WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,051–2,100 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 42 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Prague Plugin prague-plugins Cross-Site Scripting No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-15654 Patchstack
7.5 High ARMember Premium Plugin SQL Injection Unauthenticated SQL Injection via 'order' Parameter No login needed ≤ 7.3.1 CVE-2026-5073 Wordfence
8.8 High Content Visibility for Divi Builder Plugin content-visibility-for-divi-builder Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 4.02 CVE-2026-1829 Wordfence
7.5 High BookIt Plugin bookit Authentication Bypass Broken Authentication No login needed < 2.5.4.1 Fixed in 2.5.4.1 CVE-2026-40780 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Authentication Bypass Broken Authentication ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-42654 Patchstack
8.1 High Cookiteer Theme cookiteer Local File Inclusion No login needed ≤ 1.4.8 CVE-2025-68886 Patchstack
8.1 High Racquet Theme racquet Local File Inclusion No login needed ≤ 1.12.0 CVE-2025-69369 Patchstack
8.1 High Fermentio Theme fermentio Local File Inclusion No login needed ≤ 1.5.0 CVE-2025-58897 Patchstack
8.1 High Spin Theme spin Local File Inclusion No login needed ≤ 1.8 CVE-2025-58707 Patchstack
8.1 High Askka Theme askka PHP Object Injection No login needed ≤ 1.3.1 Fixed in 1.4 CVE-2026-39555 Patchstack
8.1 High WaveRide Theme waveride Local File Inclusion No login needed ≤ 1.4 Fixed in 1.5 CVE-2026-39553 Patchstack
8.1 High Blueprint Theme blueprint Local File Inclusion No login needed < 1.1.5 Fixed in 1.1.5 CVE-2026-39552 Patchstack
8.1 High Töbel Theme tobel PHP Object Injection No login needed ≤ 1.8.1 Fixed in 1.9 CVE-2026-39551 Patchstack
8.1 High Aperitif Theme aperitif PHP Object Injection No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2026-39550 Patchstack
7.1 High WP Job Portal Plugin wp-job-portal Cross-Site Scripting No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-42685 Patchstack
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Price Manipulation Payment Bypass No login needed ≤ 2.7.14 Fixed in 2.7.15 CVE-2026-42670 Patchstack
7.5 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 4.3.2.0 Fixed in 4.3.2.1 CVE-2026-42669 Patchstack
8.1 High Crafti Theme crafti Local File Inclusion No login needed ≤ 1.12 CVE-2025-58705 Patchstack
7.5 High Accordion FAQ Plugin pressapps-accordion-faq Local File Inclusion ≤ 2.2.1 CVE-2025-58024 Patchstack
8.1 High Confidant Theme confidant Local File Inclusion No login needed ≤ 1.4 CVE-2025-53440 Patchstack
8.8 High Thim Core Plugin thim-core Broken Access Control Arbitrary plugin Installation ≤ 2.3.3 CVE-2025-53345 Patchstack
7.1 High Accordion FAQ Plugin pressapps-accordion-faq Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2025-52759 Patchstack
7.5 High Really Simple Security Plugin really-simple-ssl Authentication Bypass Authentication Bypass via Two-Factor OTP Skip < 9.5.10.1 Fixed in 9.5.10.1 CVE-2026-8293 WPScan
8.2 High WP AutoSuggest Plugin wp-autosuggest SQL Injection WP AutoSuggest 0.24 SQL Injection via autosuggest.php No login needed 0.24 CVE-2018-25434 VulnCheck
7.5 High Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Plugin logtivity Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2026-42673 Patchstack
7.5 High Advanced Access Manager Plugin advanced-access-manager Authentication Bypass Bypass Vulnerability No login needed ≤ 7.1.0 Fixed in 7.1.1 CVE-2026-42674 Patchstack
7.3 High Hydra Booking Plugin hydra-booking Broken Access Control No login needed ≤ 1.1.41 Fixed in 1.1.42 CVE-2026-42675 Patchstack
7.5 High WP Document Revisions Plugin wp-document-revisions Broken Access Control No login needed < 4.0.0 Fixed in 4.0.0 CVE-2026-42677 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.14.5 Fixed in 4.14.6 CVE-2026-42678 Patchstack
7.1 High e2pdf Plugin e2pdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.32.14 Fixed in 1.32.15 CVE-2026-42681 Patchstack
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting No login needed ≤ 1.8.8 Fixed in 1.8.9 CVE-2026-42683 Patchstack
7.1 High WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.6 Fixed in 14.16.7 CVE-2026-48839 Patchstack
7.1 High LearnPress Plugin learnpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.6 Fixed in 4.3.7 CVE-2026-48865 Patchstack
8.8 High Spectra Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Arbitrary PHP Function Call via Block Attributes ≤ 2.19.25 CVE-2026-7465 Wordfence
7.5 High Simple History – Track, Log, and Audit WordPress Changes Plugin simple-history Privilege Escalation Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction Endpoint ≤ 5.26.0 CVE-2026-7459 Wordfence
7.5 High GEO my WP Plugin geo-my-wp SQL Injection Unauthenticated SQL Injection via 'swlatlng' / 'nelatlng' Parameters No login needed ≤ 4.5.5 CVE-2026-9757 Wordfence
8.1 High Media Library Assistant Plugin media-library-assistant Cross-Site Request Forgery Cross-Site Request Forgery via Bulk Action Form No login needed ≤ 3.35 CVE-2026-6075 Wordfence
7.2 High Link Whisper Free Plugin link-whisper Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 0.9.0 CVE-2025-11262 Wordfence
8.8 High WooCommerce Infinite Scroll and Ajax Pagination Plugin PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 1.8 CVE-2025-11993 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation via Form Configuration Injection ≤ 3.29.2 CVE-2026-6226 Wordfence
7.2 High HT Contact Form Plugin ht-contactform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via File Upload Field No login needed ≤ 2.8.2 CVE-2026-7052 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.11.8 CVE-2026-7797 Wordfence
8.1 High WP Contact Form 7 DB Handler Plugin wp-contact-form-7-db-handler Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter No login needed ≤ 3.0 CVE-2026-6455 Wordfence
8.8 High GutenBee Plugin gutenbee Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via wp_check_filetype_and_ext Filter ≤ 2.20.1 CVE-2026-9227 Wordfence
7.2 High SlimStat Analytics Plugin wp-slimstat Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via User-Agent Header No login needed ≤ 5.4.11 CVE-2026-7634 Wordfence
8.6 High Eupago Gateway For Woocommerce Plugin eupago-gateway-for-woocommerce Broken Access Control Unauthenticated Arbitrary Refund Initiation No login needed < 4.7.2 Fixed in 4.7.2 CVE-2026-7862 WPScan
8.8 High Crawlomatic Multipage Scraper Post Generator Plugin crawlomatic-multipage-scraper-post-generator Remote Code Execution Authenticated (Author+) Remote Code Execution via 'callback_raw' Shortcode Attribute ≤ 2.7.2 CVE-2026-9009 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover via 'user_id' URL Query Parameter ≤ 3.29.2 CVE-2026-7802 Wordfence
7.2 High Login No Captcha reCAPTCHA Plugin login-recaptcha Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via PHP_SELF No login needed ≤ 1.8.0 CVE-2026-2374 Wordfence
8.5 High Duplicate Page and Post Plugin duplicate-wp-page-post SQL Injection ≤ 2.9.5 CVE-2026-49046 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only