WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 151–200 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 8.9.0 Fixed in 8.9.1 CVE-2026-28180 Patchstack
5.3 Medium PeproDev WooCommerce Receipt Uploader Plugin Information Disclosure Unauthenticated Image Attachment Disclosure via IDOR No login needed ≤ 2.8.0 CVE-2026-14314 WPScan
5.3 Medium PeproDev WooCommerce Receipt Uploader Plugin Broken Access Control Unauthenticated Order Receipt Tampering via IDOR No login needed ≤ 2.8.0 CVE-2026-14313 WPScan
5.3 Medium DHL for WooCommerce Plugin Broken Access Control Unauthenticated Shipping Label Download via IDOR No login needed < 4.0.1 Fixed in 4.0.1 CVE-2026-16981 WPScan
2.7 Low MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16746 WPScan
7.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization < 5.0.11 Fixed in 5.0.11 CVE-2026-16605 WPScan
8.8 High Dokan Plugin dokan-lite Broken Access Control Missing Authorization to Authenticated (Vendor+) Privilege Escalation <=5.0.2 CVE-2026-8761 Wordfence
2.7 Low Brizy - Page Builder Plugin Broken Access Control Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR < 2.8.19 Fixed in 2.8.19 CVE-2026-16070 WPScan
4.3 Medium Dokan Plugin Broken Access Control Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API < 5.0.9 Fixed in 5.0.9 CVE-2026-16565 WPScan
4.3 Medium Dokan Plugin Broken Access Control Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint < 5.0.9 Fixed in 5.0.9 CVE-2026-16564 WPScan
4.3 Medium Geo My WP Plugin geo-my-wp Broken Access Control Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR < 4.5.5.3 Fixed in 4.5.5.3 CVE-2026-15260 WPScan
2.7 Low TaxoPress Plugin Information Disclosure Contributor+ Private Post Disclosure via IDOR < 3.51.0 Fixed in 3.51.0 CVE-2026-15231 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Arbitrary Notification Deletion via IDOR < 5.9.9.8 Fixed in 5.9.9.8 CVE-2026-16291 WPScan
5.5 Medium Meta Box Plugin meta-box Broken Access Control Contributor+ Arbitrary Attachment Deletion via IDOR < 5.13.1 Fixed in 5.13.1 CVE-2026-15248 WPScan
4.3 Medium FluentBoards Plugin fluent-boards Information Disclosure Subscriber+ Cross-Board Task Disclosure via IDOR < 1.95.3 Fixed in 1.95.3 CVE-2026-14938 WPScan
2.2 Low Event Tickets Plugin Broken Access Control Contributor+ Seating Layout and Ticket Inventory Modification via IDOR < 5.29.0.1 Fixed in 5.29.0.1 CVE-2026-14823 WPScan
3.8 Low Fluent Support Plugin fluent-support Broken Access Control Agent+ Arbitrary Ticket Customer Reassignment via IDOR < 2.3.1 Fixed in 2.3.1 CVE-2026-14197 WPScan
5.4 Medium wpForo Forum Plugin wpforo Broken Access Control Subscriber+ Cross-User AI Chat Message Deletion via IDOR < 3.1.2 Fixed in 3.1.2 CVE-2026-12697 WPScan
5.4 Medium BuddyPress Plugin buddypress Information Disclosure Subscriber+ Private Messages Disclosure via IDOR < 14.5.0 Fixed in 14.5.0 CVE-2026-8155 WPScan
6.5 Medium JS Help Desk – AI-Powered Support & Ticketing System Plugin js-support-ticket Information Disclosure AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR < 3.1.5 Fixed in 3.1.5 CVE-2026-15209 WPScan
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Subscriber+ Ticket Reply Modification via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-14929 WPScan
4.3 Medium Paid Member Subscriptions Plugin Information Disclosure Subscriber+ Payment Data Disclosure via IDOR < 3.0.7 Fixed in 3.0.7 CVE-2026-14847 WPScan
5.3 Medium Events Made Easy Plugin events-made-easy Broken Access Control Unauthenticated Person Data Modification via IDOR No login needed < 3.1.4 Fixed in 3.1.4 CVE-2026-14843 WPScan
4.3 Medium WP Travel Plugin wp-travel Information Disclosure Subscriber+ Booking PII Disclosure via IDOR < 11.8.1 Fixed in 11.8.1 CVE-2026-13145 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Information Disclosure Unauthenticated Form Submission Disclosure via IDOR No login needed < 6.0.9.4 Fixed in 6.0.9.4 CVE-2026-15255 WPScan
5.9 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR No login needed < 2.10.1 Fixed in 2.10.1 CVE-2026-11782 WPScan
4.3 Medium Easy Appointments Plugin easy-appointments Information Disclosure Subscriber+ Customer PII Disclosure via IDOR < 3.12.28 Fixed in 3.12.28 CVE-2026-14223 WPScan
5.4 Medium Easy Appointments Plugin easy-appointments Broken Access Control Subscriber+ Cross-User Appointment Data Modification via IDOR < 3.12.28 Fixed in 3.12.28 CVE-2026-14224 WPScan
4.2 Medium FluentCart Plugin Broken Access Control Subscriber+ Subscription Payment-Method Tampering via IDOR < 1.4.0 Fixed in 1.4.0 CVE-2026-14926 WPScan
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-59539 Patchstack
5.3 Medium Shiptastic for WooCommerce Plugin shiptastic-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-65501 Patchstack
5.4 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-65463 Patchstack
4.3 Medium Product Slider for WooCommerce Plugin woocommerce-products-slider Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.13.62 Fixed in 1.13.63 CVE-2026-65456 Patchstack
6.5 Medium Easy Appointments Plugin easy-appointments Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.12.27 Fixed in 3.12.28 CVE-2026-61946 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.40 Fixed in 2.1.50 CVE-2026-27399 Patchstack
5.4 Medium Academy LMS Plugin academy Broken Access Control Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR < 3.8.1 Fixed in 3.8.1 CVE-2026-14184 WPScan
4.3 Medium Classified Listing Plugin classified-listing Information Disclosure Subscriber+ Payment Receipt Disclosure via IDOR < 5.3.9 Fixed in 5.3.9 CVE-2026-14183 WPScan
5.4 Medium WPS Bookings for WooCommerce Plugin mwb-bookings-for-woocommerce Broken Access Control Subscriber+ Arbitrary Booking Order Cancellation via IDOR < 3.11.7 Fixed in 3.11.7 CVE-2026-12393 WPScan
5.9 Medium AI Engine Plugin ai-engine Information Disclosure Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR < 3.5.5 Fixed in 3.5.5 CVE-2026-12510 WPScan
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor SQL Injection Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter ≤ 5.0.9 CVE-2026-12941 Wordfence
5.5 Medium Kali Forms Plugin Information Disclosure Contributor+ Arbitrary Post Metadata Disclosure via IDOR < 2.4.17 Fixed in 2.4.17 CVE-2026-11580 WPScan
2.7 Low User Profile Picture Plugin metronet-profile-picture Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.6.3 Fixed in 2.6.4 CVE-2026-61971 Patchstack
7.5 High Dør Plugin dor Local File Inclusion ≤ 2.4.1 CVE-2026-57792 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.13 Fixed in 3.9.14 CVE-2026-57694 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Information Disclosure Subscriber+ Employer Email Disclosure via IDOR < 2.5.5 Fixed in 2.5.5 CVE-2026-12397 WPScan
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Instructor+ Arbitrary Post Overwrite via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12274 WPScan
5.4 Medium Tutor LMS Plugin tutor Broken Access Control Subscriber+ Arbitrary Quiz Attempt Modification via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12271 WPScan
8.1 High User Registration & Membership Plugin user-registration Broken Access Control Subscriber+ Cross-User Role and Membership Tier Modification via IDOR < 5.2.2 Fixed in 5.2.2 CVE-2026-11963 WPScan
4.3 Medium WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers ≤ 6.7.27 CVE-2026-10041 Wordfence
6.4 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title' ≤ 3.7.3 CVE-2026-12126 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only