WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,201–2,250 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 45 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.2 High Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.53 Fixed in 1.0.54 CVE-2026-39432 Patchstack
7.5 High AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator SQL Injection Unauthenticated SQL Injection in getListForTbl() No login needed ≤ 1.4.17 CVE-2026-2993 Wordfence
7.2 High LifePress Plugin lifepress Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'n' Parameter via lp_update_mds AJAX Action No login needed ≤ 2.2.2 CVE-2026-6690 Wordfence
7.3 High Custom CSS JS PHP Plugin SQL Injection Unauthenticated SQL Injection to RCE No login needed 2.0.7 – 2.0.7 CVE-2026-6433 WPScan
8.2 High Survey & Poll Plugin SQL Injection WordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params No login needed 1.5.7.3 CVE-2021-47941 VulnCheck
7.2 High Auto Affiliate Links Plugin wp-auto-affiliate-links Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'url' Parameter No login needed ≤ 6.8.8 CVE-2026-7330 Wordfence
8.8 High User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin wp-user-frontend PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 4.3.1 CVE-2026-5127 Wordfence
8.6 High SureTriggers Plugin SQL Injection Unauthenticated SQLi No login needed < 1.1.23 Fixed in 1.1.23 CVE-2026-4935 WPScan
7.1 High Bricks Builder Theme bricks Cross-Site Scripting No login needed 1.9.2 – 2.2 Fixed in 2.3 CVE-2026-41554 Patchstack
7.6 High Team Member Plugin team-showcase-supreme SQL Injection ≤ 8.5 Fixed in 8.6 CVE-2025-68060 Patchstack
8.1 High WP-Optimize Plugin wp-optimize Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via 'original-file' Post Meta ≤ 4.5.2 CVE-2026-7252 Wordfence
8.8 High Slider Revolution Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via _get_media_url 7.0.0 – 7.0.10 CVE-2026-6692 Wordfence
7.5 High BetterDocs Pro Plugin SQL Injection Unauthenticated SQL Injection via Encyclopedia 'limit' Parameter No login needed ≤ 3.7.0 CVE-2026-4348 Wordfence
7.5 High Gravity Bookings Plugin SQL Injection Unauthenticated SQL Injection via 'category_id' Parameter No login needed ≤ 2.5.9 CVE-2026-1719 Wordfence
7.2 High LatePoint Plugin latepoint Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'booking_form_page_url' Parameter No login needed ≤ 5.5.0 CVE-2026-7332 Wordfence
7.5 High WeePie Cookie Allow Plugin SQL Injection Unauthenticated SQL Injection via 'consent' Parameter No login needed ≤ 3.4.11 CVE-2026-4304 Wordfence
8.8 High Betheme Theme Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload to Remote Code Execution via Icon Pack Upload ≤ 28.4 CVE-2026-6261 Wordfence
7.5 High WordPress Plugin Backup Migration Plugin Information Disclosure WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download No login needed 1.2.8 CVE-2023-54346 VulnCheck
7.5 High Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker SQL Injection Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' No login needed ≤ 1.15.42 CVE-2026-3359 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Path Traversal Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]' No login needed ≤ 1.52.1 CVE-2026-5192 Wordfence
7.2 High Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'status' Parameter in wpr_update_form_action_meta No login needed ≤ 1.7.1056 CVE-2026-4803 Wordfence
7.5 High GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation Plugin geeky-bot SQL Injection Unauthenticated SQL Injection via 'attributekey' No login needed ≤ 1.2.0 CVE-2026-3456 Wordfence
7.5 High AWP Classifieds Plugin another-wordpress-classifieds-plugin SQL Injection Unauthenticated SQL Injection via 'regions' No login needed ≤ 4.4.5 CVE-2026-5100 Wordfence
7.5 High Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Denial of Service Conditional Fields for Contact Form 7 < 2.7.3 DoS via Uncontrolled Resource Consumption No login needed < 2.7.3 Fixed in 2.7.3 CVE-2026-25863 VulnCheck
7.5 High easy-paypal-events-tickets Plugin easy-paypal-events-tickets Information Disclosure Easy PayPal Events & Tickets < 1.4 Information Disclosure via QR Code Endpoint No login needed < 1.4.0 Fixed in 1.4.0 CVE-2026-41471 VulnCheck
7.5 High easy-paypal-events-tickets Plugin easy-paypal-events-tickets Authentication Bypass Easy PayPal Events & Tickets < 1.4 Authentication Bypass via QR Code Scanning No login needed < 1.4.0 Fixed in 1.4.0 CVE-2026-32834 VulnCheck
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names No login needed ≤ 9.1.11 CVE-2026-5063 Wordfence
8.1 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion ≤ 6.7.25 CVE-2026-2554 Wordfence
7.5 High Salon Booking System – Free Version Plugin salon-booking-system Path Traversal Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via Booking File Field Path Traversal No login needed ≤ 10.30.25 CVE-2026-6320 Wordfence
7.5 High Geo Mashup Plugin geo-mashup SQL Injection Unauthenticated Time-Based SQL Injection via 'object_ids' Parameter No login needed ≤ 1.13.18 CVE-2026-4062 Wordfence
7.5 High Geo Mashup Plugin geo-mashup SQL Injection Unauthenticated Time-Based SQL Injection via 'map_post_type' Parameter No login needed ≤ 1.13.18 CVE-2026-4061 Wordfence
7.1 High Paid Memberships Pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stripe Webhook Deletion and Payment Processing Disruption ≤ 3.6.5 CVE-2026-4100 Wordfence
7.5 High Geo Mashup Plugin geo-mashup SQL Injection Unauthenticated Time-Based SQL Injection via 'sort' Parameter No login needed ≤ 1.13.18 CVE-2026-4060 Wordfence
7.2 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Value No login needed ≤ 2.8.11 CVE-2026-5324 Wordfence
7.2 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via CSV URL Parameter No login needed ≤ 1.7.1057 CVE-2026-6229 Wordfence
8.8 High Widget Options Plugin widget-options Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Display Logic ≤ 4.2.2, ≤ 5.3.2 CVE-2026-2052 Wordfence
7.5 High ARMember Plugin armember-membership SQL Injection Unauthenticated SQL Injection via 'orderby' Parameter No login needed ≤ 4.0.60 CVE-2026-7649 Wordfence
8.1 High Profile Builder Pro Plugin profile-builder-pro PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.14.5 CVE-2026-7647 Wordfence
7.2 High Gravity Forms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Single Product Field Inside Repeater No login needed ≤ 2.10.0 CVE-2026-5110 Wordfence
7.2 High Gravity Forms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Hidden Product Field in Repeater No login needed ≤ 2.10.0 CVE-2026-5111 Wordfence
7.2 High Gravity Forms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Product Option No login needed ≤ 2.10.0 CVE-2026-5109 Wordfence
7.2 High Gravity Forms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Consent Field Hidden Input No login needed ≤ 2.10.0 CVE-2026-5113 Wordfence
7.2 High Gravity Forms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Calculation Product Field in Repeater No login needed ≤ 2.10.0 CVE-2026-5112 Wordfence
7.2 High PixelYourSite Pro Plugin pixelyoursite-pro Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery via 'urls[]' Parameter No login needed ≤ 12.5.0.1 CVE-2026-7049 Wordfence
8.8 High WP Mail Gateway Plugin wp-mail-gateway Broken Access Control Missing Authorization to Authenticated (Subscriber+) SMTP Configuration Modification via 'wmg_save_provider_config' AJAX Action ≤ 1.8 CVE-2026-6963 Wordfence
8.8 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Multisite Capability Meta Fields ≤ 2.0.8 CVE-2026-7641 Wordfence
8.8 High WP Editor Plugin wp-editor Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution via Plugin and Theme File Editor No login needed ≤ 1.2.9.2 CVE-2026-3772 Wordfence
7.5 High Otter Blocks Plugin otter-blocks Broken Access Control Improper Authorization to Unauthenticated Purchase Verification Bypass via Forged Cookie No login needed ≤ 3.1.4 CVE-2026-2892 Wordfence
7.1 High User Registration Plugin user-registration Cross-Site Scripting No login needed ≤ 5.1.5 Fixed in 5.1.6 CVE-2026-42652 Patchstack
7.6 High TaxoPress Plugin simple-tags SQL Injection ≤ 3.44.0 Fixed in 3.45.0 CVE-2026-42646 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only