WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,101–2,150 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 43 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High SAML Single Sign On Plugin miniorange-saml-20-single-sign-on Privilege Escalation Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite No login needed 4.8.85 – < 5.4.7 Fixed in 5.4.7 CVE-2026-19842 WPScan
5.4 Medium WPS Bidouille Plugin wps-bidouille Information Disclosure Subscriber+ User Email Disclosure via wps_get_users < 1.33.5 Fixed in 1.33.5 CVE-2026-19782 WPScan
5.3 Medium Membership For WooCommerce Plugin membership-for-woocommerce Information Disclosure Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass No login needed < 3.1.2 Fixed in 3.1.2 CVE-2026-19709 WPScan
6.5 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Arbitrary Media Attachment Read via IDOR < 4.5.4 Fixed in 4.5.4 CVE-2026-19417 WPScan
4.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Patient+ Cross-Patient Appointment Modification via IDOR No login needed < 4.5.4 Fixed in 4.5.4 CVE-2026-19416 WPScan
2.7 Low Easy Appointments Plugin easy-appointments Information Disclosure Contributor+ Sensitive Information Disclosure via REST Appointments Listing 3.12.28 – < 4.0.1 Fixed in 4.0.1 CVE-2026-19406 WPScan
7.1 High ProSolution WP Client Plugin prosolution-wp-client Cross-Site Scripting Reflected XSS via 'page' Parameter No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-19056 WPScan
7.1 High ProSolution WP Client Plugin prosolution-wp-client Cross-Site Scripting Reflected XSS via Multiple Parameters No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-19055 WPScan
9.0 Critical Broken Link Checker Plugin broken-link-checker Remote Code Execution Unauthenticated RCE via Query Variable Injection No login needed < 2.4.12 Fixed in 2.4.12 CVE-2026-18937 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Appointment and Payment Record Deletion via update_appointment_booked No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18779 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Information Disclosure Unauthenticated Customer PII Disclosure via Multiple AJAX Actions No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18778 WPScan
5.3 Medium TrueBooker Appointment Booking Plugin Broken Access Control Unauthenticated Arbitrary Appointment Status Change via update_appointment_status No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18777 WPScan
9.8 Critical TrueBooker Appointment Booking Plugin Privilege Escalation Unauthenticated Account Takeover via Multiple AJAX Actions No login needed < 1.2.7 Fixed in 1.2.7 CVE-2026-18776 WPScan
5.4 Medium WP Maps Plugin wp-google-map-plugin Broken Access Control Subscriber+ Unlimited Autoloaded Option Creation < 4.9.8 Fixed in 4.9.8 CVE-2026-18466 WPScan
5.3 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Unauthenticated User Email Disclosure via select_2_ajax_user No login needed < 1.5.7 Fixed in 1.5.7 CVE-2026-18231 WPScan
6.8 Medium JetEngine Plugin Cross-Site Scripting Author+ Stored XSS via SVG Upload < 3.8.14 Fixed in 3.8.14 CVE-2026-18202 WPScan
10.0 Critical W3 Total Cache Plugin w3-total-cache Path Traversal Unauthenticated Arbitrary Directory File Write and .htaccess Overwrite via Path Traversal in the Page Cache Key No login needed < 2.10.5 Fixed in 2.10.5 CVE-2026-18051 WPScan
9.8 Critical TabaPay Gateway Plugin Privilege Escalation Unauthenticated Account Takeover via Payment Callback No login needed ≤ 1.4.0 CVE-2026-18031 WPScan
7.2 High Animation Addons for Elementor Plugin animation-addons-for-elementor Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 2.7.2 Fixed in 2.7.2 CVE-2026-17565 WPScan
4.3 Medium SmartCrawl Plugin Information Disclosure Subscriber+ Private/Draft Post Title Disclosure and Post Meta Key Enumeration < 3.16.3 Fixed in 3.16.3 CVE-2026-16979 WPScan
8.6 High Product Shortlist Plugin SQL Injection Unauthenticated SQL Injection via get_shortlisted_products No login needed ≤ 1.0.4 CVE-2026-16950 WPScan
8.8 High Simple File List Plugin Cross-Site Scripting Unauthenticated Stored XSS via File Description No login needed ≤ 6.3.11 CVE-2026-16617 WPScan
8.6 High Simple File List Plugin Path Traversal Unauthenticated Arbitrary File Read and Move via Path Traversal No login needed ≤ 6.3.11 CVE-2026-16616 WPScan
7.1 High NextScripts: Social Networks Auto-Poster Plugin social-networks-auto-poster-facebook-twitter-g Cross-Site Scripting Reflected XSS via Facebook OAuth Callback No login needed < 4.4.8 Fixed in 4.4.8 CVE-2026-16570 WPScan
5.3 Medium YayCurrency Plugin yaycurrency Information Disclosure Unauthenticated Order and Vendor Financial Data Disclosure via Dokan Integration No login needed < 3.3.5 Fixed in 3.3.5 CVE-2026-16058 WPScan
6.8 Medium Easy Media Replace Plugin Cross-Site Scripting Author+ Stored XSS via Attachment Title ≤ 0.2.0 CVE-2026-15253 WPScan
7.5 High User Verification Plugin Broken Access Control Unauthenticated Arbitrary Account Lockout via IDOR No login needed ≤ 2.0.47 CVE-2026-14861 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14826 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14825 WPScan
8.8 High Booking calendar, Appointment Booking System Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG File Upload No login needed 3.2.18 – 3.2.36 CVE-2026-14334 WPScan
4.7 Medium TenWeb Speed Optimizer Plugin Cross-Site Scripting Unauthenticated Stored XSS via Critical CSS Token Bypass No login needed < 2.33.5 Fixed in 2.33.5 CVE-2026-14287 WPScan
4.3 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Broken Access Control Store Vendor+ Cross-Vendor Review Deletion and Status Update via IDOR < 3.8.1 Fixed in 3.8.1 CVE-2026-14196 WPScan
6.5 Medium Eventin Plugin wp-event-solution Broken Access Control Contributor+ Schedule Deletion and Modification via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13175 WPScan
7.2 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Speaker Account Deletion via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13174 WPScan
2.7 Low Eventin Plugin wp-event-solution Broken Access Control Contributor+ User Role and Meta Modification via Speaker Creation < 4.1.21 Fixed in 4.1.21 CVE-2026-13173 WPScan
8.1 High Eventin Plugin wp-event-solution Broken Access Control Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOR < 4.1.21 Fixed in 4.1.21 CVE-2026-13169 WPScan
8.6 High Dinatur Plugin SQL Injection Unauthenticated SQL Injection via Column Name Injection No login needed ≤ 1.18 CVE-2026-12983 WPScan
8.5 High Advanced File Manager Plugin file-manager-advanced Path Traversal Authenticated Arbitrary File Read and Write via fma_load_fma_ui < 5.4.13 Fixed in 5.4.13 CVE-2026-11565 WPScan
8.1 High Atarim Plugin atarim-visual-collaboration Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via '_wp_attached_file' Meta ≤ 5.1.1 CVE-2026-19942 Wordfence
6.4 Medium Speed Optimizer Plugin sg-cachepress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Tag Attributes ≤ 7.8.0 CVE-2026-15421 Wordfence
4.3 Medium PPWP: Password Protect Pages, Posts & Full or Partial Content Plugin Broken Access Control Improper Authorization To Authenticated (Contributor+) Master Password Exposure ≤ 1.9.15 CVE-2025-11729 Wordfence
5.9 Medium PublishPress Series Plugin organize-series Cross-Site Scripting ≤ 2.17.0 Fixed in 2.17.1 CVE-2026-27365 Patchstack
5.4 Medium B2BKing Plugin b2bking-wholesale-for-woocommerce Broken Access Control ≤ 5.2.30 Fixed in 5.2.40 CVE-2026-66589 Patchstack
6.5 Medium Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting ≤ 3.39 Fixed in 3.40 CVE-2026-66591 Patchstack
8.8 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar Cross-Site Request Forgery WordPress Notification Bar plugin <= 2.0.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66602 Patchstack
6.5 Medium Draft List Plugin simple-draft-list Cross-Site Scripting ≤ 2.6.4 Fixed in 2.6.5 CVE-2026-66603 Patchstack
9.3 Critical Readabler Plugin readabler SQL Injection No login needed < 2.0.18 Fixed in 2.0.18 CVE-2026-74015 Patchstack
8.8 High TaxoPress Plugin simple-tags PHP Object Injection ≤ 3.51.0 Fixed in 3.52.0 CVE-2026-74012 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.7 CVE-2026-74009 Patchstack
5.3 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Information Disclosure Sensitive Data Exposure No login needed ≤ 2.17.22 CVE-2026-74008 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only