WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,451–2,500 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 50 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 4.3.2.0 Fixed in 4.3.2.1 CVE-2026-42669 Patchstack
8.1 High Crafti Theme crafti Local File Inclusion No login needed ≤ 1.12 CVE-2025-58705 Patchstack
7.5 High Accordion FAQ Plugin pressapps-accordion-faq Local File Inclusion ≤ 2.2.1 CVE-2025-58024 Patchstack
8.1 High Confidant Theme confidant Local File Inclusion No login needed ≤ 1.4 CVE-2025-53440 Patchstack
4.3 Medium Thim Core Plugin thim-core Broken Access Control ≤ 2.3.3 CVE-2025-53346 Patchstack
8.8 High Thim Core Plugin thim-core Broken Access Control Arbitrary plugin Installation ≤ 2.3.3 CVE-2025-53345 Patchstack
5.3 Medium Constructor Theme constructor Broken Access Control No login needed ≤ 1.6.5 CVE-2025-53302 Patchstack
9.8 Critical Masteriyo LMS PRO Plugin learning-management-system-pro Privilege Escalation No login needed ≤ 2.20.0 Fixed in 2.20.1 CVE-2025-53209 Patchstack
6.5 Medium Printeers Print & Ship Plugin invition-print-ship Broken Access Control ≤ 1.17.0 CVE-2025-52766 Patchstack
7.1 High Accordion FAQ Plugin pressapps-accordion-faq Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2025-52759 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Broken Access Control No login needed ≤ 2.8.157 Fixed in 2.8.158 CVE-2026-42671 Patchstack
9.3 Critical WP Directory Kit Plugin wpdirectorykit SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-42672 Patchstack
7.5 High Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Plugin logtivity Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2026-42673 Patchstack
7.5 High Advanced Access Manager Plugin advanced-access-manager Authentication Bypass Bypass Vulnerability No login needed ≤ 7.1.0 Fixed in 7.1.1 CVE-2026-42674 Patchstack
7.3 High Hydra Booking Plugin hydra-booking Broken Access Control No login needed ≤ 1.1.41 Fixed in 1.1.42 CVE-2026-42675 Patchstack
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 3.0.4 Fixed in 3.0.5 CVE-2026-42676 Patchstack
7.5 High WP Document Revisions Plugin wp-document-revisions Broken Access Control No login needed < 4.0.0 Fixed in 4.0.0 CVE-2026-42677 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.14.5 Fixed in 4.14.6 CVE-2026-42678 Patchstack
6.5 Medium Classified Listing Plugin classified-listing Path Traversal Arbitrary File Download ≤ 5.3.8 Fixed in 5.3.9 CVE-2026-42679 Patchstack
9.8 Critical Contest Gallery Pro Plugin contest-gallery-pro Privilege Escalation No login needed ≤ 29.0.1 Fixed in 29.0.2 CVE-2026-42680 Patchstack
7.1 High e2pdf Plugin e2pdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.32.14 Fixed in 1.32.15 CVE-2026-42681 Patchstack
9.1 Critical wpForo Forum Plugin wpforo Broken Access Control No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-42682 Patchstack
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting No login needed ≤ 1.8.8 Fixed in 1.8.9 CVE-2026-42683 Patchstack
7.1 High WP Statistics Plugin wp-statistics Cross-Site Scripting No login needed ≤ 14.16.6 Fixed in 14.16.7 CVE-2026-48839 Patchstack
7.1 High LearnPress Plugin learnpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.6 Fixed in 4.3.7 CVE-2026-48865 Patchstack
9.6 Critical Gravity Forms Plugin gravityforms Arbitrary File Deletion No login needed ≤ 2.10.0.1 Fixed in 2.10.1 CVE-2026-48866 Patchstack
9.8 Critical AIWU Plugin ai-copilot-content-generator Privilege Escalation No login needed ≤ 1.4.17 Fixed in 1.4.19 CVE-2026-48879 Patchstack
7.5 High Simple History – Track, Log, and Audit WordPress Changes Plugin simple-history Privilege Escalation Track, Log, and Audit WordPress Changes <= 5.26.0 - Authenticated (Subscriber+) Account Takeover via Missing Authorization on Event Reaction Endpoint ≤ 5.26.0 CVE-2026-7459 Wordfence
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Portfolio Project Details ≤ 13.4.1 CVE-2025-14042 Wordfence
6.4 Medium StatCounter Plugin official-statcounter-plugin-for-wordpress Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Author Nickname ≤ 2.1.1 CVE-2026-6275 Wordfence
4.3 Medium Visualizer: Tables and Charts Manager Plugin visualizer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() Functions ≤ 3.11.14 CVE-2026-8689 Wordfence
4.3 Medium SMTP2GO Plugin smtp2go Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Read/Truncate ≤ 1.16.0 CVE-2026-7621 Wordfence
4.3 Medium Account Manager for WooCommerce Plugin account-manager-woocommerce Broken Access Control ≤ 2.1.2 CVE-2022-41656 Patchstack
4.3 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.9.2 CVE-2026-49054 Patchstack
5.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control No login needed ≤ 3.9.6 CVE-2026-49053 Patchstack
4.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control ≤ 3.9.6 CVE-2026-49052 Patchstack
4.3 Medium WP Meta and Date Remover Plugin wp-meta-and-date-remover Broken Access Control ≤ 2.3.6 CVE-2026-49051 Patchstack
4.3 Medium DearFlip Plugin 3d-flipbook-dflip-lite Broken Access Control ≤ 2.4.27 CVE-2026-49047 Patchstack
8.5 High Duplicate Page and Post Plugin duplicate-wp-page-post SQL Injection ≤ 2.9.5 CVE-2026-49046 Patchstack
6.5 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Cross-Site Scripting ≤ 5.0.2 CVE-2026-49044 Patchstack
4.3 Medium Adminimize Plugin adminimize Broken Access Control ≤ 1.11.11 CVE-2026-49045 Patchstack
4.7 Medium Facebook for WooCommerce Plugin facebook-for-woocommerce Open Redirect No login needed ≤ 3.7.0 CVE-2026-49059 Patchstack
4.3 Medium SVG Support Plugin svg-support Broken Access Control ≤ 2.5.14 CVE-2026-48973 Patchstack
7.5 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 Local File Inclusion < 6.19.5 Fixed in 6.19.5 CVE-2026-48972 Patchstack
4.3 Medium Product Import Export for WooCommerce Plugin product-import-export-for-woo Broken Access Control ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-48971 Patchstack
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2026-42762 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-42761 Patchstack
7.5 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule Authentication Bypass Broken Authentication No login needed ≤ 1.22.25 Fixed in 1.22.26 CVE-2026-42760 Patchstack
7.1 High Affiliate Super Assistent Plugin amazonsimpleadmin Cross-Site Scripting No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2026-42759 Patchstack
9.8 Critical WebinarIgnition Plugin webinar-ignition Privilege Escalation No login needed ≤ 4.08.253 Fixed in 4.08.253 CVE-2026-42758 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only