WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 2,051–2,100 of 9,010 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Prague | Cross-Site Scripting No login needed |
≤ 2.2.8 Fixed in 2.2.9 |
CVE-2025-15654 |
Patchstack | |
| 7.5 High | ARMember Premium | SQL Injection Unauthenticated SQL Injection via 'order' Parameter No login needed |
≤ 7.3.1 |
CVE-2026-5073 |
Wordfence | |
| 8.8 High | Content Visibility for Divi Builder | Remote Code Execution Authenticated (Contributor+) Remote Code Execution |
≤ 4.02 |
CVE-2026-1829 |
Wordfence | |
| 7.5 High | BookIt | Authentication Bypass Broken Authentication No login needed |
< 2.5.4.1 Fixed in 2.5.4.1 |
CVE-2026-40780 |
Patchstack | |
| 7.1 High | Wallet System for WooCommerce | Authentication Bypass Broken Authentication |
≤ 2.7.5 Fixed in 2.7.6 |
CVE-2026-42654 |
Patchstack | |
| 8.1 High | Cookiteer | Local File Inclusion No login needed |
≤ 1.4.8 |
CVE-2025-68886 |
Patchstack | |
| 8.1 High | Racquet | Local File Inclusion No login needed |
≤ 1.12.0 |
CVE-2025-69369 |
Patchstack | |
| 8.1 High | Fermentio | Local File Inclusion No login needed |
≤ 1.5.0 |
CVE-2025-58897 |
Patchstack | |
| 8.1 High | Spin | Local File Inclusion No login needed |
≤ 1.8 |
CVE-2025-58707 |
Patchstack | |
| 8.1 High | Askka | PHP Object Injection No login needed |
≤ 1.3.1 Fixed in 1.4 |
CVE-2026-39555 |
Patchstack | |
| 8.1 High | WaveRide | Local File Inclusion No login needed |
≤ 1.4 Fixed in 1.5 |
CVE-2026-39553 |
Patchstack | |
| 8.1 High | Blueprint | Local File Inclusion No login needed |
< 1.1.5 Fixed in 1.1.5 |
CVE-2026-39552 |
Patchstack | |
| 8.1 High | Töbel | PHP Object Injection No login needed |
≤ 1.8.1 Fixed in 1.9 |
CVE-2026-39551 |
Patchstack | |
| 8.1 High | Aperitif | PHP Object Injection No login needed |
≤ 1.6 Fixed in 1.6.1 |
CVE-2026-39550 |
Patchstack | |
| 7.1 High | WP Job Portal | Cross-Site Scripting No login needed |
≤ 2.5.1 Fixed in 2.5.2 |
CVE-2026-42685 |
Patchstack | |
| 7.5 High | Five Star Restaurant Reservations | Price Manipulation Payment Bypass No login needed |
≤ 2.7.14 Fixed in 2.7.15 |
CVE-2026-42670 |
Patchstack | |
| 7.5 High | EventPrime | Broken Access Control No login needed |
≤ 4.3.2.0 Fixed in 4.3.2.1 |
CVE-2026-42669 |
Patchstack | |
| 8.1 High | Crafti | Local File Inclusion No login needed |
≤ 1.12 |
CVE-2025-58705 |
Patchstack | |
| 7.5 High | Accordion FAQ | Local File Inclusion |
≤ 2.2.1 |
CVE-2025-58024 |
Patchstack | |
| 8.1 High | Confidant | Local File Inclusion No login needed |
≤ 1.4 |
CVE-2025-53440 |
Patchstack | |
| 8.8 High | Thim Core | Broken Access Control Arbitrary plugin Installation |
≤ 2.3.3 |
CVE-2025-53345 |
Patchstack | |
| 7.1 High | Accordion FAQ | Cross-Site Scripting No login needed |
≤ 2.2.1 |
CVE-2025-52759 |
Patchstack | |
| 7.5 High | Really Simple Security | Authentication Bypass Authentication Bypass via Two-Factor OTP Skip |
< 9.5.10.1 Fixed in 9.5.10.1 |
CVE-2026-8293 |
WPScan | |
| 8.2 High | WP AutoSuggest | SQL Injection WP AutoSuggest 0.24 SQL Injection via autosuggest.php No login needed |
0.24 |
CVE-2018-25434 |
VulnCheck | |
| 7.5 High | Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity | Information Disclosure Sensitive Data Exposure No login needed |
≤ 3.3.6 Fixed in 3.3.7 |
CVE-2026-42673 |
Patchstack | |
| 7.5 High | Advanced Access Manager | Authentication Bypass Bypass Vulnerability No login needed |
≤ 7.1.0 Fixed in 7.1.1 |
CVE-2026-42674 |
Patchstack | |
| 7.3 High | Hydra Booking | Broken Access Control No login needed |
≤ 1.1.41 Fixed in 1.1.42 |
CVE-2026-42675 |
Patchstack | |
| 7.5 High | WP Document Revisions | Broken Access Control No login needed |
< 4.0.0 Fixed in 4.0.0 |
CVE-2026-42677 |
Patchstack | |
| 7.1 High | GiveWP | Cross-Site Scripting No login needed |
≤ 4.14.5 Fixed in 4.14.6 |
CVE-2026-42678 |
Patchstack | |
| 7.1 High | e2pdf | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.32.14 Fixed in 1.32.15 |
CVE-2026-42681 |
Patchstack | |
| 7.1 High | VikBooking Hotel Booking Engine & PMS | Cross-Site Scripting No login needed |
≤ 1.8.8 Fixed in 1.8.9 |
CVE-2026-42683 |
Patchstack | |
| 7.1 High | WP Statistics | Cross-Site Scripting No login needed |
≤ 14.16.6 Fixed in 14.16.7 |
CVE-2026-48839 |
Patchstack | |
| 7.1 High | LearnPress | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.3.6 Fixed in 4.3.7 |
CVE-2026-48865 |
Patchstack | |
| 8.8 High | Spectra Gutenberg Blocks | Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes |
≤ 2.19.25 |
CVE-2026-7465 |
Wordfence | |
| 7.5 High | Simple History – Track, Log, and Audit WordPress Changes | Privilege Escalation Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction Endpoint |
≤ 5.26.0 |
CVE-2026-7459 |
Wordfence | |
| 7.5 High | GEO my WP | SQL Injection Unauthenticated SQL Injection via 'swlatlng' / 'nelatlng' Parameters No login needed |
≤ 4.5.5 |
CVE-2026-9757 |
Wordfence | |
| 8.1 High | Media Library Assistant | Cross-Site Request Forgery Cross-Site Request Forgery via Bulk Action Form No login needed |
≤ 3.35 |
CVE-2026-6075 |
Wordfence | |
| 7.2 High | Link Whisper Free | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 0.9.0 |
CVE-2025-11262 |
Wordfence | |
| 8.8 High | WooCommerce Infinite Scroll and Ajax Pagination | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 1.8 |
CVE-2025-11993 |
Wordfence | |
| 8.8 High | Frontend Admin by DynamiApps | Privilege Escalation Unauthenticated Privilege Escalation via Form Configuration Injection |
≤ 3.29.2 |
CVE-2026-6226 |
Wordfence | |
| 7.2 High | HT Contact Form | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via File Upload Field No login needed |
≤ 2.8.2 |
CVE-2026-7052 |
Wordfence | |
| 7.5 High | Appointment Booking Calendar | SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed |
≤ 1.6.11.8 |
CVE-2026-7797 |
Wordfence | |
| 8.1 High | WP Contact Form 7 DB Handler | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter No login needed |
≤ 3.0 |
CVE-2026-6455 |
Wordfence | |
| 8.8 High | GutenBee | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter |
≤ 2.20.1 |
CVE-2026-9227 |
Wordfence | |
| 7.2 High | SlimStat Analytics | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via User-Agent Header No login needed |
≤ 5.4.11 |
CVE-2026-7634 |
Wordfence | |
| 8.6 High | Eupago Gateway For Woocommerce | Broken Access Control Unauthenticated Arbitrary Refund Initiation No login needed |
< 4.7.2 Fixed in 4.7.2 |
CVE-2026-7862 |
WPScan | |
| 8.8 High | Crawlomatic Multipage Scraper Post Generator | Remote Code Execution Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute |
≤ 2.7.2 |
CVE-2026-9009 |
Wordfence | |
| 8.8 High | Frontend Admin by DynamiApps | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter |
≤ 3.29.2 |
CVE-2026-7802 |
Wordfence | |
| 7.2 High | Login No Captcha reCAPTCHA | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via PHP_SELF No login needed |
≤ 1.8.0 |
CVE-2026-2374 |
Wordfence | |
| 8.5 High | Duplicate Page and Post | SQL Injection |
≤ 2.9.5 |
CVE-2026-49046 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.