WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,251–2,300 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 46 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High SureForms Pro Plugin sureforms-pro Broken Access Control No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-42377 Patchstack
8.8 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Agent+) Privilege Escalation to Administrator via 'connect-customer-to-wp-user' Ability ≤ 5.4.1 CVE-2026-6741 Wordfence
7.7 High Templately Plugin templately Information Disclosure Sensitive Data Exposure ≤ 3.6.1 Fixed in 3.6.2 CVE-2026-42379 Patchstack
8.8 High Highland Software Custom Role Manager Plugin highland-software-custom-role-manager Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.0 CVE-2026-7106 Wordfence
8.1 High Drag and Drop File Upload for Contact Form 7 Plugin drag-and-drop-file-upload-for-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass No login needed ≤ 1.1.3 CVE-2026-5364 Wordfence
7.2 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process ≤ 9.1.2 CVE-2026-5464 Wordfence
7.2 High HTTP Headers Plugin http-headers Remote Code Execution Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters ≤ 1.19.2 CVE-2026-4132 Wordfence
7.2 High Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39467 Patchstack
8.1 High Everest Forms Plugin everest-forms Path Traversal Unauthenticated Arbitrary File Read and Deletion via Upload Field 'old_files' Parameter No login needed ≤ 3.4.4 CVE-2026-5478 Wordfence
8.1 High wpForo Forum Plugin wpforo Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via Custom Profile Field File Path ≤ 3.0.5 CVE-2026-6248 Wordfence
8.8 High CMP – Coming Soon & Maintenance Plugin by NiteoThemes Plugin cmp-coming-soon-maintenance Broken Access Control Coming Soon & Maintenance Plugin by NiteoThemes <= 4.1.16 - Missing Authorization to Authenticated (Administrator+) Arbitrary File Upload and Remote Code Execution ≤ 4.1.16 CVE-2026-6518 Wordfence
7.5 High Easy Appointments Plugin easy-appointments Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 3.12.21 CVE-2026-2262 Wordfence
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass No login needed ≤ 1.3.9.7 CVE-2026-5718 Wordfence
7.5 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Limited Arbitrary File Read via mfile Field No login needed ≤ 1.3.9.6 CVE-2026-5710 Wordfence
8.8 High WP Customer Area Plugin customer-area Path Traversal Authenticated (Subscriber+) Arbitrary File Read/Deletion via ajax_attach_file ≤ 8.3.4 CVE-2026-3464 Wordfence
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Path Traversal Authenticated (Contributor+) Arbitrary File Read via Path Traversal in Repeater JSON/CSV URL with Path Traversal No login needed ≤ 2.0.6 CVE-2026-4659 Wordfence
7.2 High WP Statistics Plugin wp-statistics Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter No login needed ≤ 14.16.4 CVE-2026-5231 Wordfence
8.8 High my-calendar Plugin Information Disclosure My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog No login needed < 3.7.7 CVE-2026-40308 GitHub_M
7.5 High DirectoryPress – Business Directory And Classified Ad Listing Plugin directorypress SQL Injection Business Directory And Classified Ad Listing <= 3.6.26 - Unauthenticated SQL Injection via 'packages' No login needed ≤ 3.6.26 CVE-2026-3489 Wordfence
8.8 High Career Section Plugin career-section Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.6 CVE-2025-14868 Wordfence
7.2 High Prismatic Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'prismatic_encoded' Pseudo-Shortcode No login needed ≤ 3.7.3 CVE-2026-3876 Wordfence
8.8 High Livemesh Addons by Elementor Plugin addons-for-elementor Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Widget Template Parameter ≤ 9.0 CVE-2026-1620 Wordfence
8.8 High AcyMailing Plugin acymailing Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation 9.11.0 – 10.8.1 CVE-2026-3614 Wordfence
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation No login needed ≤ 7.0.0 CVE-2026-5050 Wordfence
7.5 High Riaxe Product Customizer Plugin riaxe-product-customizer SQL Injection Unauthenticated SQL Injection via 'options' Parameter Keys in product_data No login needed ≤ 2.1.2 CVE-2026-3599 Wordfence
7.6 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection ≤ 3.7.1 CVE-2025-63029 Patchstack
7.5 High Accept Cryptocurrencies with Plisio Plugin plisio-payment-gateway-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 2.0.5 CVE-2026-6372 Patchstack
8.1 High FluentBoards Plugin fluent-boards Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.91.2 Fixed in 1.91.3 CVE-2026-40784 Patchstack
8.1 High Contact Form by WPForms Plugin wpforms-lite Cross-Site Request Forgery No login needed ≤ 1.10.0.2 Fixed in 1.10.0.3 CVE-2026-40764 Patchstack
7.6 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 8.4.2 Fixed in 8.5.0 CVE-2026-40745 Patchstack
8.5 High Beaver Builder Plugin beaver-builder-lite-version SQL Injection ≤ 2.10.1.2 Fixed in 2.10.1.5 CVE-2026-40744 Patchstack
7.2 High Accessibly Plugin otm-accessibly Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Widget Source Injection via REST API No login needed ≤ 3.0.3 CVE-2026-3643 Wordfence
7.2 High Quick Interest Slider Plugin quick-interest-slider Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.1.5 CVE-2026-5694 Wordfence
8.8 High Login as User Plugin one-click-login-as-user Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'oclaup_original_admin' Cookie ≤ 1.0.1 CVE-2026-5617 Wordfence
7.2 High Age Verification & Identity Verification by Token of Trust Plugin token-of-trust Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'description' Parameter No login needed ≤ 3.32.3 CVE-2026-2834 Wordfence
7.2 High Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts Plugin post-carousel PHP Object Injection Post Grid, Post Carousel & Slider, and List Category Posts <= 3.0.12 - Authenticated (Administrator+) PHP Object Injection ≤ 3.0.12 CVE-2026-3017 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box No login needed ≤ 1.15.40 CVE-2026-4388 Wordfence
7.2 High BackWPup Plugin backwpup Local File Inclusion Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter ≤ 5.6.6 CVE-2026-6227 Wordfence
7.5 High JetEngine Plugin SQL Injection Unauthenticated SQL Injection via '_cct_search' Parameter No login needed ≤ 3.8.6.1 CVE-2026-4352 Wordfence
8.6 High Product Filter for WooCommerce by WBW Plugin woo-product-filter SQL Injection Unauthenticated SQLi No login needed < 3.1.3 Fixed in 3.1.3 CVE-2026-3830 WPScan
7.1 High wpForo Forum Plugin wpforo Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'data[body][fileurl]' Parameter ≤ 3.0.2 CVE-2026-5809 Wordfence
8.8 High BuddyPress Groupblog Plugin bp-groupblog Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOR ≤ 1.9.3 CVE-2026-5144 Wordfence
7.2 High Optimole Plugin optimole-wp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Srcset Descriptor Parameter No login needed ≤ 4.2.2 CVE-2026-5217 Wordfence
7.1 High Cerato Plugin cerato Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.18 CVE-2025-58920 Patchstack
8.1 High VideoPro Plugin videopro Local File Inclusion No login needed ≤ 2.3.8.1 CVE-2025-58913 Patchstack
7.5 High Case Theme User Plugin case-theme-user Local File Inclusion No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-5804 Patchstack
7.1 High Gravity SMTP Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Uninstall ≤ 2.1.4 CVE-2026-4162 Wordfence
8.1 High Perfmatters Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Overwrite via 'snippets' Parameter ≤ 2.5.9 CVE-2026-4351 Wordfence
7.5 High Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter No login needed ≤ 3.9.7 CVE-2026-3360 Wordfence
8.2 High adivaha Travel Plugin adiaha-hotel SQL Injection WordPress adivaha Travel Plugin 2.3 SQL Injection via pid No login needed 2.3 CVE-2023-54359 VulnCheck

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only