WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94680 Patchstack
5.4 Medium Fluent Support Plugin fluent-support Broken Access Control ≤ 2.3.2 Fixed in 2.4.0 CVE-2026-94679 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94671 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2026-94500 Patchstack
6.5 Medium AppMySite Plugin appmysite Broken Access Control No login needed ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-94498 Patchstack
6.5 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting ≤ 3.1.69 Fixed in 3.1.70 CVE-2026-94461 Patchstack
4.8 Medium Captcha Code Plugin captcha-code-authentication Authentication Bypass Bypass Vulnerability No login needed ≤ 3.32 Fixed in 3.33 CVE-2026-94457 Patchstack
6.5 Medium Ultimate FAQ Plugin ultimate-faqs Cross-Site Scripting ≤ 2.4.14 Fixed in 2.5.0 CVE-2026-94391 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.105 Fixed in 4.11.106 CVE-2026-94168 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) ≤ 2.3.17 Fixed in 2.3.18 CVE-2026-94118 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.70 Fixed in 2.1.72 CVE-2026-94080 Patchstack
5.3 Medium WP User Manager Plugin wp-user-manager Broken Access Control No login needed ≤ 2.9.19 Fixed in 2.9.20 CVE-2026-94079 Patchstack
6.5 Medium wpForo Forum Plugin wpforo Cross-Site Scripting ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-93772 Patchstack
5.3 Medium AI Engine Plugin ai-engine Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2026-93623 Patchstack
6.5 Medium PayPlus Payment Gateway Plugin payplus-payment-gateway Broken Access Control No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2026-93620 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-93618 Patchstack
6.5 Medium WSP MCP – AI Agents Connector Plugin wsp-mcp-ai-agents-connector Broken Access Control AI Agents Connector plugin <= 2.7.0 - Broken Access Control ≤ 2.7.0 Fixed in 2.7.1 CVE-2026-93529 Patchstack
4.3 Medium SiteSkite Plugin siteskite Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-93513 Patchstack
6.1 Medium MC4WP: Mailchimp Plugin mailchimp-for-wp Cross-Site Scripting Reflected Cross-Site Scripting via 'data' Dynamic Content Tag No login needed ≤ 4.14.0 CVE-2026-87917 Wordfence
5.4 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird Cross-Site Scripting WordPress Media Library Folders & File Manager <= 6.5.6 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 6.5.6 CVE-2026-15004 Wordfence
5.3 Medium BerqWP Plugin searchpro Broken Access Control No login needed ≤ 4.1.15 Fixed in 4.1.16 CVE-2026-78528 Patchstack
6.5 Medium Geo Mashup Plugin geo-mashup Cross-Site Scripting ≤ 1.13.21 Fixed in 1.13.22 CVE-2026-78294 Patchstack
5.3 Medium User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.2.7 Fixed in 5.2.8 CVE-2026-74017 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-74005 Patchstack
5.3 Medium Booking Calendar Plugin booking Broken Access Control No login needed ≤ 11.7 Fixed in 11.8 CVE-2026-74002 Patchstack
5.3 Medium Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.8.2 Fixed in 4.8.3 CVE-2026-74000 Patchstack
5.4 Medium Cooked Plugin cooked Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.16.0 Fixed in 1.16.1 CVE-2026-73999 Patchstack
5.3 Medium Easy Invoice Plugin easy-invoice Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.4.0 CVE-2026-66676 Patchstack
6.5 Medium PublishPress Series Plugin organize-series Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-66617 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.2.1 Fixed in 2.9.2.2 CVE-2026-66579 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.2.6 Fixed in 2.3.0 CVE-2026-66578 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.6.3 Fixed in 3.6.3.1 CVE-2026-66577 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.2.1 CVE-2026-66576 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 51.1.81 Fixed in 51.1.82 CVE-2026-66575 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 8.8.3 Fixed in 8.8.4 CVE-2026-66574 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.3.3.1 Fixed in 2.3.3.2 CVE-2026-66573 Patchstack
6.5 Medium JetBlog Plugin jet-blog Cross-Site Scripting ≤ 2.4.10 Fixed in 2.4.10.1 CVE-2026-66572 Patchstack
5.3 Medium FluentAuth Plugin fluent-security Other Email Verification Bypass No login needed ≤ 2.1.2 Fixed in 3.0.0 CVE-2026-78296 Patchstack
5.4 Medium Blog2Social Plugin blog2social Broken Access Control Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post < 9.1.0 Fixed in 9.1.0 CVE-2026-89031 VulnCheck
4.3 Medium Blog2Social Plugin blog2social Information Disclosure Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user < 9.1.0 Fixed in 9.1.0 CVE-2026-89030 VulnCheck
4.3 Medium Blog2Social Plugin blog2social Broken Access Control Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler < 9.1.0 Fixed in 9.1.0 CVE-2026-89029 VulnCheck
6.1 Medium Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots Plugin bp-better-messages Cross-Site Scripting Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress <= 2.15.22 - Reflected Cross-Site Scripting via 'icn' Parameter No login needed ≤ 2.15.22 CVE-2026-18555 Wordfence
5.1 Medium design-scuole-wordpress-theme Theme Content Injection HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme 1.0 – 2.17.3 CVE-2026-89307 ENISA
5.1 Medium design-scuole-wordpress-theme Theme Cross-Site Scripting Reflected XSS in WordPress theme design-scuole-wordpress-theme No login needed 1.0 – 2.18.2 CVE-2026-87793 ENISA
6.4 Medium Bridge - Creative Multipurpose Theme Cross-Site Scripting Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute ≤ 30.8.9.1 CVE-2026-15609 Wordfence
4.2 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR < 4.7.12 Fixed in 4.7.12 CVE-2026-88912 WPScan
5.3 Medium ElasticPress Plugin elasticpress Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-62088 Patchstack
4.3 Medium Site Kit by Google Plugin google-site-kit Cross-Site Request Forgery No login needed ≤ 1.186.0 Fixed in 1.187.0 CVE-2026-62139 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.16.1 Fixed in 45.16.2 CVE-2026-62138 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only