WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 151–200 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High pCloud WP Backup Plugin pcloud-wp-backup Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2026-57757 Patchstack
8.1 High Heateor Social Login Plugin heateor-social-login Cross-Site Request Forgery No login needed ≤ 1.1.39 CVE-2026-57751 Patchstack
6.5 Medium Booked Plugin booked Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2026-57747 Patchstack
4.3 Medium Werkstatt Theme werkstatt Cross-Site Request Forgery No login needed ≤ 4.7.2 CVE-2026-57690 Patchstack
6.4 Medium GeoDirectory Plugin geodirectory Server-Side Request Forgery ≤ 2.8.161 Fixed in 2.8.162 CVE-2026-57681 Patchstack
7.2 High Paid Member Subscriptions Plugin paid-member-subscriptions Server-Side Request Forgery No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-57348 Patchstack
8.8 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter ≤ 6.0.9.1 CVE-2026-12158 Wordfence
4.3 Medium GiveWP Plugin give Cross-Site Request Forgery No login needed ≤ 4.15.3 CVE-2026-11981 Wordfence
4.3 Medium Plugin for Google Analytics by IO technologies Plugin io-engagement-analytics Cross-Site Request Forgery Cross-Site Request Forgery via 'ga_id' Parameter No login needed ≤ 1.1 CVE-2026-8944 Wordfence
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request No login needed ≤ 6.0.8.6 CVE-2026-9242 Wordfence
4.3 Medium HD Quiz Plugin hd-quiz Cross-Site Request Forgery Cross-Site Request Forgery via Multiple AJAX Handlers No login needed 2.2.0 – 2.2.1 CVE-2026-13422 Wordfence
8.8 High Paid Memberships Pro - Add Member From Admin Plugin pmpro-add-member-admin Cross-Site Request Forgery Add Member From Admin plugin <= 0.7.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 0.7.2 Fixed in 0.7.3 CVE-2026-57659 Patchstack
4.3 Medium Gmail SMTP Plugin gmail-smtp Cross-Site Request Forgery No login needed ≤ 1.2.3.19 Fixed in 1.2.3.20 CVE-2026-57657 Patchstack
8.2 High Child Theme Wizard Plugin child-theme-wizard Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2026-57655 Patchstack
6.5 Medium Real Estate 7 Theme realestate-7 Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2026-57641 Patchstack
4.3 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Request Forgery No login needed ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-57637 Patchstack
6.5 Medium FunnelKit Payment Gateway for Stripe WooCommerce Plugin funnelkit-stripe-woo-payment-gateway Cross-Site Request Forgery No login needed ≤ 1.14.0.3 Fixed in 1.14.0.4 CVE-2026-57635 Patchstack
4.9 Medium Kirki Plugin kirki Server-Side Request Forgery ≤ 6.0.11 Fixed in 6.0.12 CVE-2026-57627 Patchstack
6.4 Medium utm.codes Plugin utm-dot-codes Server-Side Request Forgery ≤ 1.9.0 Fixed in 1.9.1 CVE-2026-56026 Patchstack
8.8 High Eagle Booking Plugin eagle-booking Cross-Site Request Forgery No login needed ≤ 1.3.4.3 CVE-2025-68052 Patchstack
5.4 Medium Forget About Shortcode Buttons Plugin forget-about-shortcode-buttons Broken Access Control ≤ 2.1.3 CVE-2025-63041 Patchstack
4.3 Medium Bulk SEO Image Plugin bulk-seo-image Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.1 CVE-2026-11997 Wordfence
4.3 Medium MP Customize Login Page Plugin mp-customize-login-page Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-6292 Wordfence
7.2 High Kargo Takip Plugin kargo-takip Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'api_url' Parameter No login needed ≤ 1.2 CVE-2026-12095 Wordfence
4.3 Medium Blue Captcha Plugin blue-captcha Cross-Site Request Forgery Cross-Site Request Forgery via 'blcap_action' Parameter No login needed ≤ 2.0.1 CVE-2026-10552 Wordfence
4.3 Medium MotorDesk Plugin motordesk Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.1.2 CVE-2026-9724 Wordfence
6.4 Medium WP Meta SEO Plugin wp-meta-seo Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter ≤ 4.5.18 CVE-2026-11370 Wordfence
4.3 Medium Book a Room Event Calendar Plugin book-a-room-event-calendar Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.9 CVE-2026-9721 Wordfence
7.2 High URL Preview Plugin link-preview Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.0 CVE-2026-12100 Wordfence
6.1 Medium Osiris Signature Banner Plugin osiris-signature-banner Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter No login needed ≤ 0.5 CVE-2026-8905 Wordfence
6.5 Medium Bit integrations Plugin bit-integrations Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping No login needed ≤ 2.8.7 CVE-2026-11989 Wordfence
6.4 Medium Advanced Import: One-Click Demo Import Plugin advanced-import Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter ≤ 1.4.6 CVE-2026-4328 Wordfence
4.3 Medium User Admin Simplifier Plugin user-admin-simplifier Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2026-11775 Wordfence
6.5 Medium WP EasyPay Plugin wp-easy-pay Cross-Site Request Forgery No login needed ≤ 4.5.0 CVE-2026-56024 Patchstack
7.2 High CF7 to Webhook Plugin cf7-to-zapier Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host No login needed ≤ 5.0.0 CVE-2026-11395 Wordfence
5.3 Medium Simple Membership Plugin simple-membership Broken Access Control Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook No login needed ≤ 4.7.5 CVE-2026-12093 Wordfence
4.3 Medium Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization Plugin optimole-wp Cross-Site Request Forgery Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action No login needed ≤ 4.2.6 CVE-2026-11784 Wordfence
4.3 Medium Emergency Password Reset Plugin emergency-password-reset Cross-Site Request Forgery No login needed ≤ 8.0 Fixed in 9.0 CVE-2024-35648 Patchstack
4.3 Medium Skyline WP Theme skyline-wp Cross-Site Request Forgery No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2024-34810 Patchstack
7.5 High Bricksforge Plugin bricksforge Information Disclosure Sensitive Data Exposure No login needed ≤ 3.1.8.4 Fixed in 3.1.8.5 CVE-2026-34888 Patchstack
8.8 High Dating Theme da10 Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 11.2.0 CVE-2026-22342 Patchstack
4.7 Medium WP Migrate Lite Plugin wp-migrate-db Cross-Site Request Forgery No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2026-49043 Patchstack
4.4 Medium PopAd Plugin popad Server-Side Request Forgery ≤ 1.0.4 CVE-2025-60175 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Cross-Site Request Forgery No login needed ≤ 2.0.10 Fixed in 2.0.11 CVE-2022-47150 Patchstack
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-32110 Patchstack
4.3 Medium Yoast Duplicate Post Plugin duplicate-post Cross-Site Request Forgery Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_notice No login needed ≤ 4.6 CVE-2026-53739 VulnCheck
4.3 Medium Easy Twitter Feeds Plugin easy-twitter-feeds Cross-Site Request Forgery Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_post Action No login needed < 1.2.13 Fixed in 1.2.13 CVE-2026-53736 VulnCheck
5.3 Medium WPForms Lite Plugin Broken Access Control Unauthenticated PayPal Webhook Forgery No login needed 1.10.0.1 – < 1.10.0.5 Fixed in 1.10.0.5 CVE-2026-4986 WPScan
4.3 Medium jQuery Hover Footnotes Plugin jquery-hover-footnotes Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.4 CVE-2026-10553 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only