WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 6,408 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-84820 Patchstack
8.8 High Nokri – Job Board Theme Broken Access Control Job Board WordPress Theme <= 1.6.4 - Missing Authorization to Authenticated (Subscriber +) Privilege Escalation via Account Takeover ≤ 1.6.4 CVE-2025-9049 Wordfence
8.6 High Music Store – WordPress eCommerce Plugin music-store SQL Injection WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler No login needed 1.0.245 – < 1.4.5 Fixed in 1.4.5 CVE-2026-82304 WPScan
7.6 High WooCommerce Plugin woocommerce SQL Injection < 11.0 Fixed in 11.0 CVE-2026-57777 Patchstack
7.1 High Quick Event Manager Plugin quick-event-manager Cross-Site Scripting No login needed ≤ 9.17 CVE-2026-84848 Patchstack
7.5 High Quick Event Manager Plugin quick-event-manager Broken Access Control No login needed ≤ 9.17 CVE-2026-84847 Patchstack
7.1 High WC Ukraine Shipping Plugin wc-ukr-shipping Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.22.3 CVE-2026-84836 Patchstack
7.1 High BP Better Messages Plugin bp-better-messages Cross-Site Scripting No login needed ≤ 2.15.27 Fixed in 2.15.28 CVE-2026-84812 Patchstack
8.1 High Agentimus – AI SEO, llms.txt & MCP for AI Agents Plugin agentimus Broken Access Control AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Access Control ≤ 1.51.0 Fixed in 1.51.1 CVE-2026-84779 Patchstack
7.5 High Migrate Guru – Site Migration & Cloning Plugin migrate-guru Denial of Service Site Migration & Cloning plugin <= 6.65 - Denial of Service Attack No login needed ≤ 6.65 Fixed in 6.72 CVE-2026-84778 Patchstack
7.4 High Really Simple SSL Plugin really-simple-ssl Authentication Bypass WordPress Really Simple SSL plugin <= 9.8.0 - 2FA Bypass No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84777 Patchstack
7.5 High MalCare Security Plugin malcare-security Denial of Service Denial of Service Attack No login needed ≤ 6.69 Fixed in 6.72 CVE-2026-84776 Patchstack
7.2 High EWWW Image Optimizer Plugin ewww-image-optimizer Cross-Site Scripting No login needed ≤ 8.7.6 Fixed in 8.7.7 CVE-2026-84773 Patchstack
7.1 High Breadcrumb NavXT Plugin breadcrumb-navxt Cross-Site Scripting No login needed ≤ 7.5.1 Fixed in 7.5.2 CVE-2026-84765 Patchstack
7.1 High RTMKit Plugin rometheme-for-elementor Cross-Site Scripting No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84763 Patchstack
7.2 High LiteSpeed Cache Plugin litespeed-cache Server-Side Request Forgery No login needed ≤ 7.9 Fixed in 7.9.1 CVE-2026-84761 Patchstack
8.2 High WP Compress Plugin wp-compress-image-optimizer Broken Access Control Settings Change No login needed ≤ 7.21.28 Fixed in 7.22.0 CVE-2026-84757 Patchstack
7.1 High WCFM Membership Plugin wc-multivendor-membership Privilege Escalation ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-84756 Patchstack
8.8 High RTMKit Plugin rometheme-for-elementor PHP Object Injection ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-84752 Patchstack
7.1 High WP QuickLaTeX Plugin wp-quicklatex Cross-Site Scripting No login needed ≤ 3.8.8 CVE-2026-81776 Patchstack
7.1 High Ninja Forms File Uploads Extension Plugin ninja-forms-uploads Arbitrary File Upload Cross Site Scripting (XSS) No login needed ≤ 3.3.26 CVE-2026-81773 Patchstack
7.1 High Calculation For Contact Form 7 Plugin calculation-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0 Fixed in 1.1 CVE-2026-81300 Patchstack
7.1 High Under Construction Plugin under-construction-page Cross-Site Scripting No login needed ≤ 5.82 Fixed in 5.83 CVE-2026-81295 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-81292 Patchstack
8.8 High Mang Board WP Plugin mangboard Cross-Site Request Forgery No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2026-84770 Patchstack
8.8 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Request Forgery No login needed ≤ 1.6.12.23 Fixed in 1.6.12.24 CVE-2026-84764 Patchstack
7.1 High Activity Log Plugin aryo-activity-log Cross-Site Request Forgery No login needed ≤ 2.13.1 Fixed in 2.14.0 CVE-2026-84759 Patchstack
7.1 High Estatik Plugin estatik Cross-Site Scripting No login needed ≤ 4.3.4 CVE-2026-81775 Patchstack
7.5 High WooCommerce Product Attachment Plugin woo-product-attachment Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-81774 Patchstack
8.8 High Ninja Forms - Layout & Styles Plugin ninja-forms-style PHP Object Injection Layout & Styles plugin <= 3.0.31 - PHP Object Injection No login needed ≤ 3.0.31 CVE-2026-81772 Patchstack
7.1 High TrustedSite Plugin trustedsite Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2026-81771 Patchstack
7.1 High Interactive Geo Maps Plugin interactive-geo-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.30 CVE-2026-81770 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.1 CVE-2026-81769 Patchstack
7.1 High MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting No login needed ≤ 5.13.1 Fixed in 5.14 CVE-2026-81289 Patchstack
7.1 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Cross-Site Scripting No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-81288 Patchstack
8.8 High WP User Frontend Plugin wp-user-frontend PHP Object Injection ≤ 4.3.10 Fixed in 4.3.11 CVE-2026-81283 Patchstack
7.1 High Login With Ajax Plugin login-with-ajax Cross-Site Scripting No login needed ≤ 4.5.1 CVE-2026-82883 Patchstack
7.1 High WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting No login needed ≤ 7.8.2 Fixed in 7.9.0 CVE-2026-82229 Patchstack
8.1 High SiteGround Security Plugin sg-security Authentication Bypass WordPress SiteGround Security plugin <= 1.6.6 - 2FA Bypass No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-82228 Patchstack
7.4 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82225 Patchstack
7.1 High SliceWP Plugin slicewp Cross-Site Scripting No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2026-82224 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 6.0.9.8 Fixed in 6.0.9.9 CVE-2026-82221 Patchstack
7.1 High Super Store Finder Plugin superstorefinder-wp Cross-Site Scripting No login needed ≤ 7.10 Fixed in 7.11 CVE-2026-81768 Patchstack
7.1 High Tailored Tools Plugin tailored-tools Cross-Site Scripting No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2026-81765 Patchstack
7.1 High Email Essentials Plugin email-essentials Cross-Site Scripting No login needed ≤ 6.0.6 Fixed in 6.0.7 CVE-2026-81764 Patchstack
7.1 High LeadConnector Plugin leadconnector Cross-Site Scripting No login needed ≤ 4.0.5 Fixed in 4.0.6 CVE-2026-81298 Patchstack
7.5 High Fluent Forms Pro Add On Pack Plugin fluentformpro Privilege Escalation ≤ 6.2.12 Fixed in 6.2.13 CVE-2026-81297 Patchstack
7.5 High Fluent Forms Pro Add On Pack Plugin fluentformpro Broken Access Control No login needed ≤ 6.2.12 Fixed in 6.2.13 CVE-2026-81296 Patchstack
7.1 High Uncode Theme uncode Cross-Site Scripting No login needed ≤ 2.12.7 Fixed in 2.12.8 CVE-2026-81291 Patchstack
7.1 High Email Subscribers & Newsletters Plugin email-subscribers Cross-Site Scripting No login needed ≤ 5.9.33 Fixed in 5.9.34 CVE-2026-81290 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only