WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 2,001–2,050 of 17,704 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Mixed Media Gallery Blocks | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute |
≤ 3.3.3.1 |
CVE-2026-5743 |
Wordfence | |
| 4.3 Medium | MyParcel | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions |
≤ 4.25.1 |
CVE-2026-8678 |
Wordfence | |
| 6.5 Medium | UnderConstructionPage PRO | Path Traversal Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter |
≤ 5.76 |
CVE-2026-11426 |
Wordfence | |
| 5.3 Medium | Eventin | Broken Access Control Missing Authorization to Unauthenticated Payment Bypass via REST API No login needed |
4.0.26 – 4.1.15 |
CVE-2026-13039 |
Wordfence | |
| 4.4 Medium | Ajax Load More | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 7.0.1 |
CVE-2026-15295 |
Wordfence | |
| 6.4 Medium | Logo Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter |
≤ 5.5 |
CVE-2026-13247 |
Wordfence | |
| 5.3 Medium | KiviCare | Broken Access Control Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint No login needed |
≤ 4.4.0 |
CVE-2026-11990 |
Wordfence | |
| 6.4 Medium | Jeg Kit for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget |
≤ 3.2.6 |
CVE-2026-13710 |
Wordfence | |
| 4.9 Medium | Mail Mint | SQL Injection Authenticated (Administrator+) SQL Injection via 'recipients' Parameter |
≤ 1.24.1 |
CVE-2026-12918 |
Wordfence | |
| 6.5 Medium | JoomSport | SQL Injection Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute |
≤ 5.7.9 |
CVE-2026-13010 |
Wordfence | |
| 4.3 Medium | Invoice123 | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions |
≤ 1.7.0 |
CVE-2026-9857 |
Wordfence | |
| 6.1 Medium | ICS Calendar | Cross-Site Scripting Reflected Cross-Site Scripting via 'htmltagtitle' Parameter No login needed |
≤ 12.0.9 |
CVE-2026-9838 |
Wordfence | |
| 4.3 Medium | Import and export users and customers | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action |
≤ 2.4.0 |
CVE-2026-15026 |
Wordfence | |
| 4.3 Medium | Easy Appointments | Broken Access Control Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation |
≤ 3.12.27 |
CVE-2026-11992 |
Wordfence | |
| 4.3 Medium | Cookie Banner for GDPR / CCPA | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action |
≤ 4.3.6 |
CVE-2026-12955 |
Wordfence | |
| 4.3 Medium | GoodMeet | Cross-Site Request Forgery Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential' No login needed |
≤ 1.1.8 |
CVE-2026-6440 |
Wordfence | |
| 6.6 Medium | HappyForms | Local File Inclusion Authenticated (Admin+) Local File Inclusion |
≤ 1.26.12 |
CVE-2025-11977 |
Wordfence | |
| 4.3 Medium | FlowForms | Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints |
≤ 1.1.1 |
CVE-2026-12400 |
Wordfence | |
| 5.3 Medium | Easy Upload Files During Checkout | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter No login needed |
≤ 3.0.1 |
CVE-2026-6802 |
Wordfence | |
| 4.3 Medium | GW AI Website Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion |
≤ 1.0.1 |
CVE-2026-1946 |
Wordfence | |
| 4.9 Medium | Cookie Banner for GDPR / CCPA | SQL Injection Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter |
≤ 4.3.6 |
CVE-2026-14475 |
Wordfence | |
| 6.4 Medium | Eventin | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter |
≤ 4.1.15 |
CVE-2026-12924 |
Wordfence | |
| 6.4 Medium | Hostel | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode |
≤ 1.1.7 |
CVE-2026-3907 |
Wordfence | |
| 6.5 Medium | BetterDocs | SQL Injection Authenticated (Custom+) SQL Injection via 'lang' Parameter |
≤ 4.6.0 |
CVE-2026-15104 |
Wordfence | |
| 4.4 Medium | Highlighting Code Block | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting |
≤ 2.2.0 |
CVE-2026-12108 |
Wordfence | |
| 5.3 Medium | LA-Studio Element Kit for Elementor | Broken Access Control Unauthenticated Open Registration No login needed |
< 1.6.1 Fixed in 1.6.1 |
CVE-2026-12276 |
WPScan | |
| 6.4 Medium | All-in-One Video Gallery | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter |
≤ 4.8.5 |
CVE-2026-12123 |
Wordfence | |
| 6.4 Medium | BuddyHolis TableSearch | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2026-15301 |
Wordfence | |
| 6.4 Medium | Animation Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget |
≤ 2.6.3 |
CVE-2026-15299 |
Wordfence | |
| 6.1 Medium | Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.1.77 |
CVE-2026-15297 |
Wordfence | |
| 6.4 Medium | affiliate-toolkit – WP Affiliate Plugin with Amazon | Cross-Site Scripting WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.7.0 |
CVE-2026-15296 |
Wordfence | |
| 6.4 Medium | Sudoku Shortcode | Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute |
≤ 1.0.0 |
CVE-2026-15292 |
Wordfence | |
| 5.9 Medium | Booking calendar, Appointment Booking System | SQL Injection Unauthenticated Time-Based SQL Injection via 'wpdevart_id' No login needed |
≤ 3.2.17 |
CVE-2026-15289 |
Wordfence | |
| 6.5 Medium | rtMedia for WordPress, BuddyPress and bbPress | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 4.6.18 |
CVE-2026-15287 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP – Page Builder Features | Broken Access Control Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication |
≤ 3.5.32 |
CVE-2026-15286 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes |
≤ 6.4.11 |
CVE-2026-15285 |
Wordfence | |
| 6.4 Medium | King Addons for Elementor | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter |
≤ 51.1.62 |
CVE-2026-15284 |
Wordfence | |
| 5.3 Medium | ARMember | Path Traversal Directory Traversal via X-FILENAME No login needed |
≤ 4.0.27 |
CVE-2026-15302 |
Wordfence | |
| 4.4 Medium | WPvivid Backup for MainWP | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 0.9.33 |
CVE-2026-15283 |
Wordfence | |
| 5.4 Medium | WPCafe | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API |
≤ 3.0.14 |
CVE-2026-11818 |
Wordfence | |
| 6.1 Medium | WP Hotel Booking | Cross-Site Scripting Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters No login needed |
≤ 2.3.1 |
CVE-2026-11392 |
Wordfence | |
| 5.4 Medium | Fluent Forms | Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' |
≤ 6.2.1 |
CVE-2026-5069 |
Wordfence | |
| 6.5 Medium | Blocks for ACF Fields | Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary ACF Field Value Disclosure via 'id' Parameter |
≤ 1.6.2 |
CVE-2026-12428 |
Wordfence | |
| 5.3 Medium | Easy Invoice | Broken Access Control Unauthenticated Arbitrary Quote Accept/Decline and Invoice Creation via easy_invoice_accept_quote / easy_invoice_decline_quote AJAX Actions No login needed |
≤ 2.2.19 |
CVE-2026-9021 |
Wordfence | |
| 4.3 Medium | Employee, Leave and Recruitment Management System | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Job Deletion via crewhrm_singleJobAction AJAX Action |
≤ 1.2.2 |
CVE-2026-9237 |
Wordfence | |
| 4.3 Medium | DHL eCommerce (Benelux) for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions |
≤ 2.2.3 |
CVE-2026-9235 |
Wordfence | |
| 4.3 Medium | DSGVO All in one for WP | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset |
≤ 4.9 |
CVE-2026-4298 |
Wordfence | |
| 5.3 Medium | CorvusPay WooCommerce Payment Gateway | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter No login needed |
≤ 2.7.4 |
CVE-2026-9028 |
Wordfence | |
| 5.3 Medium | CorvusPay WooCommerce Payment Gateway | Price Manipulation Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint No login needed |
≤ 2.7.4 |
CVE-2026-9027 |
Wordfence | |
| 4.3 Medium | Colissimo Officiel : Méthodes de livraison pour WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX action |
≤ 2.9.0 |
CVE-2026-9240 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.