WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 201–250 of 29,007 vulnerabilities

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-103064 Patchstack
5.3 Medium AFFI – Affiliate Marketing for WooCommerce Plugin affi-affiliate-marketing-for-woo Broken Access Control Affiliate Marketing for WooCommerce plugin <= 1.0.9 - Broken Access Control No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2026-102390 Patchstack
4.3 Medium Majestic Support Plugin majestic-support Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-102382 Patchstack
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-102381 Patchstack
6.5 Medium FluentForm Plugin fluentform Cross-Site Scripting ≤ 6.2.14 Fixed in 6.2.15 CVE-2026-103343 Patchstack
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103341 Patchstack
5.3 Medium Site Reviews Plugin site-reviews Broken Access Control No login needed ≤ 8.3.2 Fixed in 8.3.3 CVE-2026-103340 Patchstack
8.5 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection ≤ 2.0.20 Fixed in 2.0.21 CVE-2026-103338 Patchstack
8.0 High Memberful - Membership Plugin memberful-wp Cross-Site Request Forgery Membership Plugin plugin <= 1.81.0 - Cross Site Request Forgery (CSRF) ≤ 1.81.0 Fixed in 1.81.1 CVE-2026-103067 Patchstack
5.3 Medium WP Ultimate CSV Importer Plugin wp-ultimate-csv-importer Information Disclosure Sensitive Data Exposure No login needed ≤ 9.1 Fixed in 9.2 CVE-2026-103336 Patchstack
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 6.2.14 Fixed in 6.2.15 CVE-2026-103353 Patchstack
7.2 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-103082 Patchstack
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter No login needed ≤ 1.57.2 CVE-2026-92144 Wordfence
6.4 Medium Gutenberg Essential Blocks Plugin essential-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute ≤ 6.4.5 CVE-2026-96256 Wordfence
7.2 High Business Essentials for Contact Form 7 Plugin cf7-redirect-thank-you-page Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'gateway' Form Field No login needed ≤ 1.2.1 CVE-2026-97661 Wordfence
6.1 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting Reflected Cross-Site Scripting via 's' Search Parameter No login needed ≤ 2.8.18 CVE-2026-89427 Wordfence
6.4 Medium Duplicate Post Plugin copy-delete-posts Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'noti_token' Parameter ≤ 1.5.6 CVE-2026-89424 Wordfence
4.7 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 'x' URL Query Parameter via Text Area Predefined Value No login needed ≤ 5.5.1.3 CVE-2026-100184 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields No login needed ≤ 1.15.47 CVE-2026-96813 Wordfence
6.4 Medium Awesome Support Plugin awesome-support Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action ≤ 6.4.0 CVE-2026-96268 Wordfence
6.4 Medium bbp style pack Plugin bbp-style-pack Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Author Display Name ≤ 6.4.8 CVE-2026-101925 Wordfence
8.8 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint ≤ 2.0.0 CVE-2026-95687 Wordfence
7.2 High Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer No login needed ≤ 1.5.97 CVE-2026-96573 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field No login needed ≤ 1.57.2 CVE-2026-85235 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Billing First Name / Last Name / Company Fields No login needed ≤ 5.16.1 CVE-2026-92244 Wordfence
6.4 Medium Redux Framework Plugin redux-framework Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'user-mediaurl' Media Field ≤ 4.5.14 CVE-2026-90992 Wordfence
8.1 High Super Forms Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter ≤ 6.3.316 CVE-2026-15983 Wordfence
6.1 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via 'x' URL Parameter via setChoices() No login needed ≤ 5.5.1.3 CVE-2026-100179 Wordfence
7.2 High Autoptimize Plugin autoptimize Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Path No login needed ≤ 3.1.15.1 CVE-2026-14995 Wordfence
8.8 High ByteCoreStack Plugin bcs-mcp-manager Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool ≤ 1.2.3 CVE-2026-19807 Wordfence
9.8 Critical Ultimate Multisite Plugin ultimate-multisite Authentication Bypass Unauthenticated Authentication Bypass via 'checkout_form' Parameter No login needed ≤ 2.15.0 CVE-2026-75957 Wordfence
6.1 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header) No login needed ≤ 2.8.18 CVE-2026-19902 Wordfence
9.8 Critical Super Forms Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'role' Parameter No login needed ≤ 6.3.316 CVE-2026-15989 Wordfence
7.5 High LearnPress Plugin learnpress Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter No login needed ≤ 4.4.8 CVE-2026-93882 Wordfence
6.1 Medium Social Media Share Buttons & Social Sharing Icons Plugin ultimate-social-media-icons Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via URL No login needed ≤ 3.0.1 CVE-2026-89047 Wordfence
7.5 High Payments for Hubtel Plugin payments-hubtel Information Disclosure Unauthenticated Payment Gateway Credentials Disclosure via Debug Log No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96255 WPScan
5.3 Medium Payments for Hubtel Plugin payments-hubtel Broken Access Control Unauthenticated Payment Confirmation Forgery via Delayed Payment Callback No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96200 WPScan
5.3 Medium Payments for Hubtel Plugin payments-hubtel Information Disclosure Unauthenticated Order Key Disclosure via IDOR No login needed < 1.0.2 Fixed in 1.0.2 CVE-2026-96173 WPScan
7.1 High Five Star Restaurant Reviews Plugin good-reviews-wp Cross-Site Scripting Reflected XSS No login needed < 2.3.14 Fixed in 2.3.14 CVE-2026-92412 WPScan
6.5 Medium WP Fusion Lite Plugin wp-fusion-lite Broken Access Control Unauthenticated CRM Integration Settings Update No login needed 3.37.14 – < 3.48.0 Fixed in 3.48.0 CVE-2026-90974 WPScan
5.4 Medium WP Fusion Lite Plugin wp-fusion-lite Information Disclosure Subscriber+ User Email Disclosure and Cross-User CRM Data Deletion < 3.48.0 Fixed in 3.48.0 CVE-2026-90972 WPScan
8.6 High Pro Like Button Plugin SQL Injection Unauthenticated SQLi via 'postid' Parameter No login needed < 2.0 Fixed in 2.0 CVE-2026-89296 WPScan
3.1 Low If-So Dynamic Content Plugin if-so Cross-Site Scripting Editor+ Stored XSS via Conversion Name 1.9.9 – < 1.10.2 Fixed in 1.10.2 CVE-2026-87973 WPScan
4.7 Medium If-So Dynamic Content Plugin if-so Cross-Site Scripting Reflected XSS via render_ifso_shortcodes No login needed 1.8 – < 1.10.2 Fixed in 1.10.2 CVE-2026-87970 WPScan
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Author+ Stored XSS via Package Icon < 3.3.71 Fixed in 3.3.71 CVE-2026-86610 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments SQL Injection Unauthenticated SQLi via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81809 WPScan
10.0 Critical BackupSheep Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key No login needed ≤ 1.8 CVE-2026-101148 WPScan
8.8 High Featured Image from URL (FIFU) Free & Premium Plugin Cross-Site Request Forgery Administrator Account Creation via CSRF No login needed 6.0.0 – < 6.0.8, 6.8.0 – < 8.2.8 Fixed in 6.0.8 CVE-2026-101147 WPScan
7.5 High Paytm Payment Gateway Plugin paytm-payments Cross-Site Scripting Unauthenticated Stored XSS via Payment Callback No login needed < 2.8.9 Fixed in 2.8.9 CVE-2026-81739 WPScan
8.7 High Cache Enabler Plugin cache-enabler Arbitrary File Deletion Unauthenticated Arbitrary File and Directory Deletion via cache_enabler_clear_page_cache_by_url No login needed < 1.8.17 Fixed in 1.8.17 CVE-2026-19253 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only