WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,151–2,200 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 44 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure No login needed ≤ 1.16.20 CVE-2026-74007 Patchstack
4.3 Medium WP Table Builder Plugin wp-table-builder Broken Access Control ≤ 2.2.0 CVE-2026-74006 Patchstack
5.4 Medium Gravity Booster – Styles & Layouts for Gravity Forms Plugin styles-and-layouts-for-gravity-forms Broken Access Control Styles & Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control ≤ 6.0 CVE-2026-74004 Patchstack
4.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control ≤ 1.2.6 CVE-2026-74003 Patchstack
7.5 High Starter Templates by Kadence WP Plugin kadence-starter-templates Denial of Service Denial of Service Attack No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-73997 Patchstack
9.8 Critical Masteriyo - LMS Plugin learning-management-system Arbitrary File Upload LMS plugin <= 2.3.2 - Arbitrary File Upload No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-73996 Patchstack
5.4 Medium User Registration Plugin user-registration Authentication Bypass Broken Authentication ≤ 5.2.6 Fixed in 5.2.7 CVE-2026-73995 Patchstack
7.5 High Charitable Plugin charitable Broken Access Control No login needed ≤ 1.8.11.3 Fixed in 1.8.12 CVE-2026-73994 Patchstack
6.5 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control ≤ 3.7.41 Fixed in 3.7.42 CVE-2026-73404 Patchstack
8.1 High Restaurant Menu by MotoPress Plugin mp-restaurant-menu Local File Inclusion No login needed ≤ 2.4.11 CVE-2026-73400 Patchstack
6.5 Medium Flutterwave WooCommerce Plugin rave-woocommerce-payment-gateway Authentication Bypass Broken Authentication No login needed ≤ 3.3.0 CVE-2026-73399 Patchstack
6.5 Medium Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank Authentication Bypass Broken Authentication No login needed 3.2.0 CVE-2026-73398 Patchstack
9.8 Critical Youzify Plugin youzify PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3.7 CVE-2026-73397 Patchstack
7.1 High MWB HubSpot for WooCommerce Plugin makewebbetter-hubspot-for-woocommerce Authentication Bypass Broken Authentication ≤ 1.6.7 CVE-2026-73396 Patchstack
6.5 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.36 CVE-2026-73395 Patchstack
7.1 High Subscribe2 Plugin subscribe2 Cross-Site Scripting No login needed ≤ 10.46 CVE-2026-73393 Patchstack
4.9 Medium CTX Feed Plugin webappick-product-feed-for-woocommerce Path Traversal Arbitrary File Download ≤ 6.6.47 Fixed in 6.6.48 CVE-2026-73383 Patchstack
7.1 High Site Reviews Plugin site-reviews Cross-Site Scripting No login needed ≤ 8.2.0 Fixed in 8.2.1 CVE-2026-73382 Patchstack
9.1 Critical Popup by Supsystic Plugin popup-by-supsystic Authentication Bypass Broken Authentication No login needed ≤ 1.13.0 Fixed in 1.13.1 CVE-2026-73381 Patchstack
9.8 Critical Popup by Supsystic Plugin popup-by-supsystic PHP Object Injection No login needed ≤ 1.13.0 Fixed in 1.13.1 CVE-2026-73380 Patchstack
6.5 Medium Contact Form by Supsystic Plugin contact-form-by-supsystic Authentication Bypass Bypass Vulnerability No login needed < 1.10.0 Fixed in 1.10.0 CVE-2026-73379 Patchstack
7.1 High Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Scripting No login needed < 1.10.0 Fixed in 1.10.0 CVE-2026-73378 Patchstack
7.5 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Broken Access Control No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73377 Patchstack
9.8 Critical Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic PHP Object Injection No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73376 Patchstack
7.1 High Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Cross-Site Scripting No login needed < 1.5.0 Fixed in 1.5.0 CVE-2026-73375 Patchstack
7.2 High Easy Google Maps Plugin google-maps-easy Local File Inclusion Remote File Inclusion No login needed < 1.14.2 Fixed in 1.14.2 CVE-2026-73367 Patchstack
9.8 Critical Easy Google Maps Plugin google-maps-easy PHP Object Injection No login needed ≤ 1.13.0 Fixed in 1.14.0 CVE-2026-73366 Patchstack
9.3 Critical JetAppointment Plugin jet-appointments-booking SQL Injection No login needed ≤ 2.5.2 Fixed in 2.5.2.1 CVE-2026-73365 Patchstack
7.1 High URL Shortify Plugin url-shortify Cross-Site Scripting No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2026-73362 Patchstack
7.1 High Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Cross-Site Scripting No login needed ≤ 3.4.18 Fixed in 3.4.19 CVE-2026-73361 Patchstack
7.1 High Chaty Pro Plugin chaty-pro Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2026-73360 Patchstack
6.5 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Cross-Site Scripting ≤ 4.3.9 Fixed in 4.4.0 CVE-2026-73359 Patchstack
7.1 High Affiliates Manager Plugin affiliates-manager Cross-Site Scripting No login needed ≤ 2.9.53 Fixed in 2.9.54 CVE-2026-73358 Patchstack
8.2 High Breeze Plugin breeze Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.5.12 Fixed in 2.5.13 CVE-2026-73356 Patchstack
9.3 Critical Affiliates Manager Plugin affiliates-manager SQL Injection No login needed ≤ 2.9.53 Fixed in 2.9.54 CVE-2026-73355 Patchstack
6.5 Medium GiveWP Plugin give Broken Access Control No login needed ≤ 4.16.5.1 Fixed in 4.16.6 CVE-2026-73352 Patchstack
7.1 High WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting No login needed ≤ 7.8.1 Fixed in 7.8.2 CVE-2026-73351 Patchstack
8.2 High SupportCandy Plugin supportcandy Authentication Bypass Broken Authentication No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2026-73350 Patchstack
6.5 Medium GiveWP Plugin give Broken Access Control No login needed < 4.16.6 Fixed in 4.16.6 CVE-2026-73348 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce SQL Injection ≤ 3.0.18 Fixed in 3.0.19 CVE-2026-73345 Patchstack
10.0 Critical WP Compress Plugin wp-compress-image-optimizer Remote Code Execution No login needed < 7.20.01 Fixed in 7.20.01 CVE-2026-73343 Patchstack
7.1 High WP Multilang Plugin wp-multilang Cross-Site Scripting No login needed ≤ 2.4.31 Fixed in 2.4.32 CVE-2026-73342 Patchstack
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager PHP Object Injection No login needed ≤ 6.0.9.7 Fixed in 6.0.9.8 CVE-2026-73341 Patchstack
9.3 Critical Modern Events Calendar Plugin modern-events-calendar SQL Injection No login needed < 7.35.0 Fixed in 7.35.0 CVE-2026-73339 Patchstack
7.1 High Autopay Plugin platnosci-online-blue-media Cross-Site Scripting No login needed ≤ 5.0.0 Fixed in 5.0.1 CVE-2026-73338 Patchstack
7.1 High WPDM – Premium Packages Plugin wpdm-premium-packages Cross-Site Scripting Premium Packages plugin <= 7.0.5 - Cross Site Scripting (XSS) No login needed ≤ 7.0.5 Fixed in 7.0.6 CVE-2026-73190 Patchstack
9.3 Critical Sticky Chat Widget Plugin sticky-chat-widget SQL Injection No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-73187 Patchstack
7.5 High Extra Product Options & Add-Ons for WooCommerce Plugin woocommerce-tm-extra-product-options Path Traversal Arbitrary File Download No login needed < 7.6 Fixed in 7.6 CVE-2026-73181 Patchstack
6.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Privilege Escalation ≤ 3.7.41 Fixed in 3.7.42 CVE-2026-68568 Patchstack
7.1 High Convert Pro Plugin convertpro Cross-Site Scripting No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2026-68567 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only