WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,301–2,350 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 47 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' ≤ 1.6.4 CVE-2026-4326 Wordfence
8.1 High MW WP Form Plugin mw-wp-form Remote Code Execution Unauthenticated Arbitrary File Move via regenerate_upload_file_keys No login needed ≤ 5.1.1 CVE-2026-5436 Wordfence
7.5 High WCAPF – WooCommerce Ajax Product Filter Plugin wc-ajax-product-filter SQL Injection WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection No login needed ≤ 4.2.3 CVE-2026-3396 Wordfence
8.8 High Advanced Members for ACF Plugin advanced-members Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via Path Traversal ≤ 1.2.5 CVE-2026-3243 Wordfence
7.5 High OrganicFood Theme organicfood Local File Inclusion ≤ 3.6.4 CVE-2026-39684 Patchstack
7.5 High Homeo Theme homeo Local File Inclusion ≤ 1.2.59 CVE-2026-39681 Patchstack
7.5 High Freeio Theme freeio Local File Inclusion ≤ 1.3.21 CVE-2026-39679 Patchstack
7.5 High Emphires Theme emphires Local File Inclusion ≤ 3.9 CVE-2026-39677 Patchstack
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack
7.5 High Biolife Theme biolife Local File Inclusion ≤ 3.2.3 CVE-2026-39623 Patchstack
8.8 High SpicePress Plugin spicepress Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 2.3.2.5 CVE-2026-39621 Patchstack
7.5 High Boutique Theme kute-boutique Local File Inclusion ≤ 2.3.3 CVE-2026-39613 Patchstack
7.5 High KuteShop Theme kuteshop Local File Inclusion ≤ 4.2.9 CVE-2026-39611 Patchstack
7.5 High LabtechCO Theme labtechco Local File Inclusion ≤ 8.3 Fixed in 8.4 CVE-2026-39544 Patchstack
7.5 High Mikado Core Plugin mikado-core Local File Inclusion ≤ 1.6 Fixed in 2.2.2 CVE-2026-39538 Patchstack
7.6 High FOX Plugin woocommerce-currency-switcher SQL Injection ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-39497 Patchstack
7.6 High YayMail Plugin yaymail SQL Injection ≤ 4.3.3 Fixed in 4.3.4 CVE-2026-39496 Patchstack
8.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection ≤ 1.6.9.27 Fixed in 1.6.9.29 CVE-2026-39495 Patchstack
7.6 High Amelia Plugin ameliabooking SQL Injection ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-39487 Patchstack
8.5 High Download Monitor Plugin download-monitor SQL Injection ≤ 5.1.8 Fixed in 5.1.9 CVE-2026-39486 Patchstack
7.6 High OttoKit Plugin suretriggers SQL Injection ≤ 1.1.20 Fixed in 1.1.21 CVE-2026-39479 Patchstack
7.6 High User Feedback Plugin userfeedback-lite SQL Injection ≤ 1.10.1 Fixed in 1.11.0 CVE-2026-39475 Patchstack
7.6 High Broken Link Checker Plugin broken-link-checker SQL Injection ≤ 2.4.7 Fixed in 2.4.8 CVE-2026-39466 Patchstack
7.2 High Gerador de Certificados – DevApps Plugin gerador-de-certificados-devapps Arbitrary File Upload DevApps <= 1.3.6 - Authenticated (Administrator+) Arbitrary File Upload ≤ 1.3.6 CVE-2026-4808 Wordfence
7.5 High ActivityPub Routing Plugin Information Disclosure Unauthenticated Drafts/Scheduled/Pending Posts Disclosure No login needed < 8.0.2 Fixed in 8.0.2 CVE-2026-4338 WPScan
8.8 High Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions No login needed 13.4.6 – 13.5.2.1 CVE-2026-3499 Wordfence
7.5 High Simple Social Media Share Buttons Plugin simple-social-buttons Cross-Site Request Forgery No login needed ≤ 6.2.0 Fixed in 6.2.1 CVE-2026-34904 Patchstack
7.5 High Under Construction, Coming Soon & Maintenance Mode Plugin under-construction-maintenance-mode Cross-Site Request Forgery No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2026-34896 Patchstack
8.8 High Amelia Plugin ameliabooking Broken Access Control Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter ≤ 2.1.3 CVE-2026-5465 Wordfence
8.5 High Media LIbrary Assistant Plugin media-library-assistant SQL Injection ≤ 3.34 Fixed in 3.35 CVE-2026-34885 Patchstack
8.8 High wpForo Forum Plugin wpforo Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via Post Body ≤ 2.4.16 CVE-2026-3666 Wordfence
7.2 High Visitor Traffic Real Time Statistics Plugin visitors-traffic-real-time-statistics Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.4 CVE-2026-2936 Wordfence
7.5 High Text to Speech (TTS) by Mementor Plugin text-to-speech-tts Information Disclosure Use of Hardcoded Password to Unauthenticated Remote Database Access No login needed ≤ 1.9.8 CVE-2026-1233 Wordfence
7.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Broken Access Control ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass ≤ 4.16.11 CVE-2026-3445 Wordfence
7.2 High Widgets for Social Photo Feed Plugin social-photo-feed-widget Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via feed_data No login needed ≤ 1.7.9 CVE-2026-5425 Wordfence
8.1 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation ≤ 6.7.25 CVE-2026-4896 Wordfence
8.1 High Perfmatters Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter ≤ 2.5.9.1 CVE-2026-4350 Wordfence
7.5 High W3 Total Cache Plugin w3-total-cache Information Disclosure Unauthenticated Security Token Exposure via User-Agent Header No login needed ≤ 2.9.3 CVE-2026-5032 Wordfence
7.2 High Webmention Plugin webmention Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 5.6.2 CVE-2026-0686 Wordfence
7.2 High Spam Protect for Contact Form 7 Plugin wp-contact-form-7-spam-blocker Remote Code Execution Editor+ Remote Code Execution < 1.2.10 Fixed in 1.2.10 CVE-2026-1540 WPScan
8.1 High MW WP Form Plugin mw-wp-form Remote Code Execution Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir No login needed ≤ 5.1.0 CVE-2026-4347 Wordfence
7.2 High Query Monitor Plugin query-monitor Cross-Site Scripting Reflected Cross-Site Scripting via Request URI No login needed ≤ 3.20.3 CVE-2026-4267 Wordfence
7.5 High Gravity SMTP Plugin gravitysmtp Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed ≤ 2.1.4 CVE-2026-4020 Wordfence
8.8 High Debugger & Troubleshooter Plugin debugger-troubleshooter Privilege Escalation Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation ≤ 1.3.2 CVE-2026-5130 Wordfence
7.5 High Download Monitor Plugin download-monitor Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' No login needed ≤ 5.1.7 CVE-2026-3124 Wordfence
7.2 High Oxygen Theme oxygen Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via route_path No login needed ≤ 6.0.8 CVE-2025-12886 Wordfence
7.5 High SureForms Plugin sureforms Other Unauthenticated Payment Amount Validation Bypass via 'form_id' No login needed ≤ 2.5.2 CVE-2026-4987 Wordfence
8.0 High Ultimate Member Plugin ultimate-member Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag ≤ 2.11.2 CVE-2026-4248 Wordfence
7.2 High Fluent Booking Plugin fluent-booking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed ≤ 2.0.01 CVE-2026-2231 Wordfence
7.5 High JS Help Desk – AI-Powered Support & Ticketing System Plugin js-support-ticket SQL Injection AI-Powered Support & Ticketing System <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter No login needed ≤ 3.0.4 CVE-2026-2511 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only