WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WPFunnels Plugin wpfunnels Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.13.1 Fixed in 3.13.2 CVE-2026-27371 Patchstack
7.5 High Product Designer App Plugin product-designer-app Path Traversal Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design No login needed ≤ 1.1.3 CVE-2026-75098 Wordfence
7.2 High Post Views Stats Counter Plugin post-views-stats-counter Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via User-Agent Header No login needed ≤ 1.1.7 CVE-2026-97347 Wordfence
7.5 High Motors Plugin motors-car-dealership-classified-listings SQL Injection Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_lng' Parameters No login needed ≤ 1.4.109 CVE-2026-6806 Wordfence
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Local File Inclusion Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter ≤ 1.6.12.27 CVE-2026-89294 Wordfence
8.8 High Verge3D Plugin Cross-Site Scripting Unauthenticated Stored XSS via File Storage API No login needed < 4.13.1 Fixed in 4.13.1 CVE-2026-92994 WPScan
7.1 High WP Mobile Menu Plugin mobile-menu Cross-Site Scripting Stored XSS via CSRF No login needed 2.7.4 – < 2.9 Fixed in 2.9 CVE-2026-91832 WPScan
7.5 High Robin Image Optimizer Plugin robin-image-optimizer Cross-Site Scripting Unauthenticated Stored XSS via WebP URL Delivery HTML Parser No login needed 2.0.0 – < 2.0.8 Fixed in 2.0.8 CVE-2026-89193 WPScan
7.1 High Vayu X Theme vayu-x Broken Access Control Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation < 1.0.6 Fixed in 1.0.6 CVE-2026-88797 WPScan
8.8 High All in One Files Upload for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG Upload No login needed 2.0.3 – < 2.0.17 Fixed in 2.0.17 CVE-2026-85573 WPScan
7.4 High WP User Frontend Plugin Privilege Escalation Unauthenticated Privilege Escalation via Registration Role Encryption No login needed 3.5.29 – < 4.3.12 Fixed in 4.3.12 CVE-2026-75823 WPScan
7.2 High Frontend Post Submission Manager Lite Plugin frontend-post-submission-manager-lite Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) No login needed ≤ 1.3.4 CVE-2026-96649 Wordfence
7.2 High HT Contact Form – Drag & Drop Form Builder Plugin ht-contactform Cross-Site Scripting Drag & Drop Form Builder for WordPress <= 2.10.2 Unauthenticated Stored Cross-Site Scripting via Rich Text Editor Field No login needed ≤ 2.10.2 CVE-2026-96326 Wordfence
8.8 High ConvertPlus Plugin PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via 'style' Parameter ≤ 3.6.3 CVE-2026-87741 Wordfence
7.2 High Malcure Malware Shield Plugin Remote Code Execution Multisite Subsite Admin+ Arbitrary File Write and Deletion via wpmr_ajax_request < 19.9.7 Fixed in 19.9.7 CVE-2026-96896 WPScan
8.8 High Download Manager Pro Plugin Cross-Site Scripting Unauthenticated Stored XSS via Email Lock Subscription No login needed 4.0.0 – < 7.5.6 Fixed in 7.5.6 CVE-2026-86609 WPScan
7.5 High Ad Inserter Plugin ad-inserter Remote Code Execution Subscriber+ RCE / Stored XSS via Global Custom Fields 2.8.12 – < 2.8.19 Fixed in 2.8.19 CVE-2026-81655 WPScan
8.8 High Groups Plugin groups Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'groups_join' Shortcode ≤ 4.6.0 CVE-2026-77203 Wordfence
7.5 High Testimonials Widget Plugin Broken Access Control Unauthenticated Arbitrary Post Update No login needed ≤ 4.0.4 CVE-2026-96532 WPScan
8.8 High MCP Server Plugin Cross-Site Request Forgery Administrator Account Creation via CSRF No login needed < 1.8.2 Fixed in 1.8.2 CVE-2026-96524 WPScan
7.5 High Multiple elFinder Plugins Plugin Cross-Site Scripting DOM-based XSS via postMessage Origin Bypass No login needed < 8.0.5, < 1.2.1, < 2.1.3 Fixed in 8.0.5 CVE-2026-85081 WPScan
8.0 High WP Review Slider Pro Plugin Cross-Site Scripting Subscriber+ Stored XSS via Review Form Fields < 12.7.12 Fixed in 12.7.12 CVE-2026-84096 WPScan
8.0 High WP Review Slider Pro Plugin Cross-Site Scripting Subscriber+ Stored XSS via Review Import < 12.7.12 Fixed in 12.7.12 CVE-2026-84095 WPScan
7.2 High WP Directory Kit Plugin wpdirectorykit Cross-Site Scripting Listing Admin+ Stored XSS via Category and Location Title and Icon Fields < 1.5.8 Fixed in 1.5.8 CVE-2026-16591 WPScan
7.2 High Themify Builder Plugin themify-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'css[fonts]' Parameter No login needed ≤ 7.8.1 CVE-2026-95864 Wordfence
7.2 High Repeater Fields for Elementor Forms Plugin repeater-for-elementor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Repeater Field Value No login needed ≤ 2.2.7 CVE-2026-94573 Wordfence
8.8 High Knit Pay Plugin knit-pay Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Gravity Forms Role Field ≤ 9.6.1.0 CVE-2026-89426 Wordfence
8.8 High s2Member Plugin s2member Remote Code Execution Unauthenticated Remote Code Execution via 'first_name' Parameter in PayPal Proxy Return ≤ 260814 CVE-2026-19804 Wordfence
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Shortcode Order 'elements[].title' Parameter No login needed ≤ 6.5.2 CVE-2026-84280 Wordfence
7.3 High Optima Express IDX Plugin optima-express Privilege Escalation Unauthenticated Privilege Escalation to 'ihf_clear_cache' AJAX Action to Author Role Assignment No login needed ≤ 8.7.5 CVE-2026-93901 Wordfence
7.5 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters No login needed ≤ 3.0.1 CVE-2026-89406 Wordfence
7.2 High Restaurant Menu and Food Ordering Plugin mp-restaurant-menu Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'phone_number' Parameter No login needed ≤ 2.4.14 CVE-2026-96568 Wordfence
7.2 High User Profile Builder Plugin profile-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Avatar Field No login needed ≤ 4.0.2 CVE-2026-95866 Wordfence
7.5 High WP Maps Plugin wp-google-map-plugin Local File Inclusion Authenticated (Subscriber+) Local File Inclusion via 'page' Parameter ≤ 4.9.8 CVE-2026-13456 Wordfence
7.2 High Premium Packages Plugin wpdm-premium-packages Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'cart_items[][product_name]' Parameter No login needed ≤ 7.2.1 CVE-2026-93654 Wordfence
8.1 High Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter ≤ 3.0.2 CVE-2026-92713 Wordfence
7.2 High Zero Spam Plugin zero-spam Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Nested POST Array Keys via Contact Form 7 Integration No login needed ≤ 5.7.10 CVE-2026-96752 Wordfence
7.2 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via first_name Parameter No login needed ≤ 1.8.27 CVE-2026-96039 Wordfence
7.2 High HT Contact Form Plugin ht-contactform Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume No login needed ≤ 2.10.1 CVE-2026-93303 Wordfence
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'output_format' Parameter via Pro Export Print Job No login needed ≤ 6.5.2 CVE-2026-84279 Wordfence
7.2 High Fancy Product Designer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta No login needed ≤ 6.5.2 CVE-2026-84281 Wordfence
7.2 High AMP for WP Plugin accelerated-mobile-pages Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content Regex Transformation No login needed ≤ 1.1.16 CVE-2026-83591 Wordfence
8.8 High Elementor Website Builder Plugin elementor Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-62062 Patchstack
8.8 High YOP Poll Plugin yop-poll Privilege Escalation Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route No login needed ≤ 7.0.10 CVE-2026-85682 Wordfence
7.5 High eesy_ID2WP – Publish InDesign HTML5 Plugin Path Traversal Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query Parameter No login needed ≤ 1.0.3 CVE-2026-77193 Wordfence
7.2 High MasterStudy LMS 3.5.29 Plugin Local File Inclusion < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget 3.5.29 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88843 WPScan
7.5 High wpForo Forum Plugin wpforo PHP Object Injection Subscriber+ PHP Object Injection via Profile Fields < 3.1.6 Fixed in 3.1.6 CVE-2026-80513 WPScan
8.8 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via CSV Escape-Character Mismatch in Export/Import Round Trip via display_name and nickname Profile Fields ≤ 2.4.17 CVE-2026-86583 Wordfence
8.1 High EthPress Plugin ethpress Authentication Bypass Unauthenticated Authentication Bypass No login needed ≤ 2.3.5 CVE-2026-19125 Wordfence
7.6 High W4 Post List Plugin w4-post-list SQL Injection ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-96826 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only