WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 201–250 of 17,624 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium InPost for WooCommerce Plugin Broken Access Control Unauthenticated Order Status Forgery via Shipment Webhook No login needed 1.7.5 – < 1.9.8 Fixed in 1.9.8 CVE-2026-93580 WPScan
6.8 Medium Content Egg Plugin content-egg Cross-Site Scripting Contributor+ Stored XSS via Import Queue < 11.9.0 Fixed in 11.9.0 CVE-2026-92424 WPScan
4.4 Medium EWWW Image Optimizer Plugin ewww-image-optimizer Path Traversal Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler < 8.8.0 Fixed in 8.8.0 CVE-2026-91072 WPScan
6.6 Medium EWWW Image Optimizer Plugin ewww-image-optimizer PHP Object Injection Author+ PHP Object Injection via 'eio_page_settings' Post Meta 8.6.0 – < 8.8.0 Fixed in 8.8.0 CVE-2026-91051 WPScan
4.3 Medium Image Optimizer by Elementor Plugin Information Disclosure Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks < 1.7.7 Fixed in 1.7.7 CVE-2026-90953 WPScan
4.3 Medium Robin Image Optimizer Plugin robin-image-optimizer Information Disclosure Subscriber+ Plugin Settings Disclosure via fy_ajax < 2.0.8 Fixed in 2.0.8 CVE-2026-89190 WPScan
6.8 Medium Hostinger Reach Plugin hostinger-reach Cross-Site Scripting Contributor+ Stored XSS via formId Elementor Widget Attribute 1.0.6 – < 1.8.3 Fixed in 1.8.3 CVE-2026-87777 WPScan
5.3 Medium Connections Business Directory Plugin Information Disclosure Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes No login needed ≤ 10.4.67 CVE-2026-86789 WPScan
4.3 Medium All in One Files Upload for WooCommerce Plugin Broken Access Control Subscriber+ Arbitrary Plugin Settings Update < 2.0.17 Fixed in 2.0.17 CVE-2026-85576 WPScan
6.8 Medium Audio Player Block Plugin audio-player-block Cross-Site Scripting Contributor+ Stored XSS via Audio Download URL 1.1.0 – < 1.6.3 Fixed in 1.6.3 CVE-2026-85415 WPScan
6.8 Medium EmbedPress Plugin embedpress Cross-Site Scripting Contributor+ Stored XSS via Elementor Widget showTitle Attribute 4.4.9 – < 4.6.7 Fixed in 4.6.7 CVE-2026-85001 WPScan
5.3 Medium New User Approve Plugin new-user-approve Information Disclosure Unauthenticated PII Disclosure via Zapier API Key Bypass No login needed 3.1.0 – < 3.2.10 Fixed in 3.2.10 CVE-2026-83560 WPScan
5.3 Medium Solace Extra Plugin solace-extra Information Disclosure Unauthenticated Non-Published Post Content Disclosure via Preview Routes No login needed < 1.7.2 Fixed in 1.7.2 CVE-2026-80333 WPScan
5.3 Medium WP User Frontend Plugin Broken Access Control Unauthenticated Account Creation with Registration Disabled No login needed 2.5.8 – < 4.3.12 Fixed in 4.3.12 CVE-2026-75824 WPScan
6.5 Medium FluentCart Plugin Privilege Escalation Unauthenticated Guest Customer Account Takeover via Checkout Email No login needed < 1.6.5 Fixed in 1.6.5 CVE-2026-100143 WPScan
5.3 Medium Verge3D Plugin Price Manipulation Unauthenticated Payment Bypass via v3d_payment_done No login needed 4.1.0 – 4.13.0 CVE-2026-92996 WPScan
5.3 Medium Paymattic Plugin wp-payment-form Price Manipulation Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent No login needed 4.6.20 – < 4.6.26 Fixed in 4.6.26 CVE-2026-89411 WPScan
5.4 Medium Blacklist Manager for WooCommerce Plugin Authentication Bypass Blocked User Restriction Bypass via XML-RPC and Application Passwords 1.3.0 – < 2.3.2 Fixed in 2.3.2 CVE-2026-88828 WPScan
5.3 Medium Bookly Plugin Price Manipulation Unauthenticated Payment Bypass via Booking Price Manipulation No login needed < 28.3 Fixed in 28.3 CVE-2026-86838 WPScan
6.5 Medium WPForms Lite Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation No login needed 1.5.0.1 – < 2.0.2.1 Fixed in 2.0.2.1 CVE-2026-84744 WPScan
6.8 Medium SPS-Suite Plugin SQL Injection Unauthenticated Time-Based SQLi via Search No login needed ≤ 1.4.0 CVE-2026-93000 WPScan
5.3 Medium WP Verify API Plugin Broken Access Control Unauthenticated Verification Code Email Sending to Arbitrary Recipients No login needed ≤ 1.0.0 CVE-2026-89300 WPScan
6.4 Medium Post Voting System Plugin SQL Injection Subscriber+ SQLi via 'row' Parameter ≤ 1.0 CVE-2026-89303 WPScan
6.8 Medium PowerPress Plugin Cross-Site Scripting Contributor+ Stored XSS via Podcast Player Block < 11.17.2 Fixed in 11.17.2 CVE-2026-97319 WPScan
5.9 Medium NextScripts: Social Networks Auto-Poster Plugin social-networks-auto-poster-facebook-twitter-g Information Disclosure Authenticated Social Account Credential Disclosure and Data Deletion < 4.4.8 Fixed in 4.4.8 CVE-2026-97227 WPScan
6.8 Medium Optima Express Plugin Cross-Site Scripting Author+ Stored XSS via faq_script 8.6.0 – < 8.7.6 Fixed in 8.7.6 CVE-2026-96899 WPScan
5.3 Medium Optima Express Plugin Broken Access Control Unauthenticated Author Account Creation & Application Password Rotation via ihf_clear_cache No login needed 8.5.0 – < 8.7.6 Fixed in 8.7.6 CVE-2026-96897 WPScan
6.8 Medium WP YouTube Lyte Plugin wp-youtube-lyte Cross-Site Scripting Contributor+ Stored XSS via Embed Block Attributes < 1.7.31 Fixed in 1.7.31 CVE-2026-96895 WPScan
5.3 Medium Verge3D Plugin Information Disclosure Unauthenticated Product Download Disclosure via v3d_download_file No login needed ≤ 4.13.0 CVE-2026-92995 WPScan
5.3 Medium Mailchimp for WooCommerce Plugin mailchimp-for-woocommerce Information Disclosure Unauthenticated Customer Email and Cart Disclosure via IDOR No login needed < 6.3 Fixed in 6.3 CVE-2026-92436 WPScan
6.8 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Cross-Site Scripting Contributor+ Stored XSS via Feed Import < 2.8.27 Fixed in 2.8.27 CVE-2026-89006 WPScan
4.1 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Server-Side Request Forgery Contributor+ SSRF via Campaign Preview < 2.8.27 Fixed in 2.8.27 CVE-2026-89003 WPScan
4.9 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Privilege Escalation Contributor+ Post Publication and Author Spoofing via Campaign Settings < 2.8.27 Fixed in 2.8.27 CVE-2026-89001 WPScan
4.1 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Server-Side Request Forgery Contributor+ SSRF via Campaign Run < 2.8.27 Fixed in 2.8.27 CVE-2026-89000 WPScan
4.7 Medium Bookly Plugin PHP Object Injection Bookly Administrator+ PHP Object Injection via Diagnostics Advanced Options 23.2 – < 28.3 Fixed in 28.3 CVE-2026-86841 WPScan
6.8 Medium EmbedPress Plugin embedpress Cross-Site Scripting Contributor+ Stored XSS via Instagram Carousel Block Attributes < 4.6.7 Fixed in 4.6.7 CVE-2026-85002 WPScan
5.3 Medium WebFacing Email Accounts for cPanel Plugin Local File Inclusion Unauthenticated LFI via assets/index.php No login needed 5.3 – < 5.4 Fixed in 5.4 CVE-2026-84069 WPScan
5.3 Medium UpdraftPlus Plugin Information Disclosure Subscriber+ Remote Storage Credential Disclosure via Migration Notice 1.23.8 – < 1.26.8, 2.23.8 – < 2.26.8.26 Fixed in 1.26.8 CVE-2026-82841 WPScan
5.8 Medium Testimonials Widget Plugin Server-Side Request Forgery Unauthenticated SSRF via Featured Image URL No login needed ≤ 4.0.4 CVE-2026-96533 WPScan
6.8 Medium Optimole Plugin optimole-wp Cross-Site Scripting Author+ Stored XSS via Video Player Block 4.0.0 – < 4.2.13 Fixed in 4.2.13 CVE-2026-96531 WPScan
6.8 Medium WP Delicious Plugin delicious-recipes Cross-Site Scripting Contributor+ Stored XSS via Recipe Block Tag Name < 1.10.8 Fixed in 1.10.8 CVE-2026-92411 WPScan
6.5 Medium WP Review Slider Pro Plugin SQL Injection Subscriber+ SQLi via Stored Template Filter < 12.7.12 Fixed in 12.7.12 CVE-2026-84097 WPScan
5.9 Medium File Manager Plugin wp-file-manager Information Disclosure Unauthenticated Database Backup Disclosure No login needed 7.2.2 – < 8.0.5 Fixed in 8.0.5 CVE-2026-19708 WPScan
6.8 Medium Bluff Post Plugin SQL Injection Unauthenticated SQLi via 'table_name' and 'column_name' Parameters No login needed ≤ 1.1.1 CVE-2026-89237 WPScan
5.3 Medium Team Showcase Supreme Plugin Information Disclosure Unauthenticated Sensitive Data Disclosure via wpm_6310_team_member_details No login needed < 9.3 Fixed in 9.3 CVE-2026-11871 WPScan
6.4 Medium Automatic.css Plugin automaticcss-plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via REQUEST_URI 4.0.0 CVE-2026-15273 Wordfence
4.2 Medium MasterStudy LMS 1.9 Plugin Broken Access Control < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restriction Bypass 1.9 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88848 WPScan
5.3 Medium wpForo Forum Plugin wpforo Other Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass No login needed 3.0.0 – < 3.1.6 Fixed in 3.1.6 CVE-2026-80514 WPScan
5.3 Medium Bookly Plugin Broken Access Control Unauthenticated Customer PII Update via Verification Bypass No login needed < 28.3 Fixed in 28.3 CVE-2026-86837 WPScan
5.5 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter ≤ 1.4.0.5 CVE-2026-12037 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only