WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 151–200 of 1,023 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 21
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Contact Form Builder Plugin contact-forms-builder Cross-Site Scripting WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php No login needed 1.6.1 CVE-2022-50959 VulnCheck
5.3 Medium Forminator – Contact Form, Payment Form & Custom Form Builder Plugin forminator Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter No login needed ≤ 1.52.0 CVE-2026-2729 Wordfence
5.3 Medium App Builder Plugin app-builder Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter No login needed ≤ 5.6.0 CVE-2026-7638 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 4.0.4 CVE-2026-6127 Wordfence
5.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML ≤ 3.5.5 CVE-2026-2951 Wordfence
6.4 Medium Page Builder Gutenberg Blocks Plugin coblocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data ≤ 3.1.16 CVE-2026-4801 Wordfence
5.3 Medium Kubio AI Page Builder Plugin kubio Broken Access Control Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes No login needed ≤ 2.7.2 CVE-2026-5427 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
5.3 Medium e-shot Plugin e-shot-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX No login needed ≤ 1.0.2 CVE-2026-3642 Wordfence
5.4 Medium Avada (Fusion) Builder Plugin Privilege Escalation Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution ≤ 3.15.1 CVE-2026-1509 Wordfence
4.3 Medium Avada (Fusion) Builder Plugin Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference ≤ 3.15.1 CVE-2026-1541 Wordfence
6.4 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute ≤ 12.8.9 CVE-2026-4895 Wordfence
6.4 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 2.0.8 CVE-2026-2509 Wordfence
6.4 Medium Beaver Builder Page Builder – Drag and Drop Website Builder Plugin beaver-builder-lite-version Cross-Site Scripting Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]' ≤ 2.10.1.1 CVE-2026-2481 Wordfence
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.8.1 CVE-2026-39703 Patchstack
6.5 Medium Hello Bar Popup Builder Plugin hellobar Cross-Site Scripting ≤ 1.5.1 CVE-2026-39666 Patchstack
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar ≤ 6.4.9 CVE-2026-3311 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 3.35.5 CVE-2025-14732 Wordfence
6.5 Medium SQL Chart Builder Plugin SQL Injection Unauthenticated SQL Injection No login needed < 2.3.8 Fixed in 2.3.8 CVE-2026-4079 WPScan
4.3 Medium Kadence Blocks — Page Builder Toolkit for Gutenberg Editor Plugin kadence-blocks Broken Access Control Missing Authorization to Authenticated (Contributor+) Media Upload ≤ 3.6.3 CVE-2026-2826 Wordfence
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin ultimate_vc_addons Cross-Site Scripting < 3.21.4 Fixed in 3.21.4 CVE-2026-34889 Patchstack
4.3 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Broken Access Control Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field ≤ 3.15.5 CVE-2026-3139 Wordfence
6.5 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting ≤ 2.7.0 Fixed in 2.7.1 CVE-2026-34887 Patchstack
6.4 Medium Ibtana - WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.5.7 CVE-2026-1834 Wordfence
4.3 Medium Elementor Website Builder Plugin elementor Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template ≤ 3.35.7 CVE-2026-1206 Wordfence
6.5 Medium Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control ≤ 1.6.4 Fixed in 1.7.0 CVE-2026-25398 Patchstack
5.3 Medium Punnel Plugin punnel-landing-page-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update via 'punnel_save_config' AJAX Action No login needed ≤ 1.3.1 CVE-2026-3645 Wordfence
5.3 Medium e-shot Plugin e-shot-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action No login needed ≤ 1.0.2 CVE-2026-3546 Wordfence
5.6 Medium Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder Arbitrary Shortcode Execution ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution No login needed ≤ 1.7.2 CVE-2024-13785 Wordfence
5.3 Medium Build App Online Plugin build-app-online Broken Access Control Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action No login needed ≤ 1.0.23 CVE-2026-3651 Wordfence
6.4 Medium Ecover Builder For Dummies Plugin ecover-builder-for-dummies Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.0 CVE-2026-4077 Wordfence
6.5 Medium App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter No login needed ≤ 5.5.10 CVE-2026-2375 Wordfence
5.3 Medium Instant Popup Builder Plugin instant-popup-builder Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter No login needed ≤ 1.1.7 CVE-2026-3475 Wordfence
4.3 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license ≤ 9.1.9 CVE-2026-1948 Wordfence
5.3 Medium Fusion Builder Plugin fusion-builder Broken Access Control No login needed ≤ 3.15.0 Fixed in 3.15.0 CVE-2026-32452 Patchstack
6.5 Medium Fusion Builder Plugin fusion-builder Broken Access Control ≤ 3.15.0 Fixed in 3.15.0 CVE-2026-32451 Patchstack
5.3 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Broken Access Control Lite plugin <= 1.5.6 - Broken Access Control No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2026-32395 Patchstack
5.4 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control ≤ 6.0.7.6 Fixed in 6.0.7.7 CVE-2026-32385 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32352 Patchstack
6.1 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'themebuilder' Parameter No login needed ≤ 1.6.8 CVE-2025-12473 Wordfence
5.3 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' No login needed ≤ 12.8.3 CVE-2026-2371 Wordfence
5.3 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Information Disclosure animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup No login needed ≤ 12.8.3 CVE-2026-2589 Wordfence
6.4 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 12.8.5 CVE-2026-2593 Wordfence
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin ultimate_vc_addons Broken Access Control ≤ 3.21.1 Fixed in 3.21.2 CVE-2026-28038 Patchstack
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() ≤ 1.6.0 CVE-2026-1674 Wordfence
4.4 Medium Taskbuilder Plugin taskbuilder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field ≤ 5.0.3 CVE-2026-2289 Wordfence
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Sensitive Data Exposure ≤ 1.14.4 Fixed in 1.14.5 CVE-2026-28131 Patchstack
6.4 Medium Livemesh Addons for Beaver Builder Plugin addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes ≤ 3.9.2 CVE-2026-2029 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes ≤ 3.7 CVE-2026-1614 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only