WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,901–1,950 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 39 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium List category posts Plugin list-category-posts Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute ≤ 0.95.0 CVE-2026-12434 Wordfence
4.4 Medium MxChat Plugin mxchat-basic Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting ≤ 3.2.10 CVE-2026-13005 Wordfence
5.5 Medium Kali Forms Plugin Information Disclosure Contributor+ Arbitrary Post Metadata Disclosure via IDOR < 2.4.17 Fixed in 2.4.17 CVE-2026-11580 WPScan
5.3 Medium Kali Forms Plugin Arbitrary File Upload Unauthenticated Media Upload No login needed < 2.4.17 Fixed in 2.4.17 CVE-2026-11579 WPScan
4.3 Medium Academy LMS Plugin academy Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter ≤ 3.8.0 CVE-2026-9341 Wordfence
6.4 Medium WP 2FA Plugin wp-2fa Privilege Escalation Account Takeover via 2FA Setup Email Binding < 3.1.1.2 Fixed in 3.1.1.2 CVE-2026-12988 WPScan
5.9 Medium SureForms Plugin sureforms Broken Access Control Unauthenticated Payment Amount Bypass No login needed < 2.11.1 Fixed in 2.11.1 CVE-2026-11567 WPScan
5.4 Medium BEAF Plugin Cross-Site Scripting Admin+ Stored XSS via Widget Shortcode Field < 4.7.1 Fixed in 4.7.1 CVE-2025-15665 WPScan
6.4 Medium News Kit Addons For Elementor Plugin news-kit-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets ≤ 1.4.6 CVE-2026-11390 Wordfence
6.4 Medium WP Customer Area Plugin customer-area Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute ≤ 8.3.5 CVE-2026-7640 Wordfence
5.3 Medium FoodBook Lite Plugin foodbook-light-online-food-ordering-system Broken Access Control Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action No login needed ≤ 1.5.6 CVE-2026-11802 Wordfence
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title ≤ 3.15.5 CVE-2026-12536 Wordfence
4.3 Medium Smart Slider 3 Plugin smart-slider-3 Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter ≤ 3.5.1.37 CVE-2026-12385 Wordfence
5.3 Medium Car Rental Manager Plugin car-rental-manager Broken Access Control No login needed ≤ 1.3.7 Fixed in 1.3.8 CVE-2026-61985 Patchstack
5.3 Medium Church Admin Plugin church-admin Broken Access Control No login needed ≤ 5.0.30 Fixed in 5.1.0 CVE-2026-61983 Patchstack
5.3 Medium JetSearch Plugin jet-search Information Disclosure Sensitive Data Exposure No login needed ≤ 3.6.1.2 Fixed in 3.6.1.3 CVE-2026-61977 Patchstack
5.3 Medium JetBlocks For Elementor Plugin jet-blocks Information Disclosure Sensitive Data Exposure No login needed ≤ 1.5.0 Fixed in 1.5.0.1 CVE-2026-61976 Patchstack
5.3 Medium JetReviews Plugin jet-reviews Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.1 Fixed in 3.1.0 CVE-2026-61975 Patchstack
4.9 Medium Auto Featured Image (Auto Post Thumbnail) Plugin auto-post-thumbnail Server-Side Request Forgery ≤ 5.0.4 Fixed in 5.0.5 CVE-2026-61970 Patchstack
5.4 Medium myCred Plugin mycred Broken Access Control ≤ 3.1.2 Fixed in 3.2.0 CVE-2026-61968 Patchstack
5.4 Medium License Manager for WooCommerce Plugin license-manager-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 3.0.17 Fixed in 3.0.18 CVE-2026-61958 Patchstack
4.9 Medium WooCommerce Bulk Edit Products – WP Sheet Editor Plugin woo-bulk-edit-products Broken Access Control WP Sheet Editor plugin <= 1.8.21 - Broken Access Control ≤ 1.8.21 Fixed in 1.8.22 CVE-2026-61952 Patchstack
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.11.11 Fixed in 1.6.12.0 CVE-2026-59523 Patchstack
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.12.4 Fixed in 1.6.12.6 CVE-2026-57812 Patchstack
4.3 Medium EduMall Theme edumall Broken Access Control ≤ 4.5.1 Fixed in 4.5.2 CVE-2026-57797 Patchstack
6.5 Medium Speaker Plugin speaker Cross-Site Scripting ≤ 4.1.13 CVE-2026-57783 Patchstack
5.3 Medium Universal Clocks Plugin universal-clocks Broken Access Control No login needed ≤ 1.2.0 CVE-2026-57782 Patchstack
5.3 Medium MeetingHub Plugin meetinghub Broken Access Control No login needed ≤ 1.25.10 CVE-2026-57781 Patchstack
6.5 Medium Envision Page Builder Plugin envision-page-builder Cross-Site Scripting ≤ 0.22 CVE-2026-57780 Patchstack
5.3 Medium Fascinate Plugin fascinate Broken Access Control No login needed ≤ 1.1.5 CVE-2026-57779 Patchstack
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control No login needed ≤ 3.2.36 CVE-2026-57778 Patchstack
5.3 Medium VW Wedding Plugin vw-wedding Broken Access Control No login needed ≤ 1.3.7 CVE-2026-57776 Patchstack
5.3 Medium VW Food Corner Plugin vw-food-corner Broken Access Control No login needed ≤ 1.1.0 CVE-2026-57774 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.4.8 Fixed in 3.4.9 CVE-2026-57711 Patchstack
6.5 Medium Abandoned Cart Recovery for WooCommerce Plugin woo-abandoned-cart-recovery Authentication Bypass Broken Authentication No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2026-57698 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.13 Fixed in 3.9.14 CVE-2026-57694 Patchstack
6.5 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting ≤ 2.8.11 Fixed in 2.8.12 CVE-2026-57693 Patchstack
5.8 Medium Anti-Malware Security and Brute-Force Firewall Plugin gotmls Cross-Site Scripting No login needed ≤ 4.23.89 Fixed in 4.23.90 CVE-2026-57691 Patchstack
6.5 Medium Razorpay Payment Links for WooCommerce Plugin rzp-woocommerce Broken Access Control No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57424 Patchstack
6.5 Medium Author Box WP Lens Plugin author-box-for-divi Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-57420 Patchstack
6.5 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 3.1.8 Fixed in 3.1.9 CVE-2026-57419 Patchstack
6.5 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control ≤ 20.8.13 Fixed in 20.8.14 CVE-2026-57418 Patchstack
6.5 Medium ChatBot for eCommerce – WoowBot Plugin woowbot-woocommerce-chatbot Cross-Site Scripting WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) ≤ 4.6.1 Fixed in 4.7.0 CVE-2026-57414 Patchstack
6.4 Medium Instant Image Generator Plugin ai-image Server-Side Request Forgery ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57413 Patchstack
6.5 Medium Gift Vouchers Plugin gift-voucher Broken Access Control No login needed ≤ 4.6.9 Fixed in 4.7.0 CVE-2026-57412 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2026-57408 Patchstack
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-57406 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2026-57404 Patchstack
6.5 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Cross-Site Scripting ≤ 1.0.51 Fixed in 1.0.52 CVE-2026-57402 Patchstack
6.5 Medium Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-57400 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only