WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 201–250 of 1,023 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 21
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 6.3.1 Fixed in 6.5.0 CVE-2026-22350 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.29.0 Fixed in 3.29.1 CVE-2024-50555 Patchstack
6.5 Medium Fusion Builder Plugin fusion-builder Cross-Site Scripting ≤ 3.14.1 Fixed in 3.14.2 CVE-2026-25472 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.6.9 Fixed in 5.7.0 CVE-2026-25451 Patchstack
5.3 Medium Popup Builder - Create highly converting, mobile friendly marketing popups. Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed ≤ 4.4.2 CVE-2025-13079 Wordfence
4.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' ≤ 6.4.7 CVE-2026-2386 Wordfence
5.3 Medium RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment No login needed ≤ 6.0.6.9 CVE-2025-14444 Wordfence
4.3 Medium Taskbuilder Plugin taskbuilder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation ≤ 5.0.2 CVE-2026-1640 Wordfence
6.5 Medium Taskbuilder Plugin taskbuilder SQL Injection Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters ≤ 5.0.2 CVE-2026-1639 Wordfence
4.4 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Scripting Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.50.2 CVE-2026-2002 Wordfence
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control Subscriber+ Form Creation < 6.0.7.2 Fixed in 6.0.7.2 CVE-2026-0929 WPScan
5.3 Medium Easy Form Builder Plugin easy-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Form Response Data Exposure No login needed ≤ 3.9.3 CVE-2025-14067 Wordfence
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Information Disclosure Subscriber+ Sensitive Data Disclosure < 6.0.7.2 Fixed in 6.0.7.2 CVE-2025-15520 WPScan
6.4 Medium Beaver Builder Page Builder – Drag and Drop Website Builder Plugin beaver-builder-lite-version Broken Access Control Drag and Drop Website Builder <= 2.10.0.5 - Authenticated (Custom+) Missing Authorization to Stored Cross-Site Scripting via Global Settings ≤ 2.10.0.5 CVE-2026-1231 Wordfence
5.4 Medium PopupKit Plugin popup-builder-block Broken Access Control Missing Authorization to Sensitive Information Disclosure and Data Deletion ≤ 2.2.0 CVE-2025-14895 Wordfence
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module ≤ 6.1.14 CVE-2026-0996 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Author+) Stored DOM-based Cross-Site Scripting in Post Grid ≤ 5.5.3 CVE-2025-13463 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.4.8 CVE-2025-12159 Wordfence
6.4 Medium Bold Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_tabs Shortcode ≤ 5.5.1 CVE-2025-12803 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_accordion_item Shortcode ≤ 5.6.1 CVE-2025-15267 Wordfence
5.4 Medium GreenShift - Animation and Page Builder Blocks Plugin greenshift-animation-and-page-builder-blocks Broken Access Control Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css ≤ 12.6 CVE-2026-1927 Wordfence
5.3 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 9.1.8 CVE-2025-15510 Wordfence
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.14 CVE-2025-14283 Wordfence
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary Settings Modification No login needed ≤ 6.0.7.4 CVE-2026-1054 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed ≤ 2.5.2 CVE-2025-13205 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed ≤ 2.5.2 CVE-2025-13139 Wordfence
5.9 Medium Landing Page Builder Plugin page-builder-add Cross-Site Scripting ≤ 1.5.3.4 Fixed in 1.5.3.5 CVE-2026-24620 Patchstack
5.9 Medium Livemesh Addons for WPBakery Page Builder Plugin addons-for-visual-composer Cross-Site Scripting ≤ 3.9.4 CVE-2026-24594 Patchstack
6.4 Medium Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Cross-Site Scripting Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.10.0.2 CVE-2025-15522 Wordfence
5.4 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 6.0.6.9 Fixed in 6.0.7.0 CVE-2026-24374 Patchstack
4.3 Medium Easy Form Builder Plugin easy-form-builder Broken Access Control ≤ 3.9.6 Fixed in 4.0.0 CVE-2026-22472 Patchstack
6.5 Medium BM Content Builder Plugin bm-builder Path Traversal Arbitrary File Download ≤ 3.16.3.3 Fixed in 3.16.3.3 CVE-2025-69055 Patchstack
6.5 Medium Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-68046 Patchstack
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Missing Authorization to Unauthenticated Payment Status Bypass No login needed ≤ 3.6.9 CVE-2025-14757 Wordfence
6.4 Medium SpiceForms Form Builder Plugin spiceforms-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0 CVE-2025-12178 Wordfence
4.4 Medium Internal Link Builder Plugin internal-link-builder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Settings ≤ 1.0 CVE-2025-14725 Wordfence
6.4 Medium ConvertForce Popup Builder Plugin convertforce-popup-builder Cross-Site Scripting Stored Cross-Site Scripting via entrance_animation ≤ 0.0.7 CVE-2025-14506 Wordfence
4.3 Medium WP Table Builder Plugin wp-table-builder Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table Creation ≤ 2.0.19 CVE-2025-13753 Wordfence
5.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export ≤ 1.49.1 CVE-2025-14782 Wordfence
6.8 Medium Nex-Forms Express WP Form Builder Plugin Cross-Site Scripting Authenticated Stored XSS < 9.1.8 Fixed in 9.1.8 CVE-2025-14803 WPScan
5.3 Medium Dashboard Welcome for Beaver Builder Plugin dashboard-welcome-for-beaver-builder Broken Access Control No login needed ≤ 1.0.8 CVE-2026-22488 Patchstack
5.3 Medium Fluent Forms Plugin fluentform Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder No login needed ≤ 6.1.7 CVE-2025-13722 Wordfence
4.4 Medium Email Customizer for WooCommerce | Drag and Drop Email Templates Builder Plugin email-customizer-for-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Email Template Content ≤ 2.6.7 CVE-2025-13974 Wordfence
6.4 Medium Stylish Order Form Builder Plugin stylish-order-form-builder Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'product_name' Parameter ≤ 1.0 CVE-2025-13531 Wordfence
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Broken Access Control ≤ 1.27.9 Fixed in 1.27.10 CVE-2025-69345 Patchstack
4.3 Medium Popupkit Plugin popup-builder-block Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data Deletion ≤ 2.2.0 CVE-2025-14441 Wordfence
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.3.3 Fixed in 5.3.4 CVE-2024-23511 Patchstack
6.1 Medium Shopbuilder Plugin shopbuilder Cross-Site Scripting Reflected XSS No login needed < 3.2.2 Fixed in 3.2.2 CVE-2025-13456 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only