WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 201–250 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High EscortWP Theme Other Content Deletion via Vendor-Authored Backdoor No login needed ≤ 3.6.2 CVE-2026-12685 WPScan
8.1 High WCFM - WooCommerce Multivendor Membership Plugin wc-multivendor-membership Broken Access Control WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite ≤ 2.11.10 CVE-2026-3688 Wordfence
9.8 Critical Uncanny Automator Pro Plugin Other Backdoor via Compromised Vendor Update Server No login needed 7.3.0.5 – < 7.3.0.6 Fixed in 7.3.0.6 CVE-2026-12375 WPScan
6.5 Medium Kirki Plugin kirki Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.11 Fixed in 6.0.12 CVE-2026-57680 Patchstack
2.7 Low Fluent Forms Plugin fluentform Broken Access Control Form Manager+ Cross-Form Submission Entry Deletion via IDOR < 6.2.5 Fixed in 6.2.5 CVE-2026-11578 WPScan
8.8 High Dokan Pro Plugin Privilege Escalation Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint ≤ 5.0.4 CVE-2026-12224 Wordfence
3.1 Low Fluent Forms Plugin fluentform Broken Access Control Subscriber+ Subscription Cancellation via IDOR < 6.2.1 Fixed in 6.2.1 CVE-2026-11880 WPScan
6.5 Medium Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.9.0 Fixed in 2.10.0 CVE-2026-57341 Patchstack
4.3 Medium Simple User Avatar Plugin simple-user-avatar Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.9 Fixed in 5.0 CVE-2026-57676 Patchstack
6.4 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Cross-Site Scripting Authenticated (Custom+) Stored Cross-Site Scripting via Product SKU ≤ 5.0.4 CVE-2026-11783 Wordfence
4.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter ≤ 5.0.4 CVE-2026-11987 Wordfence
8.1 High ProfilePress Plugin Broken Access Control Subscriber+ Subscription Cancellation via IDOR < 4.16.17 Fixed in 4.16.17 CVE-2026-10820 WPScan
5.3 Medium GravityView Plugin gravityview Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.0 Fixed in 3.0.1 CVE-2026-57665 Patchstack
5.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-57652 Patchstack
5.4 Medium Majestic Support Plugin majestic-support Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-57646 Patchstack
4.3 Medium PPWP Plugin password-protect-page Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.9.19 Fixed in 1.9.20 CVE-2026-57634 Patchstack
5.3 Medium Blocksy Companion Pro Plugin blocksy-companion-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.1.46 Fixed in 2.1.47 CVE-2026-57630 Patchstack
7.5 High Toolset Forms Plugin cred-frontend-editor Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.6.24 Fixed in 2.6.25 CVE-2026-56069 Patchstack
6.5 Medium Payment Gateway Based Fees and Discounts for WooCommerce Plugin checkout-fees-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2026-56048 Patchstack
7.6 High SupportCandy Plugin supportcandy Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.4.6 Fixed in 3.4.7 CVE-2026-54826 Patchstack
5.3 Medium BookPro Plugin ovabookpro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.0 CVE-2025-66123 Patchstack
6.5 Medium License Manager for WooCommerce Plugin license-manager-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.15 Fixed in 3.0.16 CVE-2026-56013 Patchstack
8.5 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.6.8 Fixed in 2.6.9 CVE-2026-54838 Patchstack
7.5 High ShapedPlugin Multiple Pro Plugins Plugin Information Disclosure Backdoor via Compromised Vendor Update Server No login needed 4.0.1 – < 4.0.2, 3.2.4 – < 3.2.5, 3.5.2 – < 3.5.3 Fixed in 4.0.2 CVE-2026-10735 WPScan
4.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers ≤ 5.0.3 CVE-2026-10023 Wordfence
5.3 Medium School Management Plugin school-management Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 93.1.0 CVE-2025-15657 Patchstack
8.2 High Clean Login Plugin clean-login Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.15 Fixed in 1.16 CVE-2026-54184 Patchstack
7.3 High Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 10.30.24 Fixed in 10.30.25 CVE-2026-40768 Patchstack
7.5 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset ≤ 5.5.1 CVE-2026-8176 Wordfence
7.5 High VikRentCar Plugin vikrentcar Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-52699 Patchstack
7.5 High Simple Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.2.9 Fixed in 5.3.0 CVE-2026-48868 Patchstack
6.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.2.1 Fixed in 4.3.0 CVE-2026-40792 Patchstack
7.1 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.3.0.0 Fixed in 4.3.0.1 CVE-2026-39518 Patchstack
7.5 High Projectopia Plugin projectopia-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.25.2 CVE-2025-59133 Patchstack
4.3 Medium BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Friends List IDOR via REST API ≤ 14.4.0 CVE-2026-53675 VulnCheck
8.1 High BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter ≤ 14.4.0 CVE-2026-53673 VulnCheck
7.3 High WCFM Membership Plugin wc-multivendor-membership Broken Access Control No login needed ≤ 2.11.10 Fixed in 2.11.11 CVE-2026-42753 Patchstack
7.5 High BP Better Messages Plugin bp-better-messages Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.14.16 Fixed in 2.15.0 CVE-2026-42736 Patchstack
6.5 Medium Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-42725 Patchstack
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.12.0 Fixed in 4.13.0 CVE-2026-27329 Patchstack
6.5 Medium Frontend File Manager Plugin Broken Access Control Subscriber+ Arbitrary Download Access via IDOR ≤ 23.6 CVE-2026-5337 WPScan
5.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Information Disclosure Unauthenticated Information Disclosure in Store Reviews REST API Endpoint No login needed ≤ 4.3.1 CVE-2026-3504 Wordfence
8.1 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion ≤ 6.7.25 CVE-2026-2554 Wordfence
8.8 High my-calendar Plugin Information Disclosure My Calendar: Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog No login needed < 3.7.7 CVE-2026-40308 GitHub_M
7.6 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection ≤ 3.7.1 CVE-2025-63029 Patchstack
8.1 High FluentBoards Plugin fluent-boards Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.91.2 Fixed in 1.91.3 CVE-2026-40784 Patchstack
5.3 Medium COMPE Plugin compe-woo-compare-products Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-40737 Patchstack
8.8 High BuddyPress Groupblog Plugin bp-groupblog Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOR ≤ 1.9.3 CVE-2026-5144 Wordfence
6.5 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Unauthenticated Arbitrary Wishlist Renaming via IDOR No login needed < 4.13.0 Fixed in 4.13.0 CVE-2026-4432 WPScan
5.3 Medium Download Attachments Plugin download-attachments Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.4.0 CVE-2026-39616 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only