WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 151–200 of 1,023 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Contact Form Builder | Cross-Site Scripting WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php No login needed |
1.6.1 |
CVE-2022-50959 |
VulnCheck | |
| 5.3 Medium | Forminator – Contact Form, Payment Form & Custom Form Builder | Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter No login needed |
≤ 1.52.0 |
CVE-2026-2729 |
Wordfence | |
| 5.3 Medium | App Builder | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter No login needed |
≤ 5.6.0 |
CVE-2026-7638 |
Wordfence | |
| 6.4 Medium | Elementor Website Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API |
≤ 4.0.4 |
CVE-2026-6127 |
Wordfence | |
| 5.4 Medium | Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor | Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML |
≤ 3.5.5 |
CVE-2026-2951 |
Wordfence | |
| 6.4 Medium | Page Builder Gutenberg Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data |
≤ 3.1.16 |
CVE-2026-4801 |
Wordfence | |
| 5.3 Medium | Kubio AI Page Builder | Broken Access Control Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes No login needed |
≤ 2.7.2 |
CVE-2026-5427 |
Wordfence | |
| 5.3 Medium | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed |
6.1.21 |
CVE-2026-4160 |
Wordfence | |
| 5.3 Medium | e-shot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX No login needed |
≤ 1.0.2 |
CVE-2026-3642 |
Wordfence | |
| 5.4 Medium | Avada (Fusion) Builder | Privilege Escalation Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution |
≤ 3.15.1 |
CVE-2026-1509 |
Wordfence | |
| 4.3 Medium | Avada (Fusion) Builder | Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference |
≤ 3.15.1 |
CVE-2026-1541 |
Wordfence | |
| 6.4 Medium | Greenshift | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute |
≤ 12.8.9 |
CVE-2026-4895 |
Wordfence | |
| 6.4 Medium | Page Builder: Pagelayer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes |
≤ 2.0.8 |
CVE-2026-2509 |
Wordfence | |
| 6.4 Medium | Beaver Builder Page Builder – Drag and Drop Website Builder | Cross-Site Scripting Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]' |
≤ 2.10.1.1 |
CVE-2026-2481 |
Wordfence | |
| 6.5 Medium | WPBITS Addons For Elementor Page Builder | Cross-Site Scripting |
≤ 1.8.1 |
CVE-2026-39703 |
Patchstack | |
| 6.5 Medium | Hello Bar Popup Builder | Cross-Site Scripting |
≤ 1.5.1 |
CVE-2026-39666 |
Patchstack | |
| 6.4 Medium | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar |
≤ 6.4.9 |
CVE-2026-3311 |
Wordfence | |
| 6.4 Medium | Elementor Website Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API |
≤ 3.35.5 |
CVE-2025-14732 |
Wordfence | |
| 6.5 Medium | SQL Chart Builder | SQL Injection Unauthenticated SQL Injection No login needed |
< 2.3.8 Fixed in 2.3.8 |
CVE-2026-4079 |
WPScan | |
| 4.3 Medium | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Broken Access Control Missing Authorization to Authenticated (Contributor+) Media Upload |
≤ 3.6.3 |
CVE-2026-2826 |
Wordfence | |
| 6.5 Medium | Ultimate Addons for WPBakery Page Builder | Cross-Site Scripting |
< 3.21.4 Fixed in 3.21.4 |
CVE-2026-34889 |
Patchstack | |
| 4.3 Medium | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Broken Access Control Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field |
≤ 3.15.5 |
CVE-2026-3139 |
Wordfence | |
| 6.5 Medium | Kubio AI Page Builder | Cross-Site Scripting |
≤ 2.7.0 Fixed in 2.7.1 |
CVE-2026-34887 |
Patchstack | |
| 6.4 Medium | Ibtana - WordPress Website Builder | Cross-Site Scripting WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.2.5.7 |
CVE-2026-1834 |
Wordfence | |
| 4.3 Medium | Elementor Website Builder | Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template |
≤ 3.35.7 |
CVE-2026-1206 |
Wordfence | |
| 6.5 Medium | Vertex Addons for Elementor | Broken Access Control |
≤ 1.6.4 Fixed in 1.7.0 |
CVE-2026-25398 |
Patchstack | |
| 5.3 Medium | Punnel | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update via 'punnel_save_config' AJAX Action No login needed |
≤ 1.3.1 |
CVE-2026-3645 |
Wordfence | |
| 5.3 Medium | e-shot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action No login needed |
≤ 1.0.2 |
CVE-2026-3546 |
Wordfence | |
| 5.6 Medium | Contact Form, Survey, Quiz & Popup Form Builder – ARForms | Arbitrary Shortcode Execution ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution No login needed |
≤ 1.7.2 |
CVE-2024-13785 |
Wordfence | |
| 5.3 Medium | Build App Online | Broken Access Control Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action No login needed |
≤ 1.0.23 |
CVE-2026-3651 |
Wordfence | |
| 6.4 Medium | Ecover Builder For Dummies | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 1.0 |
CVE-2026-4077 |
Wordfence | |
| 6.5 Medium | App Builder – Create Native Android & iOS Apps On The Flight | Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter No login needed |
≤ 5.5.10 |
CVE-2026-2375 |
Wordfence | |
| 5.3 Medium | Instant Popup Builder | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter No login needed |
≤ 1.1.7 |
CVE-2026-3475 |
Wordfence | |
| 4.3 Medium | NEX-Forms – Ultimate Forms | Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license |
≤ 9.1.9 |
CVE-2026-1948 |
Wordfence | |
| 5.3 Medium | Fusion Builder | Broken Access Control No login needed |
≤ 3.15.0 Fixed in 3.15.0 |
CVE-2026-32452 |
Patchstack | |
| 6.5 Medium | Fusion Builder | Broken Access Control |
≤ 3.15.0 Fixed in 3.15.0 |
CVE-2026-32451 |
Patchstack | |
| 5.3 Medium | Xpro Addons For Beaver Builder – Lite | Broken Access Control Lite plugin <= 1.5.6 - Broken Access Control No login needed |
≤ 1.5.6 Fixed in 1.5.7 |
CVE-2026-32395 |
Patchstack | |
| 5.4 Medium | RegistrationMagic | Broken Access Control |
≤ 6.0.7.6 Fixed in 6.0.7.7 |
CVE-2026-32385 |
Patchstack | |
| 5.3 Medium | ShopBuilder – Elementor WooCommerce Builder Addons | Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed |
≤ 3.2.4 Fixed in 3.2.5 |
CVE-2026-32372 |
Patchstack | |
| 6.5 Medium | Elementor Website Builder | Cross-Site Scripting |
≤ 3.35.5 Fixed in 3.35.6 |
CVE-2026-32352 |
Patchstack | |
| 6.1 Medium | RTMKit | Cross-Site Scripting Reflected Cross-Site Scripting via 'themebuilder' Parameter No login needed |
≤ 1.6.8 |
CVE-2025-12473 |
Wordfence | |
| 5.3 Medium | Greenshift | Broken Access Control Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' No login needed |
≤ 12.8.3 |
CVE-2026-2371 |
Wordfence | |
| 5.3 Medium | Greenshift – animation and page builder blocks | Information Disclosure animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup No login needed |
≤ 12.8.3 |
CVE-2026-2589 |
Wordfence | |
| 6.4 Medium | Greenshift – animation and page builder blocks | Cross-Site Scripting animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 12.8.5 |
CVE-2026-2593 |
Wordfence | |
| 6.5 Medium | Ultimate Addons for WPBakery Page Builder | Broken Access Control |
≤ 3.21.1 Fixed in 3.21.2 |
CVE-2026-28038 |
Patchstack | |
| 6.5 Medium | Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder | Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() |
≤ 1.6.0 |
CVE-2026-1674 |
Wordfence | |
| 4.4 Medium | Taskbuilder | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field |
≤ 5.0.3 |
CVE-2026-2289 |
Wordfence | |
| 6.5 Medium | Elementor Addon Elements | Information Disclosure Sensitive Data Exposure |
≤ 1.14.4 Fixed in 1.14.5 |
CVE-2026-28131 |
Patchstack | |
| 6.4 Medium | Livemesh Addons for Beaver Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes |
≤ 3.9.2 |
CVE-2026-2029 |
Wordfence | |
| 6.4 Medium | Rise Blocks – A Complete Gutenberg Page Builder | Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes |
≤ 3.7 |
CVE-2026-1614 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.