
Wordfence | |
| 6.4 Medium | FundEngine | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' Parameter |
≤ 1.8.1 |
CVE-2026-76063 |
Wordfence | |
| 6.1 Medium | Events Manager | Cross-Site Scripting Reflected Cross-Site Scripting via 'header_format' Parameter No login needed |
≤ 7.4.0.1 |
CVE-2026-17089 |
Wordfence | |
| 4.3 Medium | FundEngine | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'campaign_post' Parameter |
≤ 1.8.1 |
CVE-2026-75930 |
Wordfence | |
| 8.8 High | InfusedWoo Pro | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Password Reset Link Disclosure |
≤ 5.1.17 |
CVE-2026-19892 |
Wordfence | |
| 6.4 Medium | Cozy Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cozyHoverEffect Block Attribute |
≤ 2.2.16 |
CVE-2026-75019 |
Wordfence | |
| 4.4 Medium | LearnPress | Broken Access Control Missing Authorization to Authenticated (Editor+) Limited Option Update via 'field_name' Parameter |
≤ 4.4.4 |
CVE-2026-75982 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.