WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,901–1,950 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 39 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Events Manager Plugin events-manager Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'status', 'private', and 'private_only' Parameters No login needed ≤ 7.4.0 CVE-2026-10627 Wordfence
6.4 Medium Password Protect WordPress Lite Plugin password-protect-page Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.21 CVE-2025-9878 Wordfence
4.3 Medium BetterLinks Plugin betterlinks Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action ≤ 3.1.0 CVE-2026-19801 Wordfence
6.5 Medium Events Manager Plugin events-manager SQL Injection Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter in Event/Location Duplicate Action ≤ 7.4.0 CVE-2026-15023 Wordfence
4.3 Medium WP Courses LMS Plugin wp-courses Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Sensitive Information Disclosure via 'resultID' Parameter ≤ 3.2.29 CVE-2026-10630 Wordfence
7.1 High Stripe Payments Plugin stripe-payments Cross-Site Scripting No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-78282 Patchstack
7.5 High Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads Plugin siteleads Information Disclosure SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-78268 Patchstack
9.8 Critical TranslatePress Plugin translatepress-multilingual Privilege Escalation No login needed ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-78267 Patchstack
6.5 Medium AutomatorWP Plugin automatorwp Broken Access Control ≤ 5.8.3 Fixed in 5.8.4 CVE-2026-78266 Patchstack
9.8 Critical The Events Calendar Plugin the-events-calendar PHP Object Injection No login needed ≤ 6.17.2 Fixed in 6.17.3 CVE-2026-78265 Patchstack
7.1 High Toolset Blocks Plugin toolset-blocks Cross-Site Scripting No login needed ≤ 1.6.26 Fixed in 1.6.27 CVE-2026-78264 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting No login needed ≤ 5.29.2.1 Fixed in 5.29.3 CVE-2026-78263 Patchstack
9.8 Critical WP Project Manager Plugin wedevs-project-manager PHP Object Injection No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-78262 Patchstack
7.3 High WPLegalPages Plugin wplegalpages Authentication Bypass Broken Authentication No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2026-78259 Patchstack
9.8 Critical ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type PHP Object Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - PHP Object Injection No login needed ≤ 2.0.63 CVE-2026-32563 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.0 CVE-2026-32561 Patchstack
8.8 High MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator Plugin magicai-wp Local File Inclusion AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion ≤ 1.4 CVE-2026-32560 Patchstack
9.9 Critical UltimateAI Plugin ultimate_ai Arbitrary File Upload ≤ 3.1.0 CVE-2026-32559 Patchstack
7.1 High Boost Plugin boost Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2026-32556 Patchstack
9.3 Critical Boost Plugin boost SQL Injection No login needed ≤ 2.0.4 CVE-2026-32555 Patchstack
9.3 Critical WooBeWoo Product Filter Pro Plugin woofilter-pro SQL Injection No login needed ≤ 3.1.8 CVE-2026-32554 Patchstack
6.5 Medium Style Kits Plugin analogwp-templates Broken Access Control ≤ 2.6.5 Fixed in 2.6.6 CVE-2026-27364 Patchstack
8.6 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Arbitrary File Deletion No login needed ≤ 3.7.42 Fixed in 3.7.43 CVE-2026-78284 Patchstack
8.1 High Måne Theme mane Local File Inclusion No login needed ≤ 1.7 CVE-2026-66670 Patchstack
9.8 Critical FreightCo Theme freightco PHP Object Injection No login needed ≤ 1.1.15 CVE-2026-66650 Patchstack
9.8 Critical Jawn Theme jawn Privilege Escalation No login needed ≤ 1.4.2 CVE-2026-66648 Patchstack
7.1 High Urna Theme urna Cross-Site Scripting No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2026-66610 Patchstack
9.8 Critical WP Cafe Pro Plugin wpcafe-pro Local File Inclusion No login needed < 3.0.15 Fixed in 3.0.15 CVE-2026-66587 Patchstack
7.5 High WP Cafe Pro Plugin wpcafe-pro Information Disclosure Sensitive Data Exposure No login needed < 3.0.15 Fixed in 3.0.15 CVE-2026-66585 Patchstack
9.8 Critical Affiliate Pro - Affiliate Program for WooCommerce & Plugin wp-wc-affiliate-program Privilege Escalation Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation No login needed ≤ 8.9.1 CVE-2026-32558 Patchstack
9.3 Critical Woo Essential Plugin woo-essential SQL Injection No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-32551 Patchstack
8.5 High WP Project Manager Pro Plugin wedevs-project-manager-business SQL Injection ≤ 4.0.1 CVE-2026-32478 Patchstack
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
7.1 High Brave Conversion Engine (PRO) Plugin bravepopup-pro Cross-Site Scripting No login needed ≤ 0.8.6 Fixed in 0.8.7 CVE-2026-32476 Patchstack
8.5 High ProLancer Element Plugin prolancer-element SQL Injection ≤ 1.4.8 CVE-2026-32471 Patchstack
7.1 High ProLancer Element Plugin prolancer-element Broken Access Control ≤ 1.4.8 CVE-2026-28190 Patchstack
8.6 High WooCommerce File Approval Plugin woocommerce-file-approval Arbitrary File Deletion No login needed ≤ 10.7 CVE-2026-28171 Patchstack
7.5 High Super Forms Plugin super-forms Path Traversal Arbitrary File Download No login needed ≤ 6.3.315 CVE-2026-28167 Patchstack
7.1 High Tourmaster Plugin tourmaster Cross-Site Scripting No login needed ≤ 5.4.9 CVE-2026-28166 Patchstack
9.8 Critical Digits Plugin digits Privilege Escalation No login needed ≤ 9.2 CVE-2026-28165 Patchstack
7.1 High Events Made Easy Plugin events-made-easy Cross-Site Scripting No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2026-28162 Patchstack
7.5 High Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Plugin notification-master Broken Access Control Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 CVE-2026-28153 Patchstack
8.1 High Tonda Core Plugin tonda-core Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28152 Patchstack
8.1 High Tonda Theme tonda Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28151 Patchstack
8.1 High Verdure Core Plugin verdure-core Local File Inclusion No login needed ≤ 1.2 CVE-2026-66671 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.8.6 Fixed in 1.8.7 CVE-2026-78290 Patchstack
4.3 Medium Hash Form Plugin hash-form Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2026-78280 Patchstack
5.4 Medium Fluent Support Pro Plugin fluent-support-pro Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-78279 Patchstack
5.3 Medium Fluent Boards Pro Plugin fluent-boards-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78278 Patchstack
4.9 Medium FluentCRM Pro Plugin fluentcampaign-pro Server-Side Request Forgery ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78277 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only