WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,151–2,200 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 44 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Advanced Database Cleaner – Premium Plugin Local File Inclusion Premium <= 4.1.0 - Authenticated (Subscriber+) Local File Inclusion via 'template' ≤ 4.1.0 CVE-2026-7522 Wordfence
7.5 High Boost Plugin SQL Injection Unauthenticated Blind SQL Injection via Multiple Parameters No login needed ≤ 2.0.3 CVE-2026-9010 Wordfence
8.8 High Read More & Accordion Plugin expand-maker Privilege Escalation Privilege Escalation via importData ≤ 3.5.7 CVE-2026-7467 Wordfence
8.8 High Account Switcher Plugin account-switcher Authentication Bypass Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation ≤ 1.0.2 CVE-2026-6456 Wordfence
7.5 High Creative Mail – Easier WordPress & WooCommerce Email Marketing Plugin creative-mail-by-constant-contact SQL Injection Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter No login needed ≤ 1.6.9 CVE-2026-3985 Wordfence
7.5 High Kirki Plugin kirki Path Traversal Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP No login needed ≤ 6.0.6 CVE-2026-8073 Wordfence
7.5 High Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX No login needed < 3.15.0.3 Fixed in 3.15.0.3 CVE-2026-47100 VulnCheck
7.5 High Contest Gallery Plugin contest-gallery SQL Injection Unauthenticated SQL Injection No login needed ≤ 28.1.6 CVE-2026-8912 Wordfence
7.5 High Fortis For WooCommerce Plugin fortis-for-woocommerce Information Disclosure Sensitive API Key Disclosure No login needed < 1.3.1 Fixed in 1.3.1 CVE-2025-15609 WPScan
7.1 High Ajax Load More Plugin ajax-load-more Cross-Site Scripting Reflected XSS No login needed < 7.8.4 Fixed in 7.8.4 CVE-2026-6495 WPScan
7.5 High WP Maps Plugin wp-google-map-plugin Local File Inclusion Subscriber+ Local File Inclusion < 4.9.3 Fixed in 4.9.3 CVE-2026-6381 WPScan
8.6 High WP Photo Album Plus Plugin wp-photo-album-plus SQL Injection Unauthenticated SQL Injection via 'wppa-supersearch' Parameter No login needed < 9.1.11.001 Fixed in 9.1.11.001 CVE-2026-6379 WPScan
8.8 High Multiple Plugins Plugin Cross-Site Scripting Unauthenticated Stored XSS via Minify Library No login needed < 3.1.15, < 2.4.2, < 7.7.9 Fixed in 3.1.15 CVE-2026-3220 WPScan
7.5 High WP with Spritz Plugin Local File Inclusion WordPress Plugin WP with Spritz 1.0 Remote File Inclusion No login needed 1.0 CVE-2018-25329 VulnCheck
8.8 High AI Engine Plugin ai-engine Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token 3.4.9 CVE-2026-8719 Wordfence
7.5 High Malware Security and Bruteforce Firewall Plugin Path Traversal WordPress Anti-Malware Security Bruteforce Firewall <= 4.20.72 Directory Traversal No login needed ≤ 4.20.72 CVE-2021-47977 VulnCheck
8.8 High Backup and Restore Plugin backup-and-restore-for-wp Arbitrary File Deletion WordPress Plugin Backup and Restore 1.0.3 Arbitrary File Deletion 1.0.3 CVE-2021-47979 VulnCheck
7.2 High WP Learn Manager Plugin learn-manager Cross-Site Scripting WordPress Plugin WP Learn Manager 1.1.2 Stored XSS No login needed 1.1.2 CVE-2021-47975 VulnCheck
7.5 High Digital Publications Plugin Path Traversal WordPress Plugin Supsystic Digital Publications 1.6.9 Path Traversal XSS No login needed 1.6.9 CVE-2020-37245 VulnCheck
8.2 High Membership Plugin membership-for-woocommerce SQL Injection WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx No login needed 1.4.7 CVE-2020-37244 VulnCheck
8.2 High Pricing Table Plugin pricing-table-by-supsystic SQL Injection WordPress Plugin Supsystic Pricing Table 1.8.7 SQL Injection XSS No login needed 1.8.6, 1.8.7 CVE-2020-37243 VulnCheck
8.2 High Ultimate Maps Plugin ultimate-maps-by-supsystic SQL Injection WordPress Plugin Supsystic Ultimate Maps 1.1.12 SQL Injection via sidx No login needed 1.1.12 CVE-2020-37242 VulnCheck
8.8 High HS Brand Logo Slider Plugin hs-brand-logo-slider Arbitrary File Upload WordPress Plugin HS Brand Logo Slider 2.1 Unrestricted File Upload 2.1 CVE-2020-37227 VulnCheck
7.5 High WPGraphQL Plugin wp-graphql Denial of Service WordPress Plugin WPGraphQL 1.3.5 Denial of Service No login needed 1.3.5 CVE-2021-47959 VulnCheck
7.5 High Quick Playground Plugin quick-playground Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via 'stylesheet' Parameter No login needed ≤ 1.3.3 CVE-2026-6403 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation via Edit User Form ≤ 3.28.36 CVE-2026-6228 Wordfence
8.1 High FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion ≤ 1.4.5 CVE-2026-4094 Wordfence
8.1 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Deletion No login needed ≤ 2.5.2 CVE-2026-4030 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Export No login needed ≤ 2.5.2 CVE-2026-4029 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Backup Interception No login needed ≤ 2.5.2 CVE-2026-4031 Wordfence
7.5 High InfusedWoo Pro Plugin Path Traversal Unauthenticated Arbitrary File Read via 'url' Parameter No login needed ≤ 5.1.2 CVE-2026-6514 Wordfence
7.2 High ManageWP Worker Plugin worker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'MWP-Key-Name' Header No login needed ≤ 4.9.31 CVE-2026-3718 Wordfence
8.2 High Fluent Forms Plugin fluentform Broken Access Control Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter No login needed ≤ 6.2.0 CVE-2026-5395 Wordfence
8.8 High InfusedWoo Pro Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary User Meta Update ≤ 5.1.2 CVE-2026-6506 Wordfence
8.1 High Motors – Car Dealer, Classifieds & Listing Plugin Arbitrary File Deletion Car Dealer, Classifieds & Listing <= 1.4.107 - Authenticated (Subscriber+) Arbitrary File Deletion via 'stm_dealer_logo_path' Parameter ≤ 1.4.107 CVE-2026-3892 Wordfence
8.2 High Fluent Forms Plugin fluentform Broken Access Control Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter No login needed ≤ 6.1.21 CVE-2026-5396 Wordfence
7.1 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining ≤ 5.9.8.4 CVE-2026-4609 Wordfence
7.2 High Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Cached Tweet Text No login needed ≤ 2.5.4 CVE-2026-6177 Wordfence
8.8 High RTMKit Addons for Elementor Plugin rometheme-for-elementor Local File Inclusion Authenticated (Author+) Local File Inclusion via 'path' ≤ 2.0.2 CVE-2026-3425 Wordfence
7.5 High Avada Builder Plugin SQL Injection Unauthenticated SQL Injection via 'product_order' Parameter No login needed ≤ 3.15.1 CVE-2026-4798 Wordfence
7.5 High JoomSport Plugin joomsport-sports-league-results-management SQL Injection Unauthenticated SQL Injection via 'sortf' Parameter No login needed ≤ 5.7.7 CVE-2026-6929 Wordfence
8.1 High coreActivity: Activity Logging Plugin coreactivity PHP Object Injection Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field No login needed ≤ 3.0 CVE-2026-7635 Wordfence
7.5 High Court Reservation – Manage Your Court Bookings Online Plugin court-reservation SQL Injection Manage Your Court Bookings Online <= 1.10.11 - Unauthenticated SQL Injection No login needed ≤ 1.10.11 CVE-2026-1250 Wordfence
7.1 High MonsterInsights Plugin google-analytics-for-wordpress Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset ≤ 10.1.2 CVE-2026-5371 Wordfence
7.7 High WP Travel Plugin wp-travel SQL Injection ≤ 11.4.0 Fixed in 11.5.0 CVE-2026-45218 Patchstack
8.5 High Xpro Elementor Addons Plugin xpro-elementor-addons SQL Injection ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-45214 Patchstack
7.6 High BEAR Plugin woo-bulk-editor SQL Injection ≤ 1.1.7.1 Fixed in 1.1.8 CVE-2026-45213 Patchstack
8.5 High APIExperts Square for WooCommerce Plugin woosquare SQL Injection ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-45211 Patchstack
8.5 High Views for WPForms Plugin views-for-wpforms-lite SQL Injection ≤ 3.4.6 Fixed in 3.4.7 CVE-2026-42742 Patchstack
8.5 High Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend Plugin views-for-ninja-forms SQL Injection Display & Edit Ninja Forms Submissions on your site frontend plugin <= 3.3.2 - SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-42741 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only