WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 2,301–2,350 of 17,704 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | MIR blocks and shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.0 |
CVE-2026-8896 |
Wordfence | |
| 5.3 Medium | Devs Accounting | Broken Access Control Missing Authorization to Unauthenticated Account Deletion via /delete-account/ REST Endpoint No login needed |
≤ 1.2.0 |
CVE-2026-9172 |
Wordfence | |
| 4.3 Medium | Generate Security.txt | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Security.txt Deletion via delete_securitytxt AJAX Action |
≤ 1.0.12 |
CVE-2026-9616 |
Wordfence | |
| 5.3 Medium | SearchPlus | Broken Access Control Missing Authorization to Unauthenticated Settings Modification and Deletion via searchplus_save_token & searchplus_reset_token AJAX Actions No login needed |
≤ 1.7.1 |
CVE-2026-8617 |
Wordfence | |
| 4.3 Medium | MP Customize Login Page | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0 |
CVE-2026-6292 |
Wordfence | |
| 4.3 Medium | 24liveblog | Broken Access Control Missing Authorization to Authenticated (Author+) Settings Modification via update_lb24_token AJAX action |
≤ 2.2 |
CVE-2026-9184 |
Wordfence | |
| 4.3 Medium | Blue Captcha | Cross-Site Request Forgery Cross-Site Request Forgery via 'blcap_action' Parameter No login needed |
≤ 2.0.1 |
CVE-2026-10552 |
Wordfence | |
| 6.1 Medium | EntreDroppers | Cross-Site Scripting Reflected Cross-Site Scripting via PHP_SELF Parameter No login needed |
≤ 1.1.2 |
CVE-2026-8628 |
Wordfence | |
| 4.3 Medium | Reviews and Rating | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via sync_reviews AJAX Action |
≤ 1.1.4 |
CVE-2026-9619 |
Wordfence | |
| 4.3 Medium | Assistio | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Deletion via assistio_plugin_delete_assistio_settings AJAX Action |
≤ 1.1.2 |
CVE-2026-8614 |
Wordfence | |
| 5.3 Medium | Secufor_OAuth | Broken Access Control Missing Authorization to Unauthenticated Account Logout via 'secuforoauth_unregister_action' AJAX Action No login needed |
≤ 1.0.7 |
CVE-2026-7617 |
Wordfence | |
| 5.3 Medium | Advanced Contact Form 7 | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter No login needed |
≤ 1.0.0 |
CVE-2026-12094 |
Wordfence | |
| 4.3 Medium | MotorDesk | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.1.2 |
CVE-2026-9724 |
Wordfence | |
| 6.4 Medium | WP Meta SEO | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter |
≤ 4.5.18 |
CVE-2026-11370 |
Wordfence | |
| 4.3 Medium | Book a Room Event Calendar | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.9 |
CVE-2026-9721 |
Wordfence | |
| 5.3 Medium | Devs Accounting | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via 'id' Parameter No login needed |
≤ 1.2.0 |
CVE-2026-9175 |
Wordfence | |
| 6.1 Medium | Osiris Signature Banner | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter No login needed |
≤ 0.5 |
CVE-2026-8905 |
Wordfence | |
| 6.4 Medium | Xpro Addons | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets |
≤ 1.7.2 |
CVE-2026-11614 |
Wordfence | |
| 6.4 Medium | ProfileGrid | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content |
≤ 5.9.9.2 |
CVE-2026-4610 |
Wordfence | |
| 5.4 Medium | Frontend File Manager | Cross-Site Scripting Subscriber+ Stored Cross-Site Scripting via File Rename |
≤ 23.6 |
CVE-2026-8378 |
WPScan | |
| 6.8 Medium | Infility Global | SQL Injection Editor+ SQL Injection via orderby Parameter |
< 2.15.20 Fixed in 2.15.20 |
CVE-2026-7842 |
WPScan | |
| 5.3 Medium | Motors Car Dealership & Classified Listings | Cross-Site Request Forgery Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media No login needed |
< 1.4.110 Fixed in 1.4.110 |
CVE-2026-7859 |
WPScan | |
| 5.3 Medium | Pie Register | Other Unauthenticated Email Verification Bypass via Predictable Token No login needed |
< 3.8.4.10 Fixed in 3.8.4.10 |
CVE-2026-10530 |
WPScan | |
| 6.1 Medium | Ultimate WooCommerce Auction Pro | Cross-Site Scripting Reflected XSS via uwa_auctions_bids_list No login needed |
≤ 2.4.5 |
CVE-2026-4110 |
WPScan | |
| 6.5 Medium | Simple File List | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute |
≤ 6.3.7 |
CVE-2026-12119 |
Wordfence | |
| 5.3 Medium | WP Go Maps | Broken Access Control Unauthenticated Arbitrary Record Creation No login needed |
≤ 10.1.01 |
CVE-2026-12238 |
Wordfence | |
| 5.3 Medium | 2Download Connector for 2DL Hosted Checkout | Broken Access Control Missing Authorization to Unauthenticated Sensitive Customer Subscription Data Exposure via 'ToDownload_email' Parameter No login needed |
≤ 0.1.5 |
CVE-2026-6798 |
Wordfence | |
| 5.3 Medium | STRABL | Broken Access Control Unauthenticated Arbitrary Webhook Creation via REST API Endpoint No login needed |
≤ 4.5 |
CVE-2026-3640 |
Wordfence | |
| 6.5 Medium | WP Hotel Booking | Broken Access Control Subscriber+ Missing Authorization in Multiple AJAX Handlers |
< 2.3.1 Fixed in 2.3.1 |
CVE-2026-9822 |
WPScan | |
| 4.4 Medium | Blocksy Companion | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter |
≤ 2.1.45 |
CVE-2026-12430 |
Wordfence | |
| 5.3 Medium | WP DSGVO Tools (GDPR) | Broken Access Control Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters) No login needed |
≤ 3.1.39 |
CVE-2026-10034 |
Wordfence | |
| 6.5 Medium | Royal Addons for Elementor – Addons and Templates Kit for Elementor | Path Traversal Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source |
1.7.1058 – 1.7.1059 |
CVE-2026-8118 |
Wordfence | |
| 6.5 Medium | Bit integrations | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping No login needed |
≤ 2.8.7 |
CVE-2026-11989 |
Wordfence | |
| 4.3 Medium | Bogo | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST API |
≤ 3.9.1 |
CVE-2026-9013 |
Wordfence | |
| 6.4 Medium | Advanced Import: One-Click Demo Import | Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter |
≤ 1.4.6 |
CVE-2026-4328 |
Wordfence | |
| 6.4 Medium | BetterDocs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute |
≤ 4.5.3 |
CVE-2026-12157 |
Wordfence | |
| 4.9 Medium | Woosa | Path Traversal Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter |
≤ 2.0.5 |
CVE-2026-7547 |
Wordfence | |
| 6.4 Medium | Appointment Booking Calendar | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label |
≤ 1.4.4 |
CVE-2026-1856 |
Wordfence | |
| 4.3 Medium | Classified Listing | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters) |
≤ 5.4.2 |
CVE-2026-10779 |
Wordfence | |
| 4.3 Medium | User Admin Simplifier | Cross-Site Request Forgery No login needed |
≤ 3.0.0 |
CVE-2026-11775 |
Wordfence | |
| 6.5 Medium | WP EasyPay | Cross-Site Request Forgery No login needed |
≤ 4.5.0 |
CVE-2026-56024 |
Patchstack | |
| 5.9 Medium | Bricksable for Bricks Builder | Cross-Site Scripting |
≤ 1.6.83 Fixed in 1.6.84 |
CVE-2026-56009 |
Patchstack | |
| 5.9 Medium | Ocean Product Sharing | Cross-Site Scripting |
≤ 2.2.2 Fixed in 2.2.3 |
CVE-2026-56007 |
Patchstack | |
| 6.4 Medium | Slideshow Gallery LITE | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute |
≤ 1.8.5 |
CVE-2026-2021 |
Wordfence | |
| 6.4 Medium | Fancy Testimonials | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2026-8039 |
Wordfence | |
| 4.3 Medium | Appointment Booking Calendar | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter |
≤ 1.4.01 |
CVE-2026-12111 |
Wordfence | |
| 6.4 Medium | PowerPress Podcasting plugin by Blubrry | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field |
≤ 11.16.8 |
CVE-2026-12098 |
Wordfence | |
| 6.1 Medium | SysBasics Customize My Account for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via 'tab' Parameter No login needed |
≤ 4.3.6 |
CVE-2026-12137 |
Wordfence | |
| 6.4 Medium | SysBasics Customize My Account for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 4.3.6 |
CVE-2026-12136 |
Wordfence | |
| 6.5 Medium | MagicForm | Arbitrary File Upload Unauthenticated Arbitrary File Upload to RCE No login needed |
≤ 0.1.3 |
CVE-2026-9815 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.