WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 201–250 of 1,407 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Broken Access Control Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation |
≤ 1.22.0 |
CVE-2026-8848 |
Wordfence | |
| 8.8 High | Divi Form Builder | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form |
≤ 5.1.8 |
CVE-2026-5523 |
Wordfence | |
| 6.4 Medium | Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode | Cross-Site Scripting Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode |
≤ 6.20.2 |
CVE-2025-14785 |
Wordfence | |
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter No login needed |
≤ 9.2.2 |
CVE-2026-13040 |
Wordfence | |
| 9.8 Critical | Divi Form Builder | Arbitrary File Upload Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter No login needed |
≤ 5.1.8 |
CVE-2026-5524 |
Wordfence | |
| 6.5 Medium | Livemesh Addons for WPBakery Page Builder | Cross-Site Scripting |
≤ 3.9.4 |
CVE-2026-57754 |
Patchstack | |
| 7.1 High | Internal Links Manager | Cross-Site Scripting No login needed |
≤ 3.0.3 Fixed in 3.0.4 |
CVE-2026-57345 |
Patchstack | |
| 5.3 Medium | JetFormBuilder | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter No login needed |
≤ 3.6.3 |
CVE-2026-13459 |
Wordfence | |
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter No login needed |
≤ 9.2.2 |
CVE-2026-12142 |
Wordfence | |
| 8.8 High | RegistrationMagic | Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter |
≤ 6.0.9.1 |
CVE-2026-12158 |
Wordfence | |
| 6.5 Medium | Taskbuilder | SQL Injection Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter |
≤ 5.0.8 |
CVE-2026-12090 |
Wordfence | |
| 6.5 Medium | Taskbuilder | SQL Injection Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter |
≤ 5.0.8 |
CVE-2026-12110 |
Wordfence | |
| 7.1 High | Landing Page Builder | Cross-Site Scripting No login needed |
≤ 1.5.3.5 Fixed in 1.5.3.6 |
CVE-2026-57337 |
Patchstack | |
| 6.4 Medium | Page Builder by SiteOrigin | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via panels_data Parameter |
≤ 2.34.3 |
CVE-2026-13295 |
Wordfence | |
| 5.3 Medium | RegistrationMagic | Authentication Bypass Authenticated (Subscriber+) Authentication Bypass via Forged PayPal IPN Request No login needed |
≤ 6.0.8.6 |
CVE-2026-9242 |
Wordfence | |
| 5.3 Medium | NEX-Forms | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via CSVExport Class No login needed |
≤ 9.2.2 |
CVE-2026-12404 |
Wordfence | |
| 4.3 Medium | Bopo – WooCommerce Product Bundle Builder | Information Disclosure WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure |
≤ 1.1.6 Fixed in 1.2.0 |
CVE-2026-57664 |
Patchstack | |
| 8.8 High | Fusion Builder | Privilege Escalation |
≤ 3.15.4 Fixed in 3.15.5 |
CVE-2026-56008 |
Patchstack | |
| 6.5 Medium | Elementor Website Builder | Information Disclosure Sensitive Data Exposure |
≤ 4.1.3 Fixed in 4.1.4 |
CVE-2026-57619 |
Patchstack | |
| 6.4 Medium | Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns | Cross-Site Scripting Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute |
≤ 6.1.4 |
CVE-2026-10833 |
Wordfence | |
| 7.6 High | Funnel Builder by FunnelKit | SQL Injection |
≤ 3.15.0.5 Fixed in 3.15.0.6 |
CVE-2026-56052 |
Patchstack | |
| 9.1 Critical | Avada (Fusion) Builder | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Form Entry Value No login needed |
≤ 3.15.3 |
CVE-2026-8713 |
Wordfence | |
| 5.9 Medium | Bricksable for Bricks Builder | Cross-Site Scripting |
≤ 1.6.83 Fixed in 1.6.84 |
CVE-2026-56009 |
Patchstack | |
| 7.7 High | Fusion Builder | Arbitrary File Deletion |
≤ 3.15.4 Fixed in 3.15.5 |
CVE-2026-54193 |
Patchstack | |
| 6.8 Medium | JetFormBuilder | Privilege Escalation |
≤ 3.6.1 Fixed in 3.6.1.1 |
CVE-2026-54196 |
Patchstack | |
| 7.1 High | JetFormBuilder | Cross-Site Scripting No login needed |
≤ 3.6.0.1 Fixed in 3.6.1 |
CVE-2026-54195 |
Patchstack | |
| 6.5 Medium | WPBakery Page Builder | Broken Access Control |
≤ 8.7.2 Fixed in 8.7.3 |
CVE-2026-45436 |
Patchstack | |
| 7.1 High | Profile Builder Pro | Cross-Site Scripting No login needed |
≤ 3.15.0 Fixed in 3.15.1 |
CVE-2026-42385 |
Patchstack | |
| 4.3 Medium | Bricks Builder | Broken Access Control |
≤ 2.1.4 Fixed in 2.2 |
CVE-2026-40723 |
Patchstack | |
| 7.1 High | Taskbuilder | Cross-Site Scripting Reflected XSS via Shortcode No login needed |
< 5.0.8 Fixed in 5.0.8 |
CVE-2026-9570 |
WPScan | |
| 8.8 High | Fusion Builder | PHP Object Injection |
≤ 3.15.3 Fixed in 3.15.4 |
CVE-2026-12256 |
Patchstack | |
| 9.8 Critical | Fusion Builder | PHP Object Injection No login needed |
≤ 3.15.4 Fixed in 3.15.5 |
CVE-2026-54194 |
Patchstack | |
| 8.5 High | Taskbuilder | SQL Injection |
≤ 5.0.7 Fixed in 5.0.8 |
CVE-2026-52697 |
Patchstack | |
| 9.8 Critical | RegistrationMagic | Authentication Bypass Broken Authentication No login needed |
≤ 6.0.8.6 Fixed in 6.0.8.7 |
CVE-2026-49764 |
Patchstack | |
| 7.1 High | Funnel Builder by FunnelKit | Cross-Site Scripting No login needed |
≤ 3.15.0.2 Fixed in 3.15.0.3 |
CVE-2026-48966 |
Patchstack | |
| 9.3 Critical | Funnel Builder by FunnelKit | SQL Injection No login needed |
≤ 3.15.0.1 Fixed in 3.15.0.2 |
CVE-2026-42381 |
Patchstack | |
| 8.6 High | Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field | Arbitrary File Upload Save Entries, File Upload & Country Code Field plugin <= 1.0.6 - Arbitrary File Deletion No login needed |
≤ 1.0.6 Fixed in 1.0.7 |
CVE-2026-40769 |
Patchstack | |
| 10.0 Critical | WooCommerce PDF Invoice Builder | Remote Code Execution No login needed |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2026-52704 |
Patchstack | |
| 5.4 Medium | Form Builder CP | Cross-Site Scripting Editor+ Stored XSS via form_structure |
< 1.2.47 Fixed in 1.2.47 |
CVE-2026-9278 |
WPScan | |
| 6.4 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Scripting Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block |
≤ 2.0.9 |
CVE-2026-3297 |
Wordfence | |
| 5.4 Medium | Contact Form & Lead Form Elementor Builder | Broken Access Control No login needed |
≤ 1.8.4 Fixed in 1.8.5 |
CVE-2023-25969 |
Patchstack | |
| 7.2 High | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Server-Side Request Forgery Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery No login needed |
≤ 6.1.3 |
CVE-2026-10586 |
Wordfence | |
| 5.4 Medium | Popup Builder | Cross-Site Scripting WordPress Popup Builder 3.49 Persistent Cross-Site Scripting |
3.49 |
CVE-2019-25744 |
VulnCheck | |
| 8.8 High | Content Visibility for Divi Builder | Remote Code Execution Authenticated (Contributor+) Remote Code Execution |
≤ 4.02 |
CVE-2026-1829 |
Wordfence | |
| 5.4 Medium | Elementor Website Builder | Broken Access Control |
≤ 4.1.0 Fixed in 4.1.1 |
CVE-2026-49782 |
Patchstack | |
| 6.4 Medium | The Plus Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'carousel_direction' Parameter |
≤ 6.4.15 |
CVE-2026-9243 |
Wordfence | |
| 4.3 Medium | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder | Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending |
≤ 3.4.7 |
CVE-2026-4888 |
Wordfence | |
| 9.3 Critical | Easy Form Builder | SQL Injection No login needed |
≤ 4.0.6 Fixed in 4.0.7 |
CVE-2026-42747 |
Patchstack | |
| 6.4 Medium | WPBakery Page Builder Addons by Livemesh | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.9.4 |
CVE-2026-3895 |
Wordfence | |
| 6.4 Medium | WPBakery Page Builder Addons by Livemesh | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 3.9.4 |
CVE-2026-2030 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.