WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,301–2,350 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 47 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical ProSolution WP Client Plugin prosolution-wp-client Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters No login needed ≤ 2.0.8 CVE-2026-14524 Wordfence
4.4 Medium Gravity Booster Plugin styles-and-layouts-for-gravity-forms Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter ≤ 5.26 CVE-2026-12477 Wordfence
8.8 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress PHP Object Injection Authenticated (Contributor+) PHP Object Injection to Arbitrary File Deletion via 'unfurl_data' Parameter ≤ 4.5.3 CVE-2026-16099 Wordfence
9.8 Critical ProSolution WP Client Plugin prosolution-wp-client Arbitrary File Upload Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override No login needed ≤ 2.0.10 CVE-2026-16098 Wordfence
5.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field ≤ 4.16.19 CVE-2026-18385 Wordfence
4.9 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection Authenticated (Admin+) SQL Injection via 'additional_params' Parameter ≤ 9.2.4 CVE-2026-15602 Wordfence
8.8 High Query Wrangler Plugin query-wrangler Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter ≤ 1.5.57 CVE-2026-14498 Wordfence
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation via 'item_id' Parameter No login needed ≤ 3.29.9 CVE-2026-18432 Wordfence
4.3 Medium Online Scheduling and Appointment Booking System – Bookly Plugin bookly-responsive-appointment-booking-tool Broken Access Control Bookly <= 27.7 - Authenticated (Staff+) Insecure Direct Object Reference to Sensitive Information Exposure via 'params[id]' Parameter ≤ 27.7 CVE-2026-12905 Wordfence
4.4 Medium Admin Custom Login Plugin admin-custom-login Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Message Above Login Form' Setting ≤ 3.6.4 CVE-2026-2487 Wordfence
9.1 Critical Link Library Plugin link-library Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via link_url Parameter No login needed ≤ 7.9.4 CVE-2026-18855 Wordfence
9.8 Critical Pods Plugin pods Privilege Escalation Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router No login needed 2.8 – 2.8.23.3, 2.9 – 2.9.19.3, 3.0 – 3.0.10.3, … CVE-2026-19598 Wordfence
6.5 Medium WPML Multilingual CMS Plugin sitepress-multilingual-cms SQL Injection Authenticated (Translator+) SQL Injection via 'sorting' Parameter ≤ 4.9.5 CVE-2026-12248 Wordfence
8.8 High Templately Plugin templately Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch ≤ 3.7.1 CVE-2026-18438 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter No login needed ≤ 1.2.6 CVE-2026-16142 Wordfence
7.5 High Real Estate Manager Pro Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'user_has_cap' Filter ID Collision ≤ 12.8.6 CVE-2026-15142 Wordfence
8.8 High Wholesale Market Plugin wholesale-market Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'role_required' Parameter ≤ 2.2.2 CVE-2026-14279 Wordfence
9.8 Critical User Profile Builder Plugin profile-builder Authentication Bypass Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter No login needed ≤ 3.16.4 CVE-2026-15826 Wordfence
4.3 Medium ECS Plugin Broken Access Control Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynamic Repeater Handlers < 4.3.8 Fixed in 4.3.8 CVE-2026-18807 WPScan
6.5 Medium Backup Migration Plugin backup-backup Privilege Escalation Admin+ Privilege Escalation via Post-Restore Auto-Login < 2.1.7 Fixed in 2.1.7 CVE-2026-18216 WPScan
7.5 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Information Disclosure Unauthenticated Feed Configuration Disclosure No login needed < 13.5.7 Fixed in 13.5.7 CVE-2026-16611 WPScan
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Team Member+ User Email Disclosure via Users and Customers REST Endpoints < 1.6.12.17 Fixed in 1.6.12.17 CVE-2026-16541 WPScan
5.4 Medium ECS Plugin Cross-Site Scripting Contributor+ Stored XSS via Dynamic Repeater Bindings < 4.3.8 Fixed in 4.3.8 CVE-2026-14230 WPScan
5.3 Medium ECS Plugin Information Disclosure Unauthenticated Private Content Disclosure via ecsload No login needed < 4.3.8 Fixed in 4.3.8 CVE-2026-14229 WPScan
4.9 Medium Invisible Anti-Spam & CAPTCHA Plugin gdpr-compliant-recaptcha-for-all-forms SQL Injection Authenticated (Editor+) SQL Injection via Pattern JSON Keys/Values ≤ 5.1 CVE-2026-16146 Wordfence
7.2 High Invisible Anti-Spam & CAPTCHA Plugin gdpr-compliant-recaptcha-for-all-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'action' Parameter No login needed ≤ 5.1 CVE-2026-16145 Wordfence
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter No login needed ≤ 4.3.5 CVE-2026-13360 Wordfence
4.9 Medium Invisible Anti-Spam & CAPTCHA Plugin gdpr-compliant-recaptcha-for-all-forms SQL Injection Authenticated (Editor+) SQL Injection via 'key' Parameter ≤ 5.1 CVE-2026-16094 Wordfence
6.4 Medium Hydra Booking Plugin hydra-booking Cross-Site Scripting Authenticated (Host+) Stored Cross-Site Scripting via 'first_name' Parameter ≤ 1.2.2 CVE-2026-15948 Wordfence
6.5 Medium KiviCare Plugin kivicare-clinic-management-system SQL Injection Authenticated (Doctor+) SQL Injection via 'searchTerm' Parameter ≤ 4.5.1 CVE-2026-15453 Wordfence
6.4 Medium Beaver Builder Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Button Module 'button' Parameter ≤ 2.10.2.2 CVE-2026-17090 Wordfence
6.5 Medium Contest Gallery Plugin contest-gallery SQL Injection Authenticated (Author+) Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' ≤ 30.0.7 CVE-2026-16586 Wordfence
5.3 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause ≤ 1.15.44 CVE-2026-15993 Wordfence
6.5 Medium Groundhogg Plugin groundhogg SQL Injection Authenticated (Vendor+) SQL Injection via 'tag_query' Parameter ≤ 4.5.14 CVE-2026-18387 Wordfence
5.3 Medium Pinpoint Booking System Plugin booking-system Price Manipulation Unauthenticated Improper Input Validation to Price Manipulation via 'cart_data' Parameter No login needed ≤ 2.9.9.6.8 CVE-2026-12128 Wordfence
9.8 Critical User Session Synchronizer Plugin user-session-synchronizer Authentication Bypass Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters No login needed ≤ 1.4.0 CVE-2026-15341 Wordfence
9.8 Critical 6Storage Rentals Plugin 6storage-rentals Privilege Escalation Unauthenticated Account Takeover via 'email' Parameter No login needed ≤ 2.27.0 CVE-2026-15303 Wordfence
8.8 High bLoyal: Loyalty & Promotions by bLoyal Plugin bloyal Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Unprotected AJAX API URL Settings ≤ 3.1.611.78 CVE-2026-15001 Wordfence
8.8 High MaxUpload Plugin maxupload-upload-larger-files-easily Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'resumableFilename' Parameter ≤ 1.4.0 CVE-2026-15965 Wordfence
7.5 High Object Sync for Salesforce Plugin object-sync-for-salesforce SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.13 CVE-2026-15162 Wordfence
5.3 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via wpdevart_payment AJAX Action No login needed ≤ 3.2.36 CVE-2026-8840 Wordfence
6.5 Medium Image Uploader for Welcart Plugin image-uploader-for-welcart SQL Injection Authenticated (Author+) SQL Injection via Attachment 'post_title' Parameter ≤ 1.4.6 CVE-2026-16080 Wordfence
8.8 High Propovoice: All-in-One Client Management System Plugin propovoice Privilege Escalation Authenticated (ndpv_manager+) Privilege Escalation via 'role' Parameter ≤ 1.7.8 CVE-2026-15312 Wordfence
9.1 Critical RapiSafe Plugin rapisafe-multi-file-cf7 Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters No login needed ≤ 1.0.4 CVE-2026-14484 Wordfence
7.2 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REST API 'business_id' Parameter No login needed ≤ 4.6.0 CVE-2026-14433 Wordfence
7.2 High WP-Stats Plugin wp-stats Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.56 CVE-2026-19794 Wordfence
8.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment No login needed 5.8.6 – < 6.7.2 Fixed in 6.7.2 CVE-2026-18039 WPScan
5.9 Medium Epeken All Kurir Plugin epeken-all-kurir Authentication Bypass Unauthenticated Order Payment Confirmation Forgery No login needed ≤ 2.1.4 CVE-2026-16739 WPScan
8.6 High Paymob for WooCommerce Plugin paymob-for-woocommerce SQL Injection Unauthenticated SQL Injection via Paymob Callback Pixel Lookup No login needed < 4.1.9 Fixed in 4.1.9 CVE-2026-15205 WPScan
6.8 Medium Embed Google Photos Album Easily Plugin Cross-Site Scripting Contributor+ Stored XSS via link Shortcode Attribute ≤ 2.2.1 CVE-2026-14290 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only