WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,001–2,050 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 41 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High GetPaid Plugin invoicing Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.49 Fixed in 2.8.50 CVE-2026-49064 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system Privilege Escalation LMS plugin <= 2.2.0 - Privilege Escalation ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-49111 Patchstack
8.8 High Faust.js Plugin faustwp Authentication Bypass Broken Authentication ≤ 1.8.7 Fixed in 1.8.8 CVE-2026-49062 Patchstack
7.1 High Sliced Invoices Plugin sliced-invoices SQL Injection WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter 3.8.2 CVE-2019-25746 VulnCheck
7.5 High HB Audio Gallery Lite Plugin hb-audio-gallery-lite Path Traversal WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download No login needed 1.0.0 CVE-2016-20081 VulnCheck
8.2 High Answer My Question Plugin answer-my-question SQL Injection Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php No login needed 1.3 CVE-2016-20073 VulnCheck
8.2 High BBS e-Franchise Plugin bbs-e-franchise SQL Injection BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid No login needed 1.1.1 CVE-2016-20072 VulnCheck
8.2 High 404 Redirection Manager Plugin 404-redirection-manager SQL Injection WordPress 404 Redirection Manager Plugin 1.0 SQL Injection No login needed 1.0 CVE-2016-20071 VulnCheck
7.2 High Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie No login needed ≤ 27.2 CVE-2026-5513 Wordfence
7.2 High GPTranslate Plugin gptranslate Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage No login needed ≤ 2.31 CVE-2026-9109 Wordfence
7.5 High WP Ticket Plugin wp-ticket SQL Injection Unauthenticated SQL Injection via WordPress Search 's' Parameter No login needed ≤ 6.0.4 CVE-2026-9848 Wordfence
7.1 High SliceWP Plugin slicewp Cross-Site Scripting No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2026-42653 Patchstack
7.1 High WP Mail Log Plugin wp-mail-log Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 Fixed in 1.1.1 CVE-2023-33999 Patchstack
8.1 High UpdraftPlus: WP Backup & Migration Plugin updraftplus Authentication Bypass Unauthenticated Authentication Bypass via UpdraftCentral udrpc No login needed ≤ 1.26.4 CVE-2026-10795 Wordfence
8.1 High Copy & Delete Posts Plugin copy-delete-posts Privilege Escalation Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler ≤ 1.5.4 CVE-2026-53738 VulnCheck
7.1 High WPZOOM Portfolio Plugin wpzoom-portfolio Cross-Site Scripting No login needed ≤ 1.4.21 Fixed in 1.4.22 CVE-2026-49069 Patchstack
7.5 High Newsletters Plugin newsletters-lite SQL Injection Unauthenticated SQL Injection via wpmlsubscriber_id Parameter No login needed ≤ 4.13 CVE-2026-3018 Wordfence
8.8 High Spam protection, Honeypot, Anti-Spam by CleanTalk Plugin Cross-Site Scripting Unauthenticated Stored XSS via Comment Shortcode Bypass No login needed < 6.79 Fixed in 6.79 CVE-2026-8071 WPScan
8.6 High XStore Theme SQL Injection Unauthenticated SQLi No login needed < 9.7.3 Fixed in 9.7.3 CVE-2026-3326 WPScan
7.1 High BuddyPress Plugin buddypress Denial of Service BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution ≤ 14.4.0 CVE-2026-53674 VulnCheck
8.1 High BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter ≤ 14.4.0 CVE-2026-53673 VulnCheck
7.5 High Mac Photo Gallery Plugin Path Traversal WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download No login needed 3.0 CVE-2017-20250 VulnCheck
8.2 High Apptha Slider Gallery Plugin SQL Injection WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20249 VulnCheck
7.5 High Apptha Slider Gallery Plugin Path Traversal WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download No login needed 1.0 CVE-2017-20248 VulnCheck
8.2 High PICA Photo Gallery Plugin SQL Injection WordPress Plugin PICA Photo Gallery 1.0 SQL Injection No login needed 1.0 CVE-2017-20247 VulnCheck
8.2 High KittyCatfish Plugin SQL Injection KittyCatfish 2.2 Plugin for WordPress SQL Injection No login needed 2.2 CVE-2017-20246 VulnCheck
8.2 High Wow Viral Signups Plugin mwp-viral-signup SQL Injection Wow Viral Signups 2.1 WordPress Plugin SQL Injection No login needed 2.1 CVE-2017-20245 VulnCheck
8.2 High Wow Forms Plugin mwp-forms SQL Injection Wow Forms WordPress Plugin 2.1 SQL Injection No login needed 2.1 CVE-2017-20244 VulnCheck
8.2 High Product Catalog 8 Plugin product-catalog-8 SQL Injection Product Catalog 8 1.2 Plugin WordPress SQL Injection No login needed 1.2.0 CVE-2016-20065 VulnCheck
7.1 High Single Personal Message Plugin simple-personal-message SQL Injection Single Personal Message 1.0.3 WordPress Plugin SQL Injection 1.0.3 CVE-2016-20063 VulnCheck
8.2 High Simply Poll Plugin simply-poll SQL Injection Simply Poll 1.4.1 Plugin for WordPress SQL Injection No login needed 1.4.1 CVE-2016-20062 VulnCheck
8.8 High Blocksy Theme blocksy PHP Object Injection Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field ≤ 2.1.41 CVE-2026-8365 Wordfence
8.8 High Events Calendar for GeoDirectory Plugin events-for-geodirectory Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 2.3.28 CVE-2026-11616 Wordfence
7.5 High 6Storage Rentals Plugin 6storage-rentals Broken Access Control Unauthenticated Insecure Direct Object Reference to Arbitrary User Disclosure and Modification via 'userId' Parameter No login needed ≤ 2.22.0 CVE-2026-9185 Wordfence
8.1 High Recover Exit For WooCommerce Plugin recoverexit-for-woocommerce Local File Inclusion Unauthenticated Local File Inclusion via 'tpf' Parameter No login needed ≤ 1.0.3 CVE-2026-9662 Wordfence
7.2 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Text No login needed ≤ 7.5.49.7212 CVE-2026-7556 Wordfence
7.2 High Booking Package Plugin booking-package Privilege Escalation Authenticated (Editor+) Privilege Escalation via Account Takeover to updateUser AJAX Action ≤ 1.7.16 CVE-2026-9851 Wordfence
7.2 High MDJM Event Management Plugin mobile-dj-manager Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter ≤ 1.7.8.3 CVE-2026-7537 Wordfence
7.2 High Integration for Freshsales Plugin crm-integration-freshworks-any-form Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Submission Data No login needed ≤ 1.0.15 CVE-2026-8901 Wordfence
7.2 High All-In-One Security (AIOS) Plugin all-in-one-wp-security-and-firewall Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API Request Path No login needed ≤ 5.4.7 CVE-2026-8438 Wordfence
7.5 High WP User Manager Plugin wp-user-manager Path Traversal Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter No login needed ≤ 2.9.17 CVE-2026-9290 Wordfence
8.8 High Admin Columns Plugin codepress-admin-columns PHP Object Injection Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value ≤ 7.0.18 CVE-2026-7654 Wordfence
8.8 High WP Captcha PRO Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload ≤ 5.38 CVE-2026-5411 Wordfence
8.8 High WP Captcha PRO Plugin Authentication Bypass Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link ≤ 5.38 CVE-2026-5415 Wordfence
7.2 High Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns Plugin essential-blocks Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed ≤ 6.1.3 CVE-2026-10586 Wordfence
8.2 High Google Review Slider Plugin wp-google-places-review-slider SQL Injection WordPress Plugin Google Review Slider 6.1 SQL Injection via tid No login needed 6.1 CVE-2019-25745 VulnCheck
7.6 High Photo Gallery by 10Web Plugin photo-gallery SQL Injection ≤ 1.8.41 Fixed in 1.8.42 CVE-2026-49771 Patchstack
7.5 High SP Project & Document Manager Plugin sp-client-document-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function No login needed ≤ 4.71 CVE-2026-10737 Wordfence
8.8 High School Management Plugin school-management Privilege Escalation ≤ 93.2.0 CVE-2025-15656 Patchstack
7.6 High School Management Plugin school-management SQL Injection ≤ 93.2.0 CVE-2025-15655 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only