WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,001–2,050 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 41 of 1
Severity Component Vulnerability Affected versions Published CVE Source
2.7 Low Copy & Delete Posts Plugin Information Disclosure Author+ Password-Protected Post Content Disclosure < 1.5.6 Fixed in 1.5.6 CVE-2026-19085 WPScan
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated RCE via Control Character Filename Bypass No login needed < 1.3.9.9 Fixed in 1.3.9.9 CVE-2026-18781 WPScan
6.8 Medium Media Library Assistant Plugin media-library-assistant SQL Injection Author+ SQL Injection via mla_search_connector < 3.40 Fixed in 3.40 CVE-2026-16959 WPScan
2.7 Low Dokan Plugin Broken Access Control Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount < 5.0.14 Fixed in 5.0.14 CVE-2026-16577 WPScan
7.2 High Dokan Plugin Broken Access Control Shop Manager+ Arbitrary Plugin Installation/Activation via REST API < 5.0.14 Fixed in 5.0.14 CVE-2026-16576 WPScan
5.3 Medium Dokan Plugin Information Disclosure Unauthenticated Commission Settings Disclosure via Store Categories REST Endpoint No login needed < 5.0.14 Fixed in 5.0.14 CVE-2026-16575 WPScan
6.8 Medium Link Whisper Plugin SQL Injection Editor+ SQL Injection via domain Parameter < 0.9.7 Fixed in 0.9.7 CVE-2026-14601 WPScan
5.3 Medium Tamara Checkout Plugin tamara-checkout Broken Access Control Unauthenticated Order Status Manipulation No login needed ≤ 1.9.9.20 CVE-2026-16962 WPScan
3.5 Low Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Admin+ Stored XSS via drag_n_drop_heading_tag Setting < 1.3.9.9 Fixed in 1.3.9.9 CVE-2026-14325 WPScan
5.3 Medium NewPath WildApricotPress Add-on – Member Directory Plugin Information Disclosure Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API No login needed ≤ 1.0.0 CVE-2026-13736 WPScan
5.4 Medium Welcart e-Commerce Plugin usc-e-shop Authentication Bypass Session Fixation via uscesid Parameter No login needed < 2.12.1 Fixed in 2.12.1 CVE-2025-15671 WPScan
7.2 High WPForms Pro Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values No login needed ≤ 2.0.0.2 CVE-2026-18409 Wordfence
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
5.3 Medium New User Approve Plugin new-user-approve Broken Access Control No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2026-28163 Patchstack
7.6 High InfiniteWP Client Plugin iwp-client SQL Injection ≤ 1.13.9 Fixed in 1.13.10 CVE-2026-74011 Patchstack
7.5 High Koji Theme koji Broken Access Control No login needed ≤ 2.2.1 CVE-2026-74020 Patchstack
7.1 High EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control ≤ 2.4.2 CVE-2026-74019 Patchstack
9.9 Critical Warehouse Cargo Theme warehouse-cargo Arbitrary File Upload ≤ 2.6.9 CVE-2026-74018 Patchstack
9.9 Critical Smart Cleaning Theme smart-cleaning Arbitrary File Upload ≤ 4.8.6 CVE-2026-74016 Patchstack
9.9 Critical IT Residence Theme it-residence Arbitrary File Upload ≤ 3.2.1 CVE-2026-74014 Patchstack
8.5 High eShipper Commerce Plugin eshipper-commerce SQL Injection ≤ 2.16.13 CVE-2026-74013 Patchstack
9.8 Critical User Registration & Membership Pro Plugin user-registration-pro Privilege Escalation Account Takeover No login needed ≤ 5.4.5 Fixed in 5.4.6 CVE-2026-74001 Patchstack
8.5 High WP w3all phpBB Plugin wp-w3all-phpbb-integration SQL Injection ≤ 3.0.5 Fixed in 3.0.6 CVE-2026-73998 Patchstack
9.8 Critical FundEngine Plugin wp-fundraising-donation PHP Object Injection No login needed ≤ 1.7.9 Fixed in 1.8.0 CVE-2026-73993 Patchstack
9.9 Critical Query Wrangler Plugin query-wrangler Remote Code Execution ≤ 1.5.57 Fixed in 1.5.58 CVE-2026-73992 Patchstack
6.5 Medium WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting ≤ 6.3.2 Fixed in 6.4.0 CVE-2026-73402 Patchstack
9.3 Critical BookingPress Appointment Booking Pro Plugin bookingpress-appointment-booking-pro SQL Injection No login needed ≤ 6.0.2 CVE-2026-68566 Patchstack
7.1 High NotificationX Pro Plugin notificationx-pro Cross-Site Scripting No login needed ≤ 3.1.4 CVE-2026-68564 Patchstack
9.8 Critical Abandoned Cart Pro for WooCommerce Plugin woocommerce-abandon-cart-pro Privilege Escalation No login needed ≤ 10.4.0 CVE-2026-66682 Patchstack
9.3 Critical Locatoraid Store Locator Plugin locatoraid SQL Injection No login needed ≤ 3.9.72 CVE-2026-66680 Patchstack
7.6 High Leyka Plugin leyka Authentication Bypass Broken Authentication ≤ 3.32.3 CVE-2026-66677 Patchstack
7.1 High Flatastic Theme flatastic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2026-66673 Patchstack
9.8 Critical Flatastic Theme flatastic PHP Object Injection No login needed ≤ 2.0 CVE-2026-66672 Patchstack
9.3 Critical Directory Pro Plugin directory-pro SQL Injection No login needed ≤ 2.5.8 CVE-2026-66649 Patchstack
6.5 Medium Homlisti Theme homlisti Broken Access Control ≤ 3.1.2 CVE-2026-66647 Patchstack
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting No login needed ≤ 1.15.48 CVE-2026-66616 Patchstack
7.1 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2026-66615 Patchstack
7.1 High SEO Plugin by Squirrly SEO Plugin squirrly-seo Cross-Site Scripting No login needed ≤ 14.2.2 Fixed in 14.2.3 CVE-2026-66614 Patchstack
7.1 High Aora Theme aora Cross-Site Scripting No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2026-66612 Patchstack
7.1 High Paymob for WooCommerce Plugin paymob-for-woocommerce Cross-Site Scripting No login needed ≤ 4.1.10 Fixed in 4.1.11 CVE-2026-66611 Patchstack
9.3 Critical TheGem (Elementor) Theme thegem-elementor SQL Injection No login needed ≤ 5.12.3 Fixed in 5.12.3.1 CVE-2026-66609 Patchstack
7.1 High Advance Product Search Plugin th-advance-product-search Cross-Site Scripting No login needed ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-66607 Patchstack
7.1 High SmartSMTP Plugin smart-smtp Cross-Site Scripting No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-66606 Patchstack
7.1 High Swatchly – WooCommerce Variation Swatches for Products Plugin swatchly Cross-Site Scripting WooCommerce Variation Swatches for Products plugin <= 1.4.13 - Cross Site Scripting (XSS) No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2026-66605 Patchstack
7.1 High GeoDirectory Plugin geodirectory Cross-Site Scripting No login needed ≤ 2.8.173 Fixed in 2.8.174 CVE-2026-66604 Patchstack
6.5 Medium Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting ≤ 3.39 Fixed in 3.40 CVE-2026-66601 Patchstack
9.1 Critical Media LIbrary Assistant Plugin media-library-assistant Arbitrary File Upload ≤ 3.39 Fixed in 3.40 CVE-2026-66600 Patchstack
7.1 High B2BKing Premium Plugin b2bking Cross-Site Scripting No login needed ≤ 5.6.07 Fixed in 5.6.08 CVE-2026-66598 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 6.5.1.4 Fixed in 6.5.1.5 CVE-2026-66597 Patchstack
5.9 Medium WP Data Access Plugin wp-data-access Broken Access Control No login needed ≤ 5.5.80 Fixed in 5.5.81 CVE-2026-66595 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only