WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,351–2,400 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 48 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Services Section Block Plugin services-section Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block Attribute ≤ 1.4.4 CVE-2026-11402 Wordfence
4.4 Medium Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More Plugin themeisle-companion Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter ≤ 3.0.6 CVE-2026-11358 Wordfence
5.3 Medium Simple Membership Plugin simple-membership Broken Access Control Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook No login needed ≤ 4.7.5 CVE-2026-12093 Wordfence
4.3 Medium Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization Plugin optimole-wp Cross-Site Request Forgery Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action No login needed ≤ 4.2.6 CVE-2026-11784 Wordfence
4.9 Medium Advanced Order Export For WooCommerce Plugin woo-order-export-lite SQL Injection Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter ≤ 4.0.10 CVE-2026-11360 Wordfence
4.9 Medium Tutor LMS Plugin tutor SQL Injection Authenticated (Administrator+) SQL Injection via 'data' Parameter ≤ 3.9.11 CVE-2026-10736 Wordfence
4.3 Medium PressPrimer Quiz Plugin pressprimer-quiz Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification via 'quiz_id', 'item_id', and 'rule_id' Parameters ≤ 2.3.0 CVE-2026-10623 Wordfence
4.3 Medium Kadence Blocks Plugin kadence-blocks Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization ≤ 3.7.5 CVE-2026-11357 Wordfence
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter ≤ 1.15.43 CVE-2026-11776 Wordfence
5.3 Medium Event Koi Lite Plugin eventkoi-lite Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API Endpoints No login needed ≤ 1.3.13.1 CVE-2026-10029 Wordfence
5.3 Medium FireBox Popups Plugin firebox Information Disclosure Unauthenticated Sensitive Information Exposure in 'form_id' Parameter No login needed ≤ 3.1.7 CVE-2026-12120 Wordfence
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Administrator+) SQL Injection via 'name' Parameter ≤ 1.15.43 CVE-2026-11777 Wordfence
4.3 Medium Equalize Digital Accessibility Checker Plugin accessibility-checker Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary Accessibility Issue Modification via 'largeBatch' Parameter ≤ 1.42.1 CVE-2026-9199 Wordfence
4.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers ≤ 5.0.3 CVE-2026-10023 Wordfence
6.5 Medium MStore API Plugin mstore-api Authentication Bypass Broken Authentication No login needed ≤ 4.18.4 Fixed in 4.19.0 CVE-2026-54817 Patchstack
6.5 Medium WorkScout-Core Plugin workscout-core Arbitrary File Deletion No login needed ≤ 1.7.11 Fixed in 1.7.12 CVE-2026-52716 Patchstack
5.3 Medium School Management Plugin school-management Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 93.1.0 CVE-2025-15657 Patchstack
4.3 Medium Metro Magazine Theme metro-magazine Broken Access Control Broken Access Control on Notice Dismissal No login needed ≤ 1.3.7 Fixed in 1.3.8 CVE-2024-37496 Patchstack
6.5 Medium AliNext Plugin ali2woo-lite Broken Access Control ≤ 3.3.5 Fixed in 3.3.7 CVE-2024-37210 Patchstack
6.5 Medium Widget Options Plugin widget-options Information Disclosure Subscriber+ User Meta Data Exposure ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-35690 Patchstack
4.3 Medium Emergency Password Reset Plugin emergency-password-reset Cross-Site Request Forgery No login needed ≤ 8.0 Fixed in 9.0 CVE-2024-35648 Patchstack
5.3 Medium iPages Flipbook Plugin ipages-flipbook Broken Access Control No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-33909 Patchstack
4.3 Medium Shareaholic Plugin shareaholic Broken Access Control ≤ 9.7.11 Fixed in 9.7.12 CVE-2024-24709 Patchstack
4.3 Medium Social Media & Share Icons Plugin ultimate-social-media-icons Broken Access Control No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2024-31435 Patchstack
4.3 Medium Startupzy Theme startupzy Broken Access Control ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-33685 Patchstack
4.3 Medium Skyline WP Theme skyline-wp Cross-Site Request Forgery No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2024-34810 Patchstack
6.8 Medium JetFormBuilder Plugin jetformbuilder Privilege Escalation ≤ 3.6.1 Fixed in 3.6.1.1 CVE-2026-54196 Patchstack
6.5 Medium WooCommerce Anti-Fraud Plugin woocommerce-anti-fraud Broken Access Control No login needed ≤ 7.2.6 Fixed in 7.2.7 CVE-2026-49072 Patchstack
6.5 Medium WooCommerce Dropshipping Plugin woocommerce-dropshipping Authentication Bypass Broken Authentication No login needed ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-49071 Patchstack
6.5 Medium WPBakery Page Builder Plugin js_composer Broken Access Control ≤ 8.7.2 Fixed in 8.7.3 CVE-2026-45436 Patchstack
6.5 Medium Client Portal (Pro) Plugin leco-client-portal Path Traversal Arbitrary File Download ≤ 5.6.2 Fixed in 5.6.3 CVE-2026-40724 Patchstack
4.3 Medium Bricks Builder Theme bricks Broken Access Control ≤ 2.1.4 Fixed in 2.2 CVE-2026-40723 Patchstack
4.7 Medium W3 Total Cache Plugin w3-total-cache Broken Access Control ≤ 2.9.1 Fixed in 2.9.2 CVE-2026-39595 Patchstack
6.5 Medium Slimstat Analytics Plugin wp-slimstat PHP Object Injection Deserialization of untrusted data No login needed < 5.4.0 Fixed in 5.4.0 CVE-2026-27410 Patchstack
4.3 Medium MetForm Pro Plugin metform-pro Broken Access Control ≤ 3.9.1 CVE-2026-24610 Patchstack
4.3 Medium WishList Member X Plugin wishlist-member-x Broken Access Control ≤ 3.29.0 CVE-2026-24575 Patchstack
6.6 Medium Counter Box Plugin counter-box PHP Object Injection Authenticated (Administrator+) PHP Object Injection via Import ≤ 2.0.13 CVE-2026-12115 Wordfence
5.5 Medium Yoast SEO Premium Plugin wordpress-seo-premium Broken Access Control ≤ 26.6 Fixed in 26.7 CVE-2026-40722 Patchstack
6.4 Medium Permalink Manager Lite Plugin permalink-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 2.5.3.3 CVE-2026-8494 Wordfence
6.4 Medium myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program Plugin mycred Cross-Site Scripting Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute ≤ 3.1 CVE-2026-8607 Wordfence
5.3 Medium LearnPress Plugin learnpress Information Disclosure Unauthenticated Sensitive User Information Disclosure via REST API No login needed < 4.3.7 Fixed in 4.3.7 CVE-2026-8383 WPScan
5.9 Medium WP Magnific Popup Plugin Cross-Site Scripting Author+ Stored XSS via href Attribute ≤ 1.0 CVE-2026-7850 WPScan
6.5 Medium WPAMS Plugin apartment-management Broken Access Control Arbitrary Content Deletion < 49.5.3 Fixed in 49.5.3 CVE-2026-39433 Patchstack
6.5 Medium Genemy Theme genemy Broken Access Control ≤ 1.6.6 CVE-2025-69137 Patchstack
6.5 Medium WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter No login needed ≤ 10.7.0 CVE-2026-2381 Wordfence
6.5 Medium Metro Magazine Theme metro-magazine Broken Access Control No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-40809 Patchstack
6.5 Medium GetGenie Plugin getgenie Information Disclosure Sensitive Data Exposure No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2026-54197 Patchstack
6.5 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control No login needed ≤ 1.12.5 Fixed in 1.12.6 CVE-2026-54190 Patchstack
6.4 Medium File Sharing & Download Manager Plugin user-private-files Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter ≤ 2.1.6 CVE-2026-10093 Wordfence
6.5 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter ≤ 2.0.7 CVE-2026-5149 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only