WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 151–200 of 1,407 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 29
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Arbitrary File Deletion Authenticated (Admin+) Arbitrary File Deletion via Path Traversal via 'location' Parameter ≤ 9.2.3 CVE-2026-15450 Wordfence
7.2 High MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder Plugin mailchimp-subscribe-sm Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Field Values No login needed ≤ 4.3.3 CVE-2026-15052 Wordfence
5.3 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action() No login needed ≤ 1.9.0 CVE-2026-11995 Wordfence
2.7 Low Brizy – Page Builder Plugin brizy Information Disclosure Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info < 2.8.18 Fixed in 2.8.18 CVE-2026-14195 WPScan
3.7 Low Builderall Plugin Broken Access Control Unauthenticated OAuth Access Token Poisoning via Public REST Routes No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-11882 WPScan
5.4 Medium Codeless Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode Attribute ≤ 1.1.4 CVE-2026-15234 WPScan
8.1 High Profile Builder Plugin Privilege Escalation Unauthenticated Account Takeover via Auto-Login After Registration No login needed < 3.16.4 Fixed in 3.16.4 CVE-2026-15368 WPScan
7.2 High ElementsKit Lite Plugin Remote Code Execution Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13392 WPScan
6.1 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via ult_buttons Shortcode No login needed < 3.21.5 Fixed in 3.21.5 CVE-2026-14921 WPScan
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin Path Traversal Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts No login needed < 3.21.4 Fixed in 3.21.4 CVE-2026-15382 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control Unauthenticated Form Submission and User Profile Modification No login needed < 6.0.9.4 Fixed in 6.0.9.4 CVE-2026-15257 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Information Disclosure Unauthenticated Form Submission Disclosure via IDOR No login needed < 6.0.9.4 Fixed in 6.0.9.4 CVE-2026-15255 WPScan
9.8 Critical Cost Calculator Builder PRO Plugin Remote Code Execution Unauthenticated Remote Code Execution via 'orderDetails' Parameter No login needed ≤ 4.0.3 CVE-2026-14900 Wordfence
6.5 Medium Taskbuilder Plugin taskbuilder SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 5.0.9 CVE-2026-15267 Wordfence
5.0 Medium Visual Composer Website Builder Plugin visualcomposer Broken Access Control ≤ 45.15.0 Fixed in 45.16.0 CVE-2026-65568 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-65433 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-59559 Patchstack
9.8 Critical Thrive Quiz Builder Plugin thrive-quiz-builder PHP Object Injection No login needed ≤ 10.9.3.0 Fixed in 10.9.3.1 CVE-2026-59544 Patchstack
7.1 High Easy Form Builder Plugin easy-form-builder Cross-Site Scripting No login needed ≤ 4.0.12 Fixed in 4.0.13 CVE-2026-59517 Patchstack
7.1 High Funnel Kit Funnel Builder PRO Plugin funnel-builder-pro Cross-Site Scripting No login needed ≤ 3.15.0.7 Fixed in 3.15.0.8 CVE-2026-57374 Patchstack
6.5 Medium Funnel Kit Funnel Builder PRO Plugin funnel-builder-pro Cross-Site Scripting ≤ 3.15.0.4 Fixed in 3.15.0.5 CVE-2026-57373 Patchstack
7.2 High FormCraft Plugin formcraft-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters No login needed ≤ 3.9.14 CVE-2026-7232 Wordfence
9.8 Critical Easy Form Builder by WhiteStudio Plugin easy-form-builder Privilege Escalation Unauthenticated Privilege Escalation to Administrator via Password Recovery REST Endpoint No login needed ≤ 4.0.11 CVE-2026-13439 Wordfence
6.1 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored XSS via Form Submission No login needed < 9.2.3 Fixed in 9.2.3 CVE-2026-10525 WPScan
4.3 Medium Themify Builder Plugin themify-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action ≤ 7.7.7 CVE-2026-15407 Wordfence
5.5 Medium FunnelKit Plugin funnel-builder Arbitrary File Deletion Admin+ Arbitrary File Deletion via Path Traversal in Template Importer < 3.15.0.6 Fixed in 3.15.0.6 CVE-2026-12979 WPScan
7.1 High FunnelKit Plugin funnel-builder Cross-Site Scripting Reflected XSS via Divi Optin Form No login needed < 3.15.0.6 Fixed in 3.15.0.6 CVE-2026-12978 WPScan
2.7 Low RTMKit Addons for Elementor Plugin Broken Access Control Author+ Site-Wide Theme Builder Template Creation and Activation < 2.0.9 Fixed in 2.0.9 CVE-2026-12907 WPScan
6.1 Medium Header Footer Builder for Elementor Plugin header-footer-builder-for-elementor Cross-Site Scripting Contributor+ Stored XSS via Template Import No login needed < 1.2.1 Fixed in 1.2.1 CVE-2026-12869 WPScan
4.3 Medium Landing Page Builder Plugin page-builder-add Cross-Site Request Forgery Cross-Site Request Forgery to ulpb_admin_data AJAX Action No login needed ≤ 1.5.3.6 CVE-2026-12409 Wordfence
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title ≤ 3.15.5 CVE-2026-12536 Wordfence
7.1 High Funnel Builder by FunnelKit Plugin funnel-builder Cross-Site Scripting No login needed ≤ 3.15.0.8 Fixed in 3.15.0.9 CVE-2026-57816 Patchstack
6.5 Medium Envision Page Builder Plugin envision-page-builder Cross-Site Scripting ≤ 0.22 CVE-2026-57780 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2026-57732 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.2.2 Fixed in 9.2.3 CVE-2026-57668 Patchstack
7.1 High Bopo – WooCommerce Product Bundle Builder Plugin bopo-woo-product-bundle-builder Cross-Site Scripting WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-57422 Patchstack
6.5 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-57393 Patchstack
6.5 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Broken Access Control No login needed ≤ 1.2.167 Fixed in 1.2.168 CVE-2026-57390 Patchstack
7.1 High Themify Builder Plugin themify-builder Cross-Site Scripting No login needed ≤ 7.7.4 Fixed in 7.7.5 CVE-2026-57369 Patchstack
5.3 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action No login needed ≤ 9.2.2 CVE-2026-9017 Wordfence
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Information Disclosure Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys No login needed ≤ 4.0.11 CVE-2026-10865 Wordfence
6.4 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field ≤ 7.7.6 CVE-2026-15096 Wordfence
6.4 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field ≤ 7.7.6 CVE-2026-15097 Wordfence
6.5 Medium KiviCare Plugin kivicare-clinic-management-system SQL Injection Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder ≤ 4.5.0 CVE-2026-15072 Wordfence
8.8 High WP Grid Builder Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter ≤ 2.3.3 CVE-2026-13756 Wordfence
4.3 Medium GW AI Website Builder Plugin gw-ai-website-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion ≤ 1.0.1 CVE-2026-1946 Wordfence
7.5 High SureForms – Drag and Drop Form Builder Plugin sureforms Price Manipulation Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation No login needed ≤ 2.2.1 CVE-2026-15288 Wordfence
4.3 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Broken Access Control Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication ≤ 3.5.32 CVE-2026-15286 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 6.4.11 CVE-2026-15285 Wordfence
7.2 High WP Cost Estimation & Payment Forms Builder (E&P Forms) Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter No login needed ≤ 10.5.97 CVE-2026-9253 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only