WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium bbPress Plugin bbpress Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.14 Fixed in 2.6.15 CVE-2026-62137 Patchstack
5.3 Medium Flexible Quantity – Measurement Price Calculator for WooCommerce Plugin flexible-quantity-measurement-price-calculator-for-woocommerce Broken Access Control Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control No login needed ≤ 2.3.21 Fixed in 2.3.22 CVE-2026-62136 Patchstack
5.3 Medium Booktics Plugin booktics Broken Access Control No login needed ≤ 1.0.24 Fixed in 1.0.25 CVE-2026-62135 Patchstack
4.3 Medium Starter Templates Plugin astra-sites Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.7.5 Fixed in 4.7.6 CVE-2026-62134 Patchstack
5.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-62133 Patchstack
5.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control LMS plugin <= 3.4.0 - Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62132 Patchstack
5.3 Medium Passster Plugin content-protector Broken Access Control No login needed ≤ 4.3.13 Fixed in 4.3.14 CVE-2026-62114 Patchstack
4.3 Medium Slim SEO Plugin slim-seo Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.10.0 Fixed in 4.10.1 CVE-2026-62113 Patchstack
6.5 Medium Simple Payment Plugin simple-payment Cross-Site Scripting ≤ 2.5.4 Fixed in 2.5.6 CVE-2026-62111 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.9.9 Fixed in 5.9.10 CVE-2026-62110 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 11.2.5 Fixed in 11.2.6 CVE-2026-62140 Patchstack
5.3 Medium Deposits and Partial Payments for WooCommerce Plugin advanced-partial-payment-or-deposit-for-woocommerce Broken Access Control No login needed ≤ 3.1.0 Fixed in 4.0.1 CVE-2026-27378 Patchstack
6.5 Medium Salon booking system Plugin salon-booking-system Broken Access Control No login needed ≤ 10.31.9 CVE-2026-81793 Patchstack
6.5 Medium EventON Plugin eventon-lite Cross-Site Scripting ≤ 2.5.7 CVE-2026-81791 Patchstack
6.3 Medium IMPress for IDX Broker Plugin idx-broker-platinum Broken Access Control ≤ 3.3.0 CVE-2026-81788 Patchstack
6.5 Medium IMPress for IDX Broker Plugin idx-broker-platinum Authentication Bypass Broken Authentication No login needed ≤ 3.3.0 CVE-2026-81787 Patchstack
6.5 Medium BuddyForms Plugin buddyforms Broken Access Control No login needed ≤ 2.9.0 CVE-2026-81785 Patchstack
6.5 Medium WP Docs Plugin wp-docs Cross-Site Scripting ≤ 2.3.1 CVE-2026-81782 Patchstack
6.5 Medium Youzify Plugin youzify Path Traversal Arbitrary File Download ≤ 1.3.7 CVE-2026-81275 Patchstack
6.5 Medium Robokassa payment gateway for Woocommerce Plugin robokassa Broken Access Control No login needed ≤ 1.8.9 CVE-2026-78536 Patchstack
5.6 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Authentication Bypass Captcha Bypass No login needed ≤ 1.42.1 Fixed in 1.42.3 CVE-2026-66674 Patchstack
6.5 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Content Injection No login needed ≤ 1.42.1 Fixed in 1.42.3 CVE-2026-66632 Patchstack
6.5 Medium Groundhogg Plugin groundhogg Path Traversal ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-85310 Patchstack
6.4 Medium Builderall Plugin builderall-cheetah-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Module 'attributes' Setting ≤ 3.0.2 CVE-2026-15820 Wordfence
4.3 Medium Builderall Plugin builderall-cheetah-for-wp Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter ≤ 3.0.2 CVE-2026-15823 Wordfence
6.4 Medium Builderall Plugin builderall-cheetah-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting ≤ 3.0.2 CVE-2026-15796 Wordfence
4.8 Medium Hustle Plugin wordpress-popup Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Success Message Placeholders No login needed 7.0.0.1 – < 7.8.14.2 Fixed in 7.8.14.2 CVE-2026-80440 WPScan
6.4 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'episode_contributor[..][..][comment]' Parameter ≤ 4.5.5 CVE-2026-75966 Wordfence
6.5 Medium WpEvently Plugin mage-eventpress Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.6.0 Fixed in 5.6.4 CVE-2026-81802 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Privilege Escalation No login needed ≤ 6.1.5 CVE-2026-81792 Patchstack
5.3 Medium JetPopup Plugin jet-popup Broken Access Control No login needed ≤ 2.0.20.2 Fixed in 2.0.20.3 CVE-2026-27347 Patchstack
6.5 Medium WoodMart Theme woodmart Cross-Site Scripting < 8.3.8 Fixed in 8.3.8 CVE-2026-27086 Patchstack
5.4 Medium WP Rentals Theme wprentals Broken Access Control Insecure Direct Object References (IDOR) < 3.16.0 Fixed in 3.16.0 CVE-2026-27432 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.60 Fixed in 2.1.70 CVE-2026-85311 Patchstack
5.3 Medium WCFM Membership Plugin wc-multivendor-membership Broken Access Control No login needed ≤ 2.11.11 Fixed in 2.12.0 CVE-2026-32480 Patchstack
5.4 Medium LearnPress Plugin learnpress Cross-Site Scripting LearnPress WordPress Plugin < 4.4.6 Stored XSS via Quiz Question Answer Titles < 4.4.6 Fixed in 4.4.6 CVE-2026-82024 VulnCheck
4.3 Medium LearnPress Plugin learnpress Broken Access Control LearnPress WordPress Plugin < 4.4.6 Broken Object-Level Authorization via Quiz Answer Insert < 4.4.6 Fixed in 4.4.6 CVE-2026-82023 VulnCheck
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control No login needed ≤ 2.0.17 Fixed in 2.0.18 CVE-2026-85304 Patchstack
5.3 Medium Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-85309 Patchstack
5.3 Medium SureForms Plugin sureforms Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.12.5 Fixed in 2.12.6 CVE-2026-85308 Patchstack
5.3 Medium KP Agent Ready Plugin kp-agent-ready Information Disclosure Sensitive Data Exposure No login needed < 1.2.08 Fixed in 1.2.08 CVE-2026-85307 Patchstack
6.5 Medium MountDev AI MCP Connector Plugin mountdev-ai-mcp-connector Broken Access Control ≤ 1.6.5 Fixed in 1.6.6 CVE-2026-85306 Patchstack
5.4 Medium SEOPress Plugin wp-seopress Server-Side Request Forgery ≤ 10.1 Fixed in 10.2 CVE-2026-85305 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2026-85303 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2026-85302 Patchstack
6.1 Medium WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.11 Fixed in 14.16.12 CVE-2026-84774 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84769 Patchstack
5.3 Medium BookIt Plugin bookit Other Bypass Vulnerability No login needed ≤ 2.6.0.3 Fixed in 2.6.0.4 CVE-2026-84767 Patchstack
5.9 Medium FluentBooking Pro Plugin fluent-booking-pro Authentication Bypass Bypass Vulnerability No login needed ≤ 2.2.1 Fixed in 2.3.0 CVE-2026-84766 Patchstack
5.3 Medium WP EasyPay Plugin wp-easy-pay Other Bypass Vulnerability No login needed ≤ 4.5.3 Fixed in 4.5.4 CVE-2026-84762 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only