WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,951–2,000 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 40 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57395 Patchstack
6.5 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-57393 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57392 Patchstack
6.5 Medium Loops & Logic Plugin tangible-loops-and-logic Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-57391 Patchstack
6.5 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Broken Access Control No login needed ≤ 1.2.167 Fixed in 1.2.168 CVE-2026-57390 Patchstack
6.5 Medium WowAddons Plugin product-addons Broken Access Control No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2026-57377 Patchstack
6.5 Medium MStore API Plugin mstore-api Broken Access Control No login needed ≤ 4.18.4 Fixed in 4.19.0 CVE-2026-57375 Patchstack
6.5 Medium reCAPTCHA (v2 & v3) for Asgaros Forum Plugin recaptcha-for-asgaros-forum Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57365 Patchstack
6.5 Medium Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More Plugin better-payment Other Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-57364 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Information Disclosure Subscriber+ Employer Email Disclosure via IDOR < 2.5.5 Fixed in 2.5.5 CVE-2026-12397 WPScan
5.4 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Subscriber+ Arbitrary Job Approval, Featuring and Rejection < 2.5.5 Fixed in 2.5.5 CVE-2026-12396 WPScan
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Instructor+ Arbitrary Post Overwrite via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12274 WPScan
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Subscriber+ Arbitrary Auto-Approved Comment Creation < 3.9.13 Fixed in 3.9.13 CVE-2026-12273 WPScan
5.4 Medium Tutor LMS Plugin tutor Broken Access Control Subscriber+ Arbitrary Quiz Attempt Modification via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12271 WPScan
5.0 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection via Entry File Field No login needed < 1.5.2 Fixed in 1.5.2 CVE-2026-12081 WPScan
6.1 Medium Breeze Cache Plugin breeze Cross-Site Scripting Unauthenticated Stored XSS via Minify Library No login needed < 2.5.6 Fixed in 2.5.6 CVE-2026-10551 WPScan
6.4 Medium bbp style pack Plugin bbp-style-pack Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields ≤ 6.4.5 CVE-2026-15010 Wordfence
5.3 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action No login needed ≤ 9.2.2 CVE-2026-9017 Wordfence
4.3 Medium WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers ≤ 6.7.27 CVE-2026-10041 Wordfence
4.3 Medium Wallet for WooCommerce Plugin woo-wallet Broken Access Control Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action ≤ 1.6.4 CVE-2026-12103 Wordfence
5.3 Medium WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller No login needed ≤ 6.7.27 CVE-2026-12994 Wordfence
6.4 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title' ≤ 3.7.3 CVE-2026-12126 Wordfence
4.4 Medium Widgets for Google Reviews Plugin wp-reviews-plugin-for-google Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters ≤ 13.3 CVE-2026-11591 Wordfence
6.4 Medium fresh Podcaster Plugin fresh-podcaster Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes ≤ 1.0.7 CVE-2026-1382 Wordfence
4.9 Medium Catalyst Connect Zoho CRM Client Portal Plugin catalyst-connect-client-portal SQL Injection Authenticated (Administrator+) SQL Injection via uid Parameter ≤ 2.2.0 CVE-2025-5017 Wordfence
4.3 Medium WP Easy Pay Plugin wp-easy-pay Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action ≤ 4.5.0 CVE-2026-12738 Wordfence
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Information Disclosure Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys No login needed ≤ 4.0.11 CVE-2026-10865 Wordfence
5.3 Medium Context Blog Theme context-blog Information Disclosure Unauthenticated Sensitive Information Exposure via 'postID' Parameter No login needed ≤ 1.3.5 CVE-2026-6801 Wordfence
4.4 Medium White Label CMS Plugin white-label-cms Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings ≤ 2.7.12 CVE-2026-11898 Wordfence
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Price Manipulation Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler No login needed ≤ 2.3.1 CVE-2026-11901 Wordfence
5.3 Medium AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions No login needed ≤ 1.4.12 CVE-2026-6804 Wordfence
4.3 Medium ThriveDesk Plugin thrivedesk Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cache Deletion ≤ 2.1.7 CVE-2026-1832 Wordfence
5.3 Medium Solace Extra Plugin solace-extra Broken Access Control Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action No login needed ≤ 1.5.3 CVE-2026-13250 Wordfence
4.9 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter ≤ 4.11.84 CVE-2026-12141 Wordfence
6.4 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field ≤ 7.7.6 CVE-2026-15096 Wordfence
4.3 Medium Affilia Plugin affiliaa-affiliate-program-with-mlm Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification ≤ 3.3.3 CVE-2026-7559 Wordfence
6.4 Medium Starboard Suite Reservation Calendars Plugin starboard-suite-reservation-calendars Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.1.4 CVE-2025-13968 Wordfence
4.3 Medium PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute ≤ 5.14.0 CVE-2026-13116 Wordfence
4.4 Medium Print, PDF, Email by PrintFriendly Plugin printfriendly Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter ≤ 5.5.10 CVE-2026-9738 Wordfence
5.3 Medium AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Broken Access Control Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear' No login needed ≤ 1.4.12 CVE-2026-6803 Wordfence
4.3 Medium SurfLink Plugin surflink Broken Access Control Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action < 2.6.0 Fixed in 2.6.0 CVE-2026-3552 Wordfence
6.4 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field ≤ 7.7.6 CVE-2026-15097 Wordfence
4.3 Medium Notification for Telegram Plugin notification-for-telegram Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action ≤ 3.5.1 CVE-2026-7620 Wordfence
4.3 Medium Mux Video Uploader Plugin 2coders-integration-mux-video Information Disclosure Authenticated (Subscriber+) Information Exposure ≤ 1.1.4 CVE-2026-7544 Wordfence
6.5 Medium KiviCare Plugin kivicare-clinic-management-system SQL Injection Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder ≤ 4.5.0 CVE-2026-15072 Wordfence
5.3 Medium Members Plugin members Information Disclosure Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel No login needed ≤ 3.2.22 CVE-2026-12426 Wordfence
6.5 Medium Majestic Support Plugin majestic-support SQL Injection Authenticated (Subscriber+) SQL Injection via 'val' Parameter ≤ 1.1.9 CVE-2026-13262 Wordfence
4.3 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions ≤ 2.10.1 CVE-2026-10628 Wordfence
4.4 Medium Lockme OAuth2 calendars integration Plugin lockme-calendars-integration Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting ≤ 2.11.0 CVE-2026-3367 Wordfence
6.5 Medium KiviCare Plugin kivicare-clinic-management-system SQL Injection Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController ≤ 4.5.0 CVE-2026-15073 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only