WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 2,451–2,500 of 17,704 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.9 Medium | WP Emmet | Cross-Site Scripting |
≤ 0.3.4 |
CVE-2025-15658 |
Patchstack | |
| 6.5 Medium | MasterStudy LMS Pro | Broken Access Control No login needed |
< 4.7.16 Fixed in 4.7.16 |
CVE-2025-64215 |
Patchstack | |
| 6.5 Medium | Really Simple SSL | Broken Access Control |
≤ 9.5.9 Fixed in 9.5.10 |
CVE-2026-48969 |
Patchstack | |
| 6.2 Medium | Abtest | Local File Inclusion WordPress Plugin Abtest Local File Inclusion via abtest_admin.php No login needed |
1.0.6 |
CVE-2016-20082 |
VulnCheck | |
| 6.2 Medium | Brandfolder | Local File Inclusion WordPress Brandfolder Plugin 3.0 Local File Inclusion via callback.php No login needed |
≤ 3.0 |
CVE-2016-20080 |
VulnCheck | |
| 6.2 Medium | Dharma Booking | Local File Inclusion WordPress Dharma Booking 2.28.3 Local File Inclusion via proccess.php No login needed |
≤ 2.28.3 |
CVE-2016-20079 |
VulnCheck | |
| 6.2 Medium | IMDb Profile Widget | Local File Inclusion WordPress IMDb Profile Widget 1.0.8 Local File Inclusion via pic.php No login needed |
1.0.8 |
CVE-2016-20078 |
VulnCheck | |
| 6.2 Medium | Photocart Link | Local File Inclusion WordPress Plugin Photocart Link 1.6 Local File Inclusion via decode.php No login needed |
1.6 |
CVE-2016-20077 |
VulnCheck | |
| 5.4 Medium | Form Builder CP | Cross-Site Scripting Editor+ Stored XSS via form_structure |
< 1.2.47 Fixed in 1.2.47 |
CVE-2026-9278 |
WPScan | |
| 5.3 Medium | WP Go Maps | Information Disclosure Unauthenticated Sensitive Information Disclosure via Marker ID No login needed |
< 10.0.10 Fixed in 10.0.10 |
CVE-2026-8386 |
WPScan | |
| 5.3 Medium | WP Go Maps | Information Disclosure Unauthenticated Sensitive Information Disclosure via Datatables AJAX Fallback No login needed |
< 10.0.10 Fixed in 10.0.10 |
CVE-2026-8385 |
WPScan | |
| 5.4 Medium | Iptanus File Upload | Arbitrary File Upload File Overwrite via Race Condition |
< 5.1.7 Fixed in 5.1.7 |
CVE-2025-15546 |
WPScan | |
| 4.3 Medium | Meow Gallery | Broken Access Control Missing Authorization to Authenticated (Author+) Shortcode creation |
≤ 5.4.4 |
CVE-2026-1291 |
Wordfence | |
| 6.4 Medium | Canvas | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute |
≤ 2.5.2 |
CVE-2026-9629 |
Wordfence | |
| 4.3 Medium | Pagelayer | Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts' |
≤ 2.0.9 |
CVE-2026-2470 |
Wordfence | |
| 6.4 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Scripting Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block |
≤ 2.0.9 |
CVE-2026-3297 |
Wordfence | |
| 6.4 Medium | Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter |
≤ 3.1.31 |
CVE-2026-9134 |
Wordfence | |
| 4.9 Medium | WS Optimize – All-in-One Speed Booster & Cache Tools | Path Traversal All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read |
≤ 3.3.19 |
CVE-2026-12089 |
Wordfence | |
| 4.3 Medium | Hash Elements | Information Disclosure Sensitive Data Exposure |
≤ 1.5.4 Fixed in 1.5.5 |
CVE-2026-24618 |
Patchstack | |
| 6.4 Medium | The Ultimate Video Player | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute |
≤ 4.2.0 |
CVE-2026-9125 |
Wordfence | |
| 4.3 Medium | MetroStore | Broken Access Control |
≤ 1.3.2 |
CVE-2023-32959 |
Patchstack | |
| 5.4 Medium | Contact Form & Lead Form Elementor Builder | Broken Access Control No login needed |
≤ 1.8.4 Fixed in 1.8.5 |
CVE-2023-25969 |
Patchstack | |
| 4.3 Medium | WooCommerce Conversion Tracking | Cross-Site Request Forgery No login needed |
≤ 2.0.10 Fixed in 2.0.11 |
CVE-2022-47150 |
Patchstack | |
| 5.4 Medium | Advanced AJAX Product Filters | Broken Access Control Broken Access Control + CSRF |
≤ 1.6.3.3 Fixed in 1.6.3.4 |
CVE-2022-45813 |
Patchstack | |
| 4.6 Medium | YITH WooCommerce Product Slider Carousel | Cross-Site Request Forgery |
≤ 1.16.0 Fixed in 1.16.1 |
CVE-2022-44630 |
Patchstack | |
| 5.4 Medium | Soledad | Broken Access Control |
≤ 8.2.5 Fixed in 8.2.6 |
CVE-2022-42479 |
Patchstack | |
| 5.3 Medium | WP Logo Showcase Responsive Slider and Carousel | Broken Access Control No login needed |
≤ 3.6 Fixed in 3.7 |
CVE-2023-40200 |
Patchstack | |
| 4.3 Medium | WpEvently | Cross-Site Request Forgery No login needed |
≤ 4.1.2 Fixed in 4.1.3 |
CVE-2024-32110 |
Patchstack | |
| 4.7 Medium | Open User Map PRO | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'oum_location_notification' No login needed |
≤ 1.4.31 |
CVE-2026-2827 |
Wordfence | |
| 5.4 Medium | Simple Link Directory | Cross-Site Scripting Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes |
≤ 9.0.4 |
CVE-2026-53742 |
VulnCheck | |
| 5.4 Medium | Simple Link Directory | Cross-Site Scripting Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option |
≤ 9.0.4 |
CVE-2026-53741 |
VulnCheck | |
| 5.4 Medium | Yoast Duplicate Post | Cross-Site Scripting Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Notice |
≤ 4.6 |
CVE-2026-53740 |
VulnCheck | |
| 4.3 Medium | Yoast Duplicate Post | Cross-Site Request Forgery Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_notice No login needed |
≤ 4.6 |
CVE-2026-53739 |
VulnCheck | |
| 6.1 Medium | Juicer | Cross-Site Scripting Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response No login needed |
≤ 1.12.18 |
CVE-2026-53737 |
VulnCheck | |
| 4.3 Medium | Easy Twitter Feeds | Cross-Site Request Forgery Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_post Action No login needed |
< 1.2.13 Fixed in 1.2.13 |
CVE-2026-53736 |
VulnCheck | |
| 6.4 Medium | aThemes Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget Setting |
≤ 1.1.8 |
CVE-2026-8613 |
Wordfence | |
| 4.4 Medium | MW WP Form | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameter |
≤ 5.1.3 |
CVE-2026-8853 |
Wordfence | |
| 6.4 Medium | Easy Image Collage | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters |
≤ 1.13.6 |
CVE-2026-9019 |
Wordfence | |
| 6.4 Medium | Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates | Cross-Site Scripting GSAP Powered Elementor Addons & Website Templates <= 2.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters |
≤ 2.6.7 |
CVE-2025-8444 |
Wordfence | |
| 4.3 Medium | BuddyPress | Broken Access Control BuddyPress 14.4.0 Friends List IDOR via REST API |
≤ 14.4.0 |
CVE-2026-53675 |
VulnCheck | |
| 6.2 Medium | WP Vault | Local File Inclusion WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter No login needed |
0.8.6.6 |
CVE-2016-20064 |
VulnCheck | |
| 4.3 Medium | User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation |
≤ 4.3.2 |
CVE-2026-4058 |
Wordfence | |
| 6.4 Medium | Prime Elementor Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget HTML Tag Settings |
≤ 1.3.3 |
CVE-2026-8677 |
Wordfence | |
| 6.4 Medium | MailerPress | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Campaign HTML Content Field |
≤ 2.0.4 |
CVE-2026-8599 |
Wordfence | |
| 6.5 Medium | Slider Revolution | Information Disclosure Authenticated (Subscriber+) Sensitive Information Disclosure |
7.0 – 7.0.10 |
CVE-2026-7542 |
Wordfence | |
| 5.3 Medium | WPForms Lite | Broken Access Control Unauthenticated PayPal Webhook Forgery No login needed |
1.10.0.1 – < 1.10.0.5 Fixed in 1.10.0.5 |
CVE-2026-4986 |
WPScan | |
| 6.4 Medium | kk blog card | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.3 |
CVE-2026-8895 |
Wordfence | |
| 6.1 Medium | Product Filter Widget for Elementor | Cross-Site Scripting Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter No login needed |
≤ 1.0.6 |
CVE-2026-11603 |
Wordfence | |
| 4.3 Medium | jQuery Hover Footnotes | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.4 |
CVE-2026-10553 |
Wordfence | |
| 4.3 Medium | FastPicker, an order picker and order management system (oms) for WooCommerce on steroids | Cross-Site Request Forgery Cross-Site Request Forgery via Settings Save No login needed |
≤ 1.0.2 |
CVE-2026-8904 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.