WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,251–2,300 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 46 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium WooMS Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery and Sensitive Information Disclosure No login needed ≤ 9.14 CVE-2026-13700 WPScan
9.8 Critical Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder PHP Object Injection ARForms <= 1.8.5 - Unauthenticated PHP Object Injection No login needed ≤ 1.8.5 CVE-2024-13784 Wordfence
4.3 Medium Kirki Plugin kirki Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'context' Parameter ≤ 6.1.1 CVE-2026-18347 Wordfence
4.9 Medium Kirki Plugin kirki Path Traversal Authenticated (Editor+) Path Traversal to Arbitrary File Read via 'data' Parameter ≤ 6.1.1 CVE-2026-17604 Wordfence
7.5 High WP Travel Engine Plugin wp-travel-engine Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter No login needed ≤ 6.8.4 CVE-2026-17087 Wordfence
7.2 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action No login needed ≤ 27.7 CVE-2026-13424 Wordfence
7.2 High Gallery by BestWebSoft Plugin gallery-plugin SQL Injection Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys ≤ 4.7.9 CVE-2026-2497 Wordfence
6.5 Medium WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Deletion No login needed ≤ 7.10.09 CVE-2026-17608 Wordfence
5.3 Medium Forminator Forms Plugin forminator Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter No login needed ≤ 1.55.0.2 CVE-2026-12998 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.8 CVE-2026-2357 Wordfence
7.2 High Infility Global Plugin infility-global Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint No login needed ≤ 2.15.21 CVE-2026-10734 Wordfence
7.5 High Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Information Disclosure Unauthenticated Customer File Disclosure via getpublicfileupload No login needed < 1.2.176 Fixed in 1.2.176 CVE-2026-19728 WPScan
6.5 Medium Visualizer Plugin visualizer Information Disclosure Contributor+ Cross-User Chart Configuration Disclosure < 4.0.7 Fixed in 4.0.7 CVE-2026-19726 WPScan
9.1 Critical WPvivid Backup & Migration Plugin Path Traversal Unauthenticated Path Traversal via send_to_site_connect No login needed < 0.9.131 Fixed in 0.9.131 CVE-2026-19725 WPScan
7.5 High CatFolders Document Gallery Plugin Information Disclosure Unauthenticated Attachment Disclosure via REST API No login needed < 2.0.7 Fixed in 2.0.7 CVE-2026-19717 WPScan
9.1 Critical Simple JWT Login Plugin simple-jwt-login Privilege Escalation Unauthenticated Account Takeover via Missing Google id_token Audience Validation No login needed < 3.6.8 Fixed in 3.6.8 CVE-2026-19714 WPScan
6.1 Medium Masteriyo LMS Plugin learning-management-system Cross-Site Scripting Instructor+ Stored XSS via Quiz Description No login needed < 2.3.3 Fixed in 2.3.3 CVE-2026-19712 WPScan
6.5 Medium Premium Packages – Sell Digital Products Securely Plugin wpdm-premium-packages Broken Access Control Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount Withdrawal Request < 7.0.7 Fixed in 7.0.7 CVE-2026-19711 WPScan
6.5 Medium ECS Plugin Information Disclosure Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source < 4.3.10 Fixed in 4.3.10 CVE-2026-19613 WPScan
7.2 High WP Directory Kit Plugin wpdirectorykit SQL Injection Admin+ SQL Injection via section Parameter < 1.5.7 Fixed in 1.5.7 CVE-2026-18653 WPScan
7.2 High All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Remote Code Execution Multisite Subsite Admin+ Network-Wide PHP Code Execution via REST Import < 7.108 Fixed in 7.108 CVE-2026-17533 WPScan
5.7 Medium Manual Image Crop Plugin manual-image-crop Broken Access Control Subscriber+ Arbitrary Attachment Image Overwrite via IDOR < 1.15 Fixed in 1.15 CVE-2026-15384 WPScan
5.4 Medium Divi Theme Cross-Site Scripting Contributor+ Stored XSS via Social Media Follow Skype URL 5.0 – < 5.9.0 Fixed in 5.9.0 CVE-2026-13712 WPScan
7.2 High WCPOS Plugin woocommerce-pos Remote Code Execution Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine ≤ 1.9.14 CVE-2026-17581 Wordfence
4.9 Medium WC Vendors Plugin wc-vendors SQL Injection Authenticated (Shop Manager+) SQL Injection via 'status' Parameter ≤ 2.7.0 CVE-2026-15351 Wordfence
6.5 Medium The School Management Plugin school-management-system SQL Injection Authenticated (Custom+) SQL Injection via 'order[0][dir]' Parameter ≤ 5.4 CVE-2026-9767 Wordfence
4.9 Medium Slider Hero with Video Background, Animation Plugin slider-hero SQL Injection Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate) ≤ 9.1.7 CVE-2026-17582 Wordfence
6.4 Medium Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 4.9.0 CVE-2026-16775 Wordfence
4.3 Medium ShortPixel Adaptive Images Plugin shortpixel-adaptive-images Broken Access Control Missing Authorization to Authenticated (Subscriber+) Third-Party Plugin Option Modification via 'causer' Parameter ≤ 3.11.5 CVE-2026-15345 Wordfence
6.5 Medium StoreEngine Plugin storeengine Path Traversal Authenticated (Vendor+) Arbitrary File Read via Path Traversal in Downloadable File URL ≤ 2.1.1 CVE-2026-15056 Wordfence
6.6 Medium Turnkey bbPress by WeaverTheme Plugin weaver-for-bbpress PHP Object Injection Authenticated (Administrator+) PHP Object Injection ≤ 1.7.1 CVE-2026-10035 Wordfence
9.1 Critical Solace Extra Plugin solace-extra Broken Access Control Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action No login needed ≤ 1.6.0 CVE-2026-18316 Wordfence
6.4 Medium Snippet Shortcodes Plugin shortcode-variables Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 5.2.0 CVE-2026-16758 Wordfence
4.9 Medium User Login History Plugin user-login-history SQL Injection Authenticated (Administrator+) SQL Injection via 'blog_id' Parameter ≤ 2.1.7 CVE-2026-2283 Wordfence
6.4 Medium SureDash Plugin suredash Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'draweropenverposition' Block/Shortcode Attribute ≤ 1.10.3 CVE-2026-18402 Wordfence
6.4 Medium Video Gallery Plugin youtube-showcase Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment 'post_title' via emd_mb_meta Shortcode ≤ 4.0.4 CVE-2026-15790 Wordfence
6.4 Medium Toocheke Companion Plugin toocheke-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'series_bg_color' Post Meta ≤ 2.10 CVE-2026-15604 Wordfence
4.3 Medium Kubio AI Page Builder Plugin kubio Broken Access Control Missing Authorization to Authenticated (Contributor+) Front-Page/Menu/Template Configuration Reversion via kubio_restore_front_page AJAX Action ≤ 2.8.5 CVE-2026-16779 Wordfence
6.4 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'theme' Shortcode Attribute ≤ 1.4.0 CVE-2026-15726 Wordfence
7.2 High Autopay Plugin platnosci-online-blue-media Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter No login needed ≤ 5.0.0 CVE-2026-15002 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option ≤ 11.2.1 CVE-2026-15963 Wordfence
6.1 Medium Advanced File Manager Plugin file-manager-advanced Cross-Site Scripting Reflected Cross-Site Scripting via postMessage 'soundFile' Parameter No login needed ≤ 5.4.12 CVE-2026-15009 Wordfence
4.3 Medium Password Protect WordPress Lite Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update ≤ 1.9.20 CVE-2025-10005 Wordfence
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting ≤ 1.7.1064 CVE-2026-17123 Wordfence
6.4 Medium Loco Translate Plugin loco-translate Cross-Site Scripting Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments ≤ 2.8.7 CVE-2026-15066 Wordfence
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints ≤ 3.5.2 CVE-2026-13167 Wordfence
5.3 Medium Product Table & List Builder For WooCommerce Plugin wc-product-table-lite Content Injection Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter No login needed ≤ 5.6.0 CVE-2026-15441 Wordfence
6.5 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure ≤ 1.6.12.10 CVE-2026-13358 Wordfence
6.4 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter ≤ 11.2.1 CVE-2026-11780 Wordfence
6.5 Medium Fullscreen Galleria Plugin fullscreen-galleria SQL Injection Authenticated (Contributor+) SQL Injection via 'href' Attribute in Post Content ≤ 1.6.12 CVE-2026-16079 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only