WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 2,451–2,500 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.8 Critical | OAuth Single Sign On – SSO (OAuth Client) | Authentication Bypass SSO (OAuth Client) plugin <= 7.0.0 - Broken Authentication No login needed |
≤ 7.0.0 Fixed in 7.0.1 |
CVE-2026-28008 |
Patchstack | |
| 7.1 High | Business Directory | Cross-Site Scripting No login needed |
≤ 6.4.25 Fixed in 6.4.26 |
CVE-2026-28004 |
Patchstack | |
| 7.1 High | Maspik – Spam blacklist | Cross-Site Scripting Spam blacklist plugin <= 2.9.1 - Cross Site Scripting (XSS) No login needed |
≤ 2.9.1 Fixed in 2.9.2 |
CVE-2026-28003 |
Patchstack | |
| 9.3 Critical | WP Directory Kit | SQL Injection No login needed |
≤ 1.5.4 Fixed in 1.5.5 |
CVE-2026-28001 |
Patchstack | |
| 6.5 Medium | Tourfic | Broken Access Control |
≤ 2.23.1 Fixed in 2.23.2 |
CVE-2026-27999 |
Patchstack | |
| 10.0 Critical | QA Analytics | Remote Code Execution No login needed |
≤ 5.2.0.0 Fixed in 5.2.0.1 |
CVE-2026-27544 |
Patchstack | |
| 8.1 High | MStore API | Privilege Escalation No login needed |
≤ 4.20.0 Fixed in 4.21.0 |
CVE-2026-27543 |
Patchstack | |
| 7.1 High | Welcart e-Commerce | Cross-Site Scripting No login needed |
≤ 2.11.31 Fixed in 2.11.32 |
CVE-2026-27539 |
Patchstack | |
| 7.5 High | WP Directory Kit | SQL Injection No login needed |
≤ 1.5.4 Fixed in 1.5.5 |
CVE-2026-27538 |
Patchstack | |
| 6.5 Medium | Popup by Supsystic | Cross-Site Scripting |
≤ 1.11.2 Fixed in 1.12.0 |
CVE-2026-27537 |
Patchstack | |
| 7.1 High | MailChimp Subscribe Forms | Cross-Site Scripting No login needed |
≤ 4.3.3 Fixed in 4.3.4 |
CVE-2026-27536 |
Patchstack | |
| 7.1 High | Solace Extra | Broken Access Control |
≤ 1.6.0 Fixed in 1.6.1 |
CVE-2026-27535 |
Patchstack | |
| 7.2 High | Car Rental Manager | PHP Object Injection |
≤ 1.3.9 Fixed in 1.4.0 |
CVE-2026-27380 |
Patchstack | |
| 7.5 High | Taxi Booking Manager for WooCommerce | Broken Access Control No login needed |
≤ 2.0.3 Fixed in 2.0.5 |
CVE-2026-27345 |
Patchstack | |
| 10.0 Critical | Link Factory | Other Backdoor No login needed | Not stated | CVE-2026-15413 |
WPScan | |
| 5.4 Medium | Ecwid by Lightspeed Ecommerce Shopping Cart | Broken Access Control Subscriber+ Store Disconnection via 'ec_disconnect' Action |
< 7.0.9 Fixed in 7.0.9 |
CVE-2026-14332 |
WPScan | |
| 6.4 Medium | PPWP – Password Protect Pages | Cross-Site Scripting Password Protect Pages <= 1.9.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.9.21 |
CVE-2026-3639 |
Wordfence | |
| 7.2 High | Fluent Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values No login needed |
≤ 6.2.11 |
CVE-2026-18146 |
Wordfence | |
| 5.4 Medium | ShopEngine | Information Disclosure Customer PII Disclosure via Forced Authentication No login needed |
< 4.9.3 Fixed in 4.9.3 |
CVE-2026-19088 |
WPScan | |
| 8.2 High | WP Helper Premium | Information Disclosure Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation No login needed |
< 4.7.6 Fixed in 4.7.6 |
CVE-2026-18945 |
WPScan | |
| 3.7 Low | Amelia | Information Disclosure Provider+ Cross-Customer Appointment Data Disclosure via IDOR No login needed |
< 2.4.6 Fixed in 2.4.6 |
CVE-2026-14213 |
WPScan | |
| 9.8 Critical | Customer Email Verification for WooCommerce | Privilege Escalation Unauthenticated Account Takeover via Type-Juggling Authentication Bypass No login needed |
2.4.0 – < 3.2.6 Fixed in 3.2.6 |
CVE-2026-14182 |
WPScan | |
| 7.5 High | KiviCare | Privilege Escalation Unauthenticated Privilege Escalation via Registration No login needed |
< 4.5.2 Fixed in 4.5.2 |
CVE-2026-13610 |
WPScan | |
| 5.3 Medium | TLP Food Menu | Broken Access Control Unauthenticated Reservation Status Modification No login needed |
< 6.0.2 Fixed in 6.0.2 |
CVE-2026-13328 |
WPScan | |
| 5.3 Medium | Prevent Direct Access – Protect WordPress Files | Broken Access Control Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access No login needed |
≤ 2.8.8.8 |
CVE-2026-3835 |
Wordfence | |
| 6.5 Medium | draft-list | Cross-Site Scripting Contributor Stored Cross-Site Scripting via Draft Title in Custom Drafts Template Attributes |
< 2.6.4 |
CVE-2026-49466 |
GitHub_M | |
| 3.7 Low | Estatik Real Estate | Other Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch No login needed |
< 4.3.4 Fixed in 4.3.4 |
CVE-2026-18044 |
WPScan | |
| 5.3 Medium | Quick PayPal Payments | Price Manipulation Unauthenticated Payment Bypass via PayPal IPN No login needed |
≤ 5.7.50 |
CVE-2026-17008 |
WPScan | |
| 5.3 Medium | Payment Button for PayPal | Price Manipulation Unauthenticated Payment Price Manipulation No login needed |
≤ 1.2.3.44 |
CVE-2026-16990 |
WPScan | |
| 6.5 Medium | Kirki | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Form Email Actions No login needed |
< 6.2.1 Fixed in 6.2.1 |
CVE-2026-16747 |
WPScan | |
| 5.3 Medium | Payment Gateway for PayPal on WooCommerce | Price Manipulation Unauthenticated Payment Bypass via PayPal Advanced Return Handler No login needed |
< 9.2.1 Fixed in 9.2.1 |
CVE-2026-16621 |
WPScan | |
| 5.3 Medium | Welcart e-Commerce | Price Manipulation Unauthenticated Payment Bypass via Forged Settlement Callback No login needed |
< 2.11.33 Fixed in 2.11.33 |
CVE-2026-15213 |
WPScan | |
| 6.5 Medium | Wallet System for WooCommerce | Price Manipulation Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount |
< 2.7.10 Fixed in 2.7.10 |
CVE-2026-15045 |
WPScan | |
| 9.3 Critical | Tablesome Table | SQL Injection No login needed |
≤ 1.2.9 |
CVE-2026-66659 |
Patchstack | |
| 5.4 Medium | Royal Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Icon Box Widget |
< 1.7.1065 Fixed in 1.7.1065 |
CVE-2026-19217 |
WPScan | |
| 5.3 Medium | Order Sync with Zendesk for WooCommerce | Information Disclosure Unauthenticated Customer Order Data Disclosure No login needed |
< 2.2.3 Fixed in 2.2.3 |
CVE-2026-19073 |
WPScan | |
| 4.3 Medium | ProSolution WP Client | Broken Access Control Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls |
< 2.0.9 Fixed in 2.0.9 |
CVE-2026-19052 |
WPScan | |
| 6.4 Medium | ProSolution WP Client | Server-Side Request Forgery Subscriber+ SSRF via proSol_url_validate |
< 2.0.9 Fixed in 2.0.9 |
CVE-2026-19050 |
WPScan | |
| 4.3 Medium | WP Photo Album Plus | Arbitrary File Upload Subscriber+ Cross-Album File Upload via Missing Authorization |
< 9.2.09.002 Fixed in 9.2.09.002 |
CVE-2026-18962 |
WPScan | |
| 6.5 Medium | WPC Admin Columns | Information Disclosure Subscriber+ Arbitrary User/Post/Term Meta Disclosure |
< 2.3.4 Fixed in 2.3.4 |
CVE-2026-18943 |
WPScan | |
| 7.5 High | Ezoic | Broken Access Control Unauthenticated Database Export via Content Export REST Routes No login needed |
2.6.35 – < 2.23.1 Fixed in 2.23.1 |
CVE-2026-18789 |
WPScan | |
| 8.6 High | WP Directory Kit | SQL Injection Unauthenticated SQL Injection via search_location and search_category No login needed |
< 1.5.6 Fixed in 1.5.6 |
CVE-2026-18474 |
WPScan | |
| 9.8 Critical | WooCommerce Subscriptions | Remote Code Execution Unauthenticated RCE via PHP Object Injection No login needed |
4.7.0 – < 9.1.0 Fixed in 9.1.0 |
CVE-2026-18391 |
WPScan | |
| 9.8 Critical | Events Manager | Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed |
7.1 – < 7.4.1 Fixed in 7.4.1 |
CVE-2026-18366 |
WPScan | |
| 8.1 High | WP Directory Kit | SQL Injection Subscriber+ SQL Injection via section Parameter |
< 1.5.6 Fixed in 1.5.6 |
CVE-2026-18230 |
WPScan | |
| 8.1 High | Events Manager | SQL Injection Subscriber+ Booking Consent Record Tampering via SQL Injection |
< 7.4.1 Fixed in 7.4.1 |
CVE-2026-18057 |
WPScan | |
| 7.5 High | WP Photo Album Plus | Information Disclosure Unauthenticated Option Disclosure via gettogo No login needed |
< 9.2.07.002 Fixed in 9.2.07.002 |
CVE-2026-18049 |
WPScan | |
| 7.5 High | WP Photo Album Plus | Arbitrary File Deletion Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal No login needed |
< 9.2.07.002 Fixed in 9.2.07.002 |
CVE-2026-18048 |
WPScan | |
| 4.3 Medium | Cookie Consent | Broken Access Control Subscriber+ MaxMind License Key Update |
0.0.9 – < 0.0.10 Fixed in 0.0.10 |
CVE-2026-18046 |
WPScan | |
| 5.3 Medium | User Access Manager | Information Disclosure Unauthenticated Restricted Content Disclosure via REST API No login needed |
< 2.3.15 Fixed in 2.3.15 |
CVE-2026-18035 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.