WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 2,301–2,350 of 9,010 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | Vertex Addons for Elementor | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' |
≤ 1.6.4 |
CVE-2026-4326 |
Wordfence | |
| 8.1 High | MW WP Form | Remote Code Execution Unauthenticated Arbitrary File Move via regenerate_upload_file_keys No login needed |
≤ 5.1.1 |
CVE-2026-5436 |
Wordfence | |
| 7.5 High | WCAPF – WooCommerce Ajax Product Filter | SQL Injection WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection No login needed |
≤ 4.2.3 |
CVE-2026-3396 |
Wordfence | |
| 8.8 High | Advanced Members for ACF | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via Path Traversal |
≤ 1.2.5 |
CVE-2026-3243 |
Wordfence | |
| 7.5 High | OrganicFood | Local File Inclusion |
≤ 3.6.4 |
CVE-2026-39684 |
Patchstack | |
| 7.5 High | Homeo | Local File Inclusion |
≤ 1.2.59 |
CVE-2026-39681 |
Patchstack | |
| 7.5 High | Freeio | Local File Inclusion |
≤ 1.3.21 |
CVE-2026-39679 |
Patchstack | |
| 7.5 High | Emphires | Local File Inclusion |
≤ 3.9 |
CVE-2026-39677 |
Patchstack | |
| 7.1 High | Extra Fees Plugin for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 4.3.3 |
CVE-2026-39671 |
Patchstack | |
| 7.5 High | Biolife | Local File Inclusion |
≤ 3.2.3 |
CVE-2026-39623 |
Patchstack | |
| 8.8 High | SpicePress | Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed |
≤ 2.3.2.5 |
CVE-2026-39621 |
Patchstack | |
| 7.5 High | Boutique | Local File Inclusion |
≤ 2.3.3 |
CVE-2026-39613 |
Patchstack | |
| 7.5 High | KuteShop | Local File Inclusion |
≤ 4.2.9 |
CVE-2026-39611 |
Patchstack | |
| 7.5 High | LabtechCO | Local File Inclusion |
≤ 8.3 Fixed in 8.4 |
CVE-2026-39544 |
Patchstack | |
| 7.5 High | Mikado Core | Local File Inclusion |
≤ 1.6 Fixed in 2.2.2 |
CVE-2026-39538 |
Patchstack | |
| 7.6 High | FOX | SQL Injection |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2026-39497 |
Patchstack | |
| 7.6 High | YayMail | SQL Injection |
≤ 4.3.3 Fixed in 4.3.4 |
CVE-2026-39496 |
Patchstack | |
| 8.5 High | Simply Schedule Appointments | SQL Injection |
≤ 1.6.9.27 Fixed in 1.6.9.29 |
CVE-2026-39495 |
Patchstack | |
| 7.6 High | Amelia | SQL Injection |
≤ 2.1.1 Fixed in 2.1.2 |
CVE-2026-39487 |
Patchstack | |
| 8.5 High | Download Monitor | SQL Injection |
≤ 5.1.8 Fixed in 5.1.9 |
CVE-2026-39486 |
Patchstack | |
| 7.6 High | OttoKit | SQL Injection |
≤ 1.1.20 Fixed in 1.1.21 |
CVE-2026-39479 |
Patchstack | |
| 7.6 High | User Feedback | SQL Injection |
≤ 1.10.1 Fixed in 1.11.0 |
CVE-2026-39475 |
Patchstack | |
| 7.6 High | Broken Link Checker | SQL Injection |
≤ 2.4.7 Fixed in 2.4.8 |
CVE-2026-39466 |
Patchstack | |
| 7.2 High | Gerador de Certificados – DevApps | Arbitrary File Upload DevApps <= 1.3.6 - Authenticated (Administrator+) Arbitrary File Upload |
≤ 1.3.6 |
CVE-2026-4808 |
Wordfence | |
| 7.5 High | ActivityPub Routing | Information Disclosure Unauthenticated Drafts/Scheduled/Pending Posts Disclosure No login needed |
< 8.0.2 Fixed in 8.0.2 |
CVE-2026-4338 |
WPScan | |
| 8.8 High | Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce | Cross-Site Request Forgery Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions No login needed |
13.4.6 – 13.5.2.1 |
CVE-2026-3499 |
Wordfence | |
| 7.5 High | Simple Social Media Share Buttons | Cross-Site Request Forgery No login needed |
≤ 6.2.0 Fixed in 6.2.1 |
CVE-2026-34904 |
Patchstack | |
| 7.5 High | Under Construction, Coming Soon & Maintenance Mode | Cross-Site Request Forgery No login needed |
≤ 2.1.1 Fixed in 2.1.2 |
CVE-2026-34896 |
Patchstack | |
| 8.8 High | Amelia | Broken Access Control Insecure Direct Object Reference to Authenticated (Employee+) Privilege Escalation via 'externalId' Parameter |
≤ 2.1.3 |
CVE-2026-5465 |
Wordfence | |
| 8.5 High | Media LIbrary Assistant | SQL Injection |
≤ 3.34 Fixed in 3.35 |
CVE-2026-34885 |
Patchstack | |
| 8.8 High | wpForo Forum | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via Post Body |
≤ 2.4.16 |
CVE-2026-3666 |
Wordfence | |
| 7.2 High | Visitor Traffic Real Time Statistics | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 8.4 |
CVE-2026-2936 |
Wordfence | |
| 7.5 High | Text to Speech (TTS) by Mementor | Information Disclosure Use of Hardcoded Password to Unauthenticated Remote Database Access No login needed |
≤ 1.9.8 |
CVE-2026-1233 |
Wordfence | |
| 7.1 High | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | Broken Access Control ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass |
≤ 4.16.11 |
CVE-2026-3445 |
Wordfence | |
| 7.2 High | Widgets for Social Photo Feed | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via feed_data No login needed |
≤ 1.7.9 |
CVE-2026-5425 |
Wordfence | |
| 8.1 High | WCFM - WooCommerce Frontend Manager | Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation |
≤ 6.7.25 |
CVE-2026-4896 |
Wordfence | |
| 8.1 High | Perfmatters | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter |
≤ 2.5.9.1 |
CVE-2026-4350 |
Wordfence | |
| 7.5 High | W3 Total Cache | Information Disclosure Unauthenticated Security Token Exposure via User-Agent Header No login needed |
≤ 2.9.3 |
CVE-2026-5032 |
Wordfence | |
| 7.2 High | Webmention | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 5.6.2 |
CVE-2026-0686 |
Wordfence | |
| 7.2 High | Spam Protect for Contact Form 7 | Remote Code Execution Editor+ Remote Code Execution |
< 1.2.10 Fixed in 1.2.10 |
CVE-2026-1540 |
WPScan | |
| 8.1 High | MW WP Form | Remote Code Execution Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir No login needed |
≤ 5.1.0 |
CVE-2026-4347 |
Wordfence | |
| 7.2 High | Query Monitor | Cross-Site Scripting Reflected Cross-Site Scripting via Request URI No login needed |
≤ 3.20.3 |
CVE-2026-4267 |
Wordfence | |
| 7.5 High | Gravity SMTP | Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed |
≤ 2.1.4 |
CVE-2026-4020 |
Wordfence | |
| 8.8 High | Debugger & Troubleshooter | Privilege Escalation Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation |
≤ 1.3.2 |
CVE-2026-5130 |
Wordfence | |
| 7.5 High | Download Monitor | Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Order Completion via 'token' and 'order_id' No login needed |
≤ 5.1.7 |
CVE-2026-3124 |
Wordfence | |
| 7.2 High | Oxygen | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via route_path No login needed |
≤ 6.0.8 |
CVE-2025-12886 |
Wordfence | |
| 7.5 High | SureForms | Other Unauthenticated Payment Amount Validation Bypass via 'form_id' No login needed |
≤ 2.5.2 |
CVE-2026-4987 |
Wordfence | |
| 8.0 High | Ultimate Member | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure to Account Takeover via Shortcode Template Tag |
≤ 2.11.2 |
CVE-2026-4248 |
Wordfence | |
| 7.2 High | Fluent Booking | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Parameters No login needed |
≤ 2.0.01 |
CVE-2026-2231 |
Wordfence | |
| 7.5 High | JS Help Desk – AI-Powered Support & Ticketing System | SQL Injection AI-Powered Support & Ticketing System <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter No login needed |
≤ 3.0.4 |
CVE-2026-2511 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.