WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,051–2,100 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 42 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Hydra Booking Plugin hydra-booking Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter ≤ 1.2.1 CVE-2026-12433 Wordfence
4.9 Medium Mail Mint Plugin mail-mint SQL Injection Authenticated (Administrator+) SQL Injection via 'contact_ids' Parameter ≤ 1.24.2 CVE-2026-14342 Wordfence
5.3 Medium User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin wp-user-frontend Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter No login needed ≤ 4.3.7 CVE-2026-12418 Wordfence
4.3 Medium Memberships and User Profiles for WooCommerce Plugin ecommerce-user-profiles-by-profilegrid Broken Access Control Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation ≤ 3.4 CVE-2026-11359 Wordfence
5.3 Medium GamiPress Plugin gamipress Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter No login needed ≤ 7.9.4 CVE-2026-13450 Wordfence
6.1 Medium Mang Board WP Plugin mangboard Cross-Site Scripting Reflected Cross-Site Scripting via 'stag' Parameter No login needed ≤ 2.3.4 CVE-2026-13334 Wordfence
6.5 Medium ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support Plugin erp SQL Injection Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter ≤ 1.17.5 CVE-2026-13011 Wordfence
5.3 Medium User Frontend Plugin wp-user-frontend Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter No login needed ≤ 4.3.7 CVE-2026-12406 Wordfence
6.4 Medium Bookero.pl Plugin bookeropl Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 2.2 CVE-2026-6910 Wordfence
6.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute ≤ 5.113.0 CVE-2026-13771 Wordfence
6.5 Medium Backup and Staging by WP Time Capsule Plugin wp-time-capsule Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function ≤ 1.22.26 CVE-2026-8996 Wordfence
6.6 Medium WPFunnels Plugin wpfunnels Local File Inclusion Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter ≤ 3.12.7 CVE-2026-13080 Wordfence
5.3 Medium Age Verification & Identity Verification by Token of Trust Plugin token-of-trust Broken Access Control Missing Authorization to Unauthenticated Information Exposure via 'tot_export_table' Parameter No login needed ≤ 4.0.2 CVE-2026-7558 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes ≤ 3.3.61 CVE-2026-14343 Wordfence
6.4 Medium AcyMailing Plugin acymailing Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute ≤ 10.10.2 CVE-2026-12170 Wordfence
6.4 Medium Post Grid Gutenberg Blocks for News, Magazines, Blog Websites Plugin ultimate-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute ≤ 5.0.31 CVE-2026-13253 Wordfence
6.4 Medium Block, Suspend, Report for BuddyPress Plugin bp-toolkit Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter ≤ 3.6.4 CVE-2026-4653 Wordfence
5.3 Medium Fediverse Embeds Plugin fediverse-embeds Server-Side Request Forgery Unauthenticated SSRF via Site Info Endpoint No login needed < 1.5.8 Fixed in 1.5.8 CVE-2026-12517 WPScan
5.3 Medium Fediverse Embeds Plugin fediverse-embeds Server-Side Request Forgery Unauthenticated SSRF via Media Proxy No login needed < 1.5.8 Fixed in 1.5.8 CVE-2026-12516 WPScan
6.5 Medium Everest Forms Plugin everest-forms Broken Access Control Unauthenticated Missing Authorization via Site Assistant REST Endpoints No login needed 3.4.2 – < 3.5.0 Fixed in 3.5.0 CVE-2026-12270 WPScan
5.3 Medium WP Support Plus Responsive Ticket System Plugin Broken Access Control Unauthenticated Support Ticket Access via Session Cookie Forgery No login needed ≤ 9.1.2 CVE-2026-11875 WPScan
5.3 Medium WP DSGVO Tools (GDPR) Plugin shapepress-dsgvo Information Disclosure Unauthenticated Sensitive Information Disclosure via Subject Access Request No login needed < 3.1.40 Fixed in 3.1.40 CVE-2026-11869 WPScan
6.4 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute ≤ 4.7.4 CVE-2026-6740 Wordfence
4.7 Medium Smash Balloon Social Photo Feed – Easy Social Feeds Plugin instagram-feed Cross-Site Request Forgery Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter No login needed ≤ 6.11.1 CVE-2026-12002 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup ≤ 6.6.2 CVE-2026-6459 Wordfence
5.3 Medium User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin wp-user-frontend Broken Access Control Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite No login needed ≤ 4.3.1 CVE-2026-5459 Wordfence
6.4 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute ≤ 2026.1 CVE-2026-6742 Wordfence
6.4 Medium Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Plugin coming-soon Cross-Site Scripting Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode ≤ 6.20.2 CVE-2025-14785 Wordfence
6.3 Medium Themehunk Login Registration Plugin themehunk-login-registration Privilege Escalation Unauthenticated Privilege Escalation via 'role' Parameter ≤ 1.0.2 CVE-2026-14250 Wordfence
4.9 Medium Recurio Plugin recurio SQL Injection Authenticated (Shop Manager+) SQL Injection via 'data' Parameter ≤ 1.1.3 CVE-2026-12936 Wordfence
5.3 Medium Bulk Order Update for WooCommerce Plugin bulk-order-update-for-woocommerce Path Traversal Unauthenticated Arbitrary File Read via 'csv_url' Parameter No login needed ≤ 1.6 CVE-2026-14500 Wordfence
6.4 Medium Sympl Repeater for ACF and Elementor Plugin acf-repeater-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via ACF Repeater Field Values ≤ 2.3 CVE-2026-10570 Wordfence
4.3 Medium Wp Js Detect Plugin wp-js-detect Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0.9 CVE-2026-9731 Wordfence
5.3 Medium User Management Plugin user-management Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 1.2 CVE-2026-12097 Wordfence
4.4 Medium Chatra Live Chat + ChatBot + Cart Saver Plugin chatra-live-chat Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting ≤ 1.0.12 CVE-2026-12041 Wordfence
6.1 Medium Social Share, Social Login and Social Comments Plugin super-socializer Cross-Site Scripting Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter No login needed ≤ 7.14.5 CVE-2026-11798 Wordfence
4.6 Medium WP Travel Engine Plugin wp-travel-engine Path Traversal Subscriber+ Arbitrary Media File Move via user_profile_image < 6.8.1 Fixed in 6.8.1 CVE-2026-10834 WPScan
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 2.7.9.8 CVE-2026-11328 Wordfence
6.4 Medium Reviews Widgets for Google, Yelp & TripAdvisor Plugin fb-reviews-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute ≤ 2.7.3 CVE-2026-12154 Wordfence
4.3 Medium CrawlWP SEO Plugin mihdan-index-now Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2026-59520 Patchstack
5.3 Medium FormLayer Plugin formlayer Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-59519 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.9.9 Fixed in 2.8.0 CVE-2026-59511 Patchstack
4.3 Medium RTMKit Plugin rometheme-for-elementor Local File Inclusion Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter ≤ 2.0.7 CVE-2026-5137 Wordfence
5.3 Medium LatePoint Plugin latepoint Broken Access Control Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step No login needed ≤ 5.6.1 CVE-2026-11398 Wordfence
6.4 Medium GenerateBlocks Plugin generateblocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute ≤ 2.2.1 CVE-2026-9756 Wordfence
6.4 Medium Zakra Theme zakra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API ≤ 4.2.0 CVE-2026-4804 Wordfence
4.3 Medium Ad Inserter Plugin ad-inserter Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute ≤ 2.8.16 CVE-2026-11900 Wordfence
5.4 Medium CURCY Plugin woo-multi-currency Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter ≤ 2.2.14 CVE-2026-11778 Wordfence
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure ≤ 11.1.4 CVE-2026-9230 Wordfence
6.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter ≤ 2.0.7 CVE-2026-8351 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only