WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 151–200 of 29,007 vulnerabilities

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Icon Library Parameter < 2.0.21 Fixed in 2.0.21 CVE-2026-85016 WPScan
5.3 Medium Request a Quote Plugin get-a-quote-button-for-woocommerce Information Disclosure Unauthenticated Quote Request Contact Record Disclosure via emd_get_std_pagenum No login needed ≤ 2.5.6 CVE-2026-90988 WPScan
4.3 Medium Popup Maker WP Plugin Broken Access Control Subscriber+ Missing Authorization via sgpm_connect ≤ 1.4.5 CVE-2026-85004 WPScan
5.3 Medium Paytm Payment Gateway Plugin paytm-payments Authentication Bypass Unauthenticated Order Status Manipulation via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81740 WPScan
6.8 Medium Tabs Responsive Plugin Cross-Site Scripting Shop Manager+ Stored XSS via WooCommerce Product Tab Content ≤ 2.5 CVE-2026-13718 WPScan
5.4 Medium Autoptimize Plugin autoptimize Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Author Name No login needed ≤ 3.1.15.1 CVE-2026-78471 Wordfence
9.1 Critical Super Forms Plugin Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter No login needed ≤ 6.3.316 CVE-2026-15896 Wordfence
7.5 High SiteOrigin Widgets Bundle Plugin so-widgets-bundle Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter ≤ 1.73.2 CVE-2026-92174 Wordfence
7.2 High Ninja Forms Plugin ninja-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission No login needed ≤ 3.15.4 CVE-2026-90438 Wordfence
8.8 High Super Forms – Drag & Drop Form Builder Plugin Privilege Escalation Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login ≤ 6.3.316 CVE-2026-15897 Wordfence
8.1 High Ninja Forms - File Uploads Plugin Arbitrary File Upload File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload No login needed ≤ 3.3.34 CVE-2026-92820 Wordfence
6.1 Medium Avada | Website Builder For WordPress & WooCommerce Theme Cross-Site Scripting Reflected Cross-Site Scripting via 'lang' Parameter No login needed ≤ 7.16.1 CVE-2026-84925 Wordfence
9.8 Critical Divi Membership Plugin Authentication Bypass Unauthenticated Authentication Bypass via 'paypal_param' Parameter No login needed ≤ 2.3.0 CVE-2026-19660 Wordfence
7.2 High CTX Feed Pro Plugin Remote Code Execution Authenticated (Administrator+) Remote Code Execution ≤ 7.6.12 CVE-2026-10026 Wordfence
7.2 High Visitors Traffic Real Time Statistics Pro Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title) No login needed ≤ 11.22 CVE-2026-93367 Wordfence
9.8 Critical DevKit Pro Plugin Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow No login needed ≤ 2.3.0 CVE-2026-14378 Wordfence
5.4 Medium Prime Mover Plugin prime-mover Cross-Site Scripting Prime Mover < 2.2.1 Stored XSS via Package Metadata < 2.2.1 Fixed in 2.2.1 CVE-2026-101890 VulnCheck
6.5 Medium Prime Mover Plugin prime-mover Path Traversal Prime Mover < 2.2.1 Path Traversal via wprime-config.json < 2.2.1 Fixed in 2.2.1 CVE-2026-101889 VulnCheck
7.2 High Prime Mover Plugin prime-mover Path Traversal Prime Mover < 2.2.1 Zip Slip Path Traversal File Write < 2.2.1 Fixed in 2.2.1 CVE-2026-101888 VulnCheck
6.5 Medium Review Schema Plugin review-schema Broken Access Control No login needed 3.1.0 CVE-2026-97280 Patchstack
5.3 Medium hCaptcha for WP Plugin hcaptcha-for-forms-and-more Authentication Bypass Bypass Vulnerability No login needed ≤ 5.3.0 Fixed in 5.4.0 CVE-2026-103347 Patchstack
8.8 High ByteCoreStack – MCP Connector for AI Tools Plugin bcs-mcp-manager Privilege Escalation MCP Connector for AI Tools plugin <= 1.2.2 - Privilege Escalation ≤ 1.2.2 Fixed in 1.2.4 CVE-2026-103068 Patchstack
7.1 High Parallax Section block Plugin parallax-section Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.1.0 CVE-2026-102378 Patchstack
7.5 High Photo Reviews for WooCommerce Plugin woo-photo-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2026-100517 Patchstack
7.5 High REST API Log Plugin wp-rest-api-log Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2026-100514 Patchstack
7.6 High Gratisfaction Plugin gratisfaction-all-in-one-loyalty-contests-referral-program-for-woocommerce Broken Access Control ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-97297 Patchstack
8.8 High Icegram Plugin icegram PHP Object Injection ≤ 3.1.31 Fixed in 3.1.44 CVE-2026-97284 Patchstack
6.3 Medium WP Project Manager Plugin wedevs-project-manager Broken Access Control ≤ 4.0.7 Fixed in 4.1.0 CVE-2026-97281 Patchstack
7.6 High Social Boost Plugin social-boost Broken Access Control ≤ 3.6.2 Fixed in 3.7.0 CVE-2026-97277 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97273 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.13.1 Fixed in 3.13.2 CVE-2026-97269 Patchstack
7.1 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Cross-Site Scripting No login needed ≤ 1.1.13 Fixed in 1.1.15 CVE-2026-97268 Patchstack
7.1 High MaxGalleria Plugin maxgalleria Cross-Site Scripting No login needed ≤ 6.5.3 Fixed in 6.5.4 CVE-2026-97260 Patchstack
6.5 Medium Aruba Migration Tool Plugin aruba-wp-migration-tool Broken Access Control ≤ 1.0.4 Fixed in 1.0.5 CVE-2026-97258 Patchstack
6.5 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.9.3 Fixed in 5.9.4 CVE-2026-97251 Patchstack
8.6 High AcyMailing SMTP Newsletter Plugin acymailing Arbitrary File Deletion No login needed ≤ 11.0.5 Fixed in 11.1.0 CVE-2026-95588 Patchstack
7.2 High Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce PHP Object Injection ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-94390 Patchstack
7.5 High WP Full Stripe Free Plugin wp-full-stripe-free Broken Access Control No login needed ≤ 8.5.6 Fixed in 8.5.7 CVE-2026-62073 Patchstack
9.3 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload SQL Injection No login needed ≤ 5.1.10 Fixed in 5.2.0 CVE-2026-62071 Patchstack
9.8 Critical Authorizer Plugin authorizer Privilege Escalation No login needed ≤ 3.15.3 Fixed in 3.16.0 CVE-2026-103752 Patchstack
5.3 Medium CF7 Apps Plugin contact-form-7-honeypot Information Disclosure Sensitive Data Exposure No login needed ≤ 3.7.2 Fixed in 3.8.0 CVE-2026-62058 Patchstack
7.6 High Ultimate Member Plugin ultimate-member SQL Injection ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-62059 Patchstack
7.6 High Captivate Sync Plugin captivatesync-trade SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-62060 Patchstack
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-62061 Patchstack
5.4 Medium WpTravelly Plugin tour-booking-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-62063 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.8.4 Fixed in 6.8.5 CVE-2026-102394 Patchstack
6.5 Medium Metform Plugin metform Cross-Site Scripting ≤ 4.3.0 Fixed in 4.3.1 CVE-2026-103339 Patchstack
8.5 High BuildKit – Product Builder for WooCommerce – Custom PC Builder Plugin woo-product-builder SQL Injection Product Builder for WooCommerce – Custom PC Builder plugin <= 1.0.28 - SQL Injection ≤ 1.0.28 Fixed in 1.0.29 CVE-2026-102379 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103063 Patchstack
5.3 Medium Pie Register Plugin pie-register Information Disclosure Sensitive Data Exposure No login needed ≤ 3.8.4.13 Fixed in 3.8.4.14 CVE-2026-103345 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only