WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Cwicly Plugin cwicly Remote Code Execution ≤ 1.4.4 CVE-2026-32444 Patchstack
9.6 Critical Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Arbitrary File Upload No login needed ≤ 7.1.67 CVE-2026-28192 Patchstack
9.8 Critical Forminator Forms Plugin forminator Arbitrary File Upload Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration No login needed ≤ 1.56.1 CVE-2026-15748 Wordfence
9.8 Critical Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder PHP Object Injection ARForms <= 1.8.5 - Unauthenticated PHP Object Injection No login needed ≤ 1.8.5 CVE-2024-13784 Wordfence
9.1 Critical WPvivid Backup & Migration Plugin Path Traversal Unauthenticated Path Traversal via send_to_site_connect No login needed < 0.9.131 Fixed in 0.9.131 CVE-2026-19725 WPScan
9.1 Critical Simple JWT Login Plugin simple-jwt-login Privilege Escalation Unauthenticated Account Takeover via Missing Google id_token Audience Validation No login needed < 3.6.8 Fixed in 3.6.8 CVE-2026-19714 WPScan
9.1 Critical Solace Extra Plugin solace-extra Broken Access Control Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action No login needed ≤ 1.6.0 CVE-2026-18316 Wordfence
9.1 Critical ProSolution WP Client Plugin prosolution-wp-client Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters No login needed ≤ 2.0.8 CVE-2026-14524 Wordfence
9.8 Critical ProSolution WP Client Plugin prosolution-wp-client Arbitrary File Upload Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override No login needed ≤ 2.0.10 CVE-2026-16098 Wordfence
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation via 'item_id' Parameter No login needed ≤ 3.29.9 CVE-2026-18432 Wordfence
9.1 Critical Link Library Plugin link-library Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via link_url Parameter No login needed ≤ 7.9.4 CVE-2026-18855 Wordfence
9.8 Critical Pods Plugin pods Privilege Escalation Unauthenticated Privilege Escalation via Authorization Bypass to Admin Methods via 'pods_admin' AJAX Router No login needed 2.8 – 2.8.23.3, 2.9 – 2.9.19.3, 3.0 – 3.0.10.3, … CVE-2026-19598 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Privilege Escalation Unauthenticated Account Takeover via Insecure Direct Object Reference in 'truebooker_wp_user_id' Parameter No login needed ≤ 1.2.6 CVE-2026-16142 Wordfence
9.8 Critical User Profile Builder Plugin profile-builder Authentication Bypass Unauthenticated Authentication Bypass via Type Confusion to Administrator Account Takeover via 'username' Parameter No login needed ≤ 3.16.4 CVE-2026-15826 Wordfence
9.8 Critical User Session Synchronizer Plugin user-session-synchronizer Authentication Bypass Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters No login needed ≤ 1.4.0 CVE-2026-15341 Wordfence
9.8 Critical 6Storage Rentals Plugin 6storage-rentals Privilege Escalation Unauthenticated Account Takeover via 'email' Parameter No login needed ≤ 2.27.0 CVE-2026-15303 Wordfence
9.1 Critical RapiSafe Plugin rapisafe-multi-file-cf7 Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'rsmfcf7_session' and 'file_name' Parameters No login needed ≤ 1.0.4 CVE-2026-14484 Wordfence
9.8 Critical Wishlist Member X Plugin Privilege Escalation Unauthenticated Account Takeover via 'mergewith' Parameter No login needed ≤ 3.34.1 CVE-2026-12949 Wordfence
9.8 Critical Fluent Forms Pro Plugin fluentformpro Other Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build No login needed 6.2.7 CVE-2026-73532 VulnCheck
9.8 Critical Ninja Tables Pro Plugin ninja-tables Other Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build No login needed 5.2.11 CVE-2026-73533 VulnCheck
9.8 Critical Nokri Theme nokri Broken Access Control No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2026-66691 Patchstack
9.3 Critical Church Admin Plugin church-admin SQL Injection No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-66478 Patchstack
9.3 Critical Everest Backup Plugin everest-backup SQL Injection No login needed ≤ 2.3.12 CVE-2026-66472 Patchstack
9.8 Critical Cartify Theme cartify-multipurpose-woocommerce-wordpress-theme Privilege Escalation Account Takeover No login needed ≤ 1.3.0.1 CVE-2026-66465 Patchstack
9.3 Critical RealPress Plugin realpress SQL Injection No login needed ≤ 1.1.2 CVE-2026-66458 Patchstack
9.8 Critical Salon booking system Plugin salon-booking-system Authentication Bypass Broken Authentication No login needed ≤ 10.30.26 Fixed in 10.30.27 CVE-2026-66453 Patchstack
9.3 Critical If-So Dynamic Content Personalization Plugin if-so SQL Injection No login needed ≤ 1.10 Fixed in 1.10.0.1 CVE-2026-66446 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.1.1 Fixed in 2.1.2 CVE-2026-66436 Patchstack
9.8 Critical SMS Alert Order Notifications Plugin sms-alert Privilege Escalation No login needed ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-66424 Patchstack
9.3 Critical Listdom Plugin listdom SQL Injection No login needed ≤ 5.6.0 Fixed in 5.7.0 CVE-2026-61969 Patchstack
9.8 Critical miniorange otp verification Plugin miniorange-otp-verification Privilege Escalation No login needed ≤ 5.5.1 Fixed in 5.5.2 CVE-2026-61967 Patchstack
9.3 Critical WPJAM Basic Plugin wpjam-basic SQL Injection No login needed ≤ 7.0.1 Fixed in 7.0.2 CVE-2026-61966 Patchstack
10.0 Critical WP BASE Booking Plugin wp-base-booking-of-appointments-services-and-events Remote Code Execution Arbitrary Code Execution No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2026-61962 Patchstack
9.8 Critical Log in with Google Plugin login-with-google Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2026-28185 Patchstack
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on PHP Object Injection No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2026-28149 Patchstack
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on Other Bypass Vulnerability No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2026-28148 Patchstack
9.3 Critical Web Directory Free Plugin web-directory-free SQL Injection No login needed ≤ 1.7.13 Fixed in 2.0 CVE-2026-28142 Patchstack
9.8 Critical OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Authentication Bypass SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication No login needed ≤ 7.0.0 Fixed in 7.0.1 CVE-2026-28008 Patchstack
9.3 Critical WP Directory Kit Plugin wpdirectorykit SQL Injection No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2026-28001 Patchstack
10.0 Critical QA Analytics Plugin qa-heatmap-analytics Remote Code Execution No login needed ≤ 5.2.0.0 Fixed in 5.2.0.1 CVE-2026-27544 Patchstack
10.0 Critical Link Factory Plugin Other Backdoor No login needed Not stated CVE-2026-15413 WPScan
9.8 Critical Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Privilege Escalation Unauthenticated Account Takeover via Type-Juggling Authentication Bypass No login needed 2.4.0 – < 3.2.6 Fixed in 3.2.6 CVE-2026-14182 WPScan
9.3 Critical Tablesome Table Plugin tablesome SQL Injection No login needed ≤ 1.2.9 CVE-2026-66659 Patchstack
9.8 Critical WooCommerce Subscriptions Plugin Remote Code Execution Unauthenticated RCE via PHP Object Injection No login needed 4.7.0 – < 9.1.0 Fixed in 9.1.0 CVE-2026-18391 WPScan
9.8 Critical Events Manager Plugin events-manager Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed 7.1 – < 7.4.1 Fixed in 7.4.1 CVE-2026-18366 WPScan
9.1 Critical TeraWallet - Wallet for WooCommerce Plugin Broken Access Control Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up No login needed < 1.6.10 Fixed in 1.6.10 CVE-2026-16538 WPScan
9.8 Critical WPMU DEV Dashboard Plugin Remote Code Execution Remote Code Execution via Hub Install Action No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-16051 WPScan
9.8 Critical Gift Cards For WooCommerce Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 4.2.10 Fixed in 4.2.10 CVE-2026-15039 WPScan
9.8 Critical Formidable Digital Signatures Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Signature Field No login needed ≤ 3.0.6 CVE-2026-16230 Wordfence
9.8 Critical Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed 2.0.0 – < 2.0.2 Fixed in 2.0.2 CVE-2026-19089 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only