WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,351–2,400 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 48 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-34886 Patchstack
7.2 High AI Engine Plugin ai-engine Privilege Escalation ≤ 3.4.9 Fixed in 3.5.0 CVE-2026-27407 Patchstack
8.1 High Paid Videochat Turnkey Site Plugin ppv-live-webcams PHP Object Injection Deserialization of untrusted data No login needed ≤ 7.3.23 Fixed in 7.3.24 CVE-2026-27333 Patchstack
7.5 High WpTravelly Plugin tour-booking-manager Authentication Bypass Bypass Vulnerability No login needed ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-27089 Patchstack
9.8 Critical Broadcast Live Video Plugin videowhisper-live-streaming-integration PHP Object Injection No login needed < 7.1.3 Fixed in 7.1.3 CVE-2026-27053 Patchstack
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control No login needed < 6.6.0 Fixed in 6.6.0 CVE-2026-25440 Patchstack
7.5 High User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.1.2 Fixed in 5.1.3 CVE-2026-25425 Patchstack
8.5 High PowerPress Podcasting Plugin powerpress SQL Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-24637 Patchstack
7.1 High Redirection for Contact Form 7 Plugin wpcf7-redirect Cross-Site Scripting No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2026-23970 Patchstack
9.8 Critical Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin cf7-active-campaign PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2026-9691 Patchstack
6.5 Medium Bookify Plugin bookify Broken Access Control ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-69332 Patchstack
7.1 High Eli's WordCents adSense Widget with Analytics Plugin wordcents Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.03.27 CVE-2025-68872 Patchstack
7.1 High Okay Toolkit Plugin okay-toolkit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-68851 Patchstack
7.1 High iRobots.txt SEO Plugin irobotstxt-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-68840 Patchstack
6.3 Medium bunny.net Plugin bunnycdn Broken Access Control ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-68049 Patchstack
4.4 Medium PopAd Plugin popad Server-Side Request Forgery ≤ 1.0.4 CVE-2025-60175 Patchstack
7.5 High Projectopia Plugin projectopia-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.25.2 CVE-2025-59133 Patchstack
6.5 Medium Elizaibots Plugin elizaibot-chatbots Cross-Site Scripting ≤ 1.0.2 CVE-2025-15659 Patchstack
5.9 Medium WP Emmet Plugin wp-emmet Cross-Site Scripting ≤ 0.3.4 CVE-2025-15658 Patchstack
6.5 Medium MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control No login needed < 4.7.16 Fixed in 4.7.16 CVE-2025-64215 Patchstack
7.5 High GetPaid Plugin invoicing Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.49 Fixed in 2.8.50 CVE-2026-49064 Patchstack
6.5 Medium Really Simple SSL Plugin really-simple-ssl Broken Access Control ≤ 9.5.9 Fixed in 9.5.10 CVE-2026-48969 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system Privilege Escalation LMS plugin <= 2.2.0 - Privilege Escalation ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-49111 Patchstack
8.8 High Faust.js Plugin faustwp Authentication Bypass Broken Authentication ≤ 1.8.7 Fixed in 1.8.8 CVE-2026-49062 Patchstack
10.0 Critical WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Remote Code Execution No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-52704 Patchstack
7.1 High Sliced Invoices Plugin sliced-invoices SQL Injection WordPress Sliced Invoices 3.8.2 SQL Injection via post Parameter 3.8.2 CVE-2019-25746 VulnCheck
9.8 Critical Baggage Freight Shipping Australia Plugin baggage-freight Arbitrary File Upload WordPress Plugin Baggage Freight Shipping Australia 0.1.0 Arbitrary File Upload No login needed 0.1.0 CVE-2018-25436 VulnCheck
6.2 Medium Abtest Plugin Local File Inclusion WordPress Plugin Abtest Local File Inclusion via abtest_admin.php No login needed 1.0.6 CVE-2016-20082 VulnCheck
7.5 High HB Audio Gallery Lite Plugin hb-audio-gallery-lite Path Traversal WordPress Plugin HB Audio Gallery Lite 1.0.0 Path Traversal File Download No login needed 1.0.0 CVE-2016-20081 VulnCheck
6.2 Medium Brandfolder Plugin brandfolder Local File Inclusion WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php No login needed ≤ 3.0 CVE-2016-20080 VulnCheck
6.2 Medium Dharma Booking Plugin dharma-booking Local File Inclusion WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php No login needed ≤ 2.28.3 CVE-2016-20079 VulnCheck
6.2 Medium IMDb Profile Widget Plugin imdb-widget Local File Inclusion WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php No login needed 1.0.8 CVE-2016-20078 VulnCheck
6.2 Medium Photocart Link Plugin photocart-link Local File Inclusion WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php No login needed 1.6 CVE-2016-20077 VulnCheck
8.2 High Answer My Question Plugin answer-my-question SQL Injection Answer My Question 1.3 Plugin WordPress SQL Injection via modal.php No login needed 1.3 CVE-2016-20073 VulnCheck
8.2 High BBS e-Franchise Plugin bbs-e-franchise SQL Injection BBS e-Franchise 1.1.1 WordPress Plugin SQL Injection via uid No login needed 1.1.1 CVE-2016-20072 VulnCheck
8.2 High 404 Redirection Manager Plugin 404-redirection-manager SQL Injection WordPress 404 Redirection Manager Plugin 1.0 SQL Injection No login needed 1.0 CVE-2016-20071 VulnCheck
7.5 High WP Ticket Plugin wp-ticket SQL Injection Unauthenticated SQL Injection via WordPress Search 's' Parameter No login needed ≤ 6.0.4 CVE-2026-9848 Wordfence
4.3 Medium Hash Elements Plugin hash-elements Information Disclosure Sensitive Data Exposure ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-24618 Patchstack
6.4 Medium The Ultimate Video Player Plugin presto-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute ≤ 4.2.0 CVE-2026-9125 Wordfence
7.1 High SliceWP Plugin slicewp Cross-Site Scripting No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2026-42653 Patchstack
9.3 Critical Product Filter by WBW Plugin woo-product-filter SQL Injection No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2026-39494 Patchstack
9.3 Critical JoomSport Plugin joomsport-sports-league-results-management SQL Injection No login needed ≤ 5.7.7 Fixed in 5.7.8 CVE-2026-42647 Patchstack
9.8 Critical Hippoo Mobile App for WooCommerce Plugin hippoo Privilege Escalation No login needed ≤ 1.9.4 Fixed in 1.9.5 CVE-2026-49060 Patchstack
4.3 Medium MetroStore Theme metrostore Broken Access Control ≤ 1.3.2 CVE-2023-32959 Patchstack
5.4 Medium Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Broken Access Control No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2023-25969 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Cross-Site Request Forgery No login needed ≤ 2.0.10 Fixed in 2.0.11 CVE-2022-47150 Patchstack
5.4 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Broken Access Control Broken Access Control + CSRF ≤ 1.6.3.3 Fixed in 1.6.3.4 CVE-2022-45813 Patchstack
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
5.4 Medium Soledad Theme soledad Broken Access Control ≤ 8.2.5 Fixed in 8.2.6 CVE-2022-42479 Patchstack
5.3 Medium WP Logo Showcase Responsive Slider and Carousel Plugin wp-logo-showcase-responsive-slider-slider Broken Access Control No login needed ≤ 3.6 Fixed in 3.7 CVE-2023-40200 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only