WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,501–2,550 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 51 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Reflected XSS via lbstart No login needed < 9.2.07.002 Fixed in 9.2.07.002 CVE-2026-17013 WPScan
8.1 High Form Maker by 10Web Plugin form-maker SQL Injection Subscriber+ SQL Injection via display_name < 1.15.45 Fixed in 1.15.45 CVE-2026-16977 WPScan
5.3 Medium WP Travel Engine Plugin wp-travel-engine Information Disclosure Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart No login needed < 6.8.5 Fixed in 6.8.5 CVE-2026-16737 WPScan
9.1 Critical TeraWallet - Wallet for WooCommerce Plugin Broken Access Control Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up No login needed < 1.6.10 Fixed in 1.6.10 CVE-2026-16538 WPScan
7.1 High Blubrry PowerPress Plugin Server-Side Request Forgery Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL < 11.17.1 Fixed in 11.17.1 CVE-2026-16294 WPScan
7.5 High Total Upkeep Plugin boldgrid-backup Information Disclosure Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret No login needed < 1.17.3 Fixed in 1.17.3 CVE-2026-16253 WPScan
5.4 Medium Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting Author+ Stored XSS via Product Name < 2.11.34 Fixed in 2.11.34 CVE-2026-16066 WPScan
9.8 Critical WPMU DEV Dashboard Plugin Remote Code Execution Remote Code Execution via Hub Install Action No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-16051 WPScan
4.3 Medium Cookie Consent Plugin Information Disclosure Subscriber+ Consent Settings Update and Consent Log Disclosure < 0.0.10 Fixed in 0.0.10 CVE-2026-15388 WPScan
5.4 Medium Patterns Kit Plugin Cross-Site Scripting Contributor+ Stored XSS via YouTube Popup Link ≤ 1.0.3 CVE-2026-15249 WPScan
9.8 Critical Gift Cards For WooCommerce Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 4.2.10 Fixed in 4.2.10 CVE-2026-15039 WPScan
7.5 High Import WP Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via Export File Download No login needed < 2.14.23 Fixed in 2.14.23 CVE-2026-14925 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Subscriber+ Campaign Creation via Missing Authorization < 2.2.1 Fixed in 2.2.1 CVE-2026-14859 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Information Disclosure Subscriber+ Order Data Disclosure via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14858 WPScan
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Subscriber+ Campaign Update Modification via IDOR < 2.2.1 Fixed in 2.2.1 CVE-2026-14857 WPScan
8.8 High KiviCare Plugin kivicare-clinic-management-system SQL Injection Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint < 4.5.2 Fixed in 4.5.2 CVE-2026-13613 WPScan
4.3 Medium KiviCare Plugin kivicare-clinic-management-system Information Disclosure Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR < 4.5.2 Fixed in 4.5.2 CVE-2026-13612 WPScan
4.3 Medium Eventin Plugin wp-event-solution Information Disclosure Contributor+ Order Information Disclosure via IDOR 4.1.9 – < 4.1.20 Fixed in 4.1.20 CVE-2026-13177 WPScan
8.2 High Eventin Plugin wp-event-solution Broken Access Control Unauthenticated Account Creation via Waiting List Endpoint No login needed < 4.1.20 Fixed in 4.1.20 CVE-2026-13171 WPScan
6.5 Medium Eventin Plugin wp-event-solution Information Disclosure Contributor+ Customer PII Disclosure via REST API < 4.1.20 Fixed in 4.1.20 CVE-2026-13168 WPScan
6.5 Medium LearnPress Plugin learnpress Information Disclosure Subscriber+ Sensitive Information Exposure via AI Assistant < 4.4.4 Fixed in 4.4.4 CVE-2026-12976 WPScan
8.1 High Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect Plugin ventraconnect-social-login Authentication Bypass Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback No login needed ≤ 1.4.3 CVE-2026-18961 Wordfence
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token ≤ 3.29.9 CVE-2026-15606 Wordfence
8.1 High GeoDirectory Plugin geodirectory Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision ≤ 2.8.169 CVE-2026-19091 Wordfence
7.5 High InstaWP Connect Plugin instawp-connect Information Disclosure Unauthenticated Cryptographic Key Disclosure No login needed ≤ 0.1.3.6 CVE-2026-13457 Wordfence
9.8 Critical Formidable Digital Signatures Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Signature Field No login needed ≤ 3.0.6 CVE-2026-16230 Wordfence
8.8 High AcyMailing Plugin acymailing Broken Access Control Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update ≤ 10.11.1 CVE-2026-15426 Wordfence
4.3 Medium Ray Enterprise Translation Plugin Broken Access Control Subscriber+ Language Addition and Deletion ≤ 1.7.3 CVE-2026-14549 WPScan
6.5 Medium Ray Enterprise Translation Plugin Broken Access Control Subscriber+ Arbitrary API Token Update ≤ 1.7.3 CVE-2026-14548 WPScan
6.4 Medium Kirki - Freeform Page Builder, Website Builder & Customizer Plugin Cross-Site Scripting Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode ≤ 6.2.0 CVE-2026-16974 Wordfence
6.5 Medium sucuri-wordpress-plugin Plugin Path Traversal Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php ≤ 2.7.3 CVE-2026-73033 VulnCheck
5.4 Medium WP Umbrella Plugin wp-health Cross-Site Request Forgery No login needed 2.24.2 – 2.26.2 Fixed in 2.27.0 CVE-2026-66642 Patchstack
9.8 Critical Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed 2.0.0 – < 2.0.2 Fixed in 2.0.2 CVE-2026-19089 WPScan
6.5 Medium Copy & Delete Posts Plugin Broken Access Control Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization < 1.5.5 Fixed in 1.5.5 CVE-2026-19077 WPScan
5.3 Medium Advanced Classifieds & Directory Pro Plugin advanced-classifieds-and-directory-pro Information Disclosure Unauthenticated Non-Public Listing Custom Field Disclosure No login needed < 3.4.3 Fixed in 3.4.3 CVE-2026-19074 WPScan
8.8 High CheckView Plugin checkview Authentication Bypass Administrator Account Creation via REST API Authentication Bypass No login needed 2.0.29 – < 2.3.2 Fixed in 2.3.2 CVE-2026-18786 WPScan
4.3 Medium FoodBoxBooker Plugin foodboxbooker Broken Access Control Subscriber+ Arbitrary User Profile Update < 1.0.8 Fixed in 1.0.8 CVE-2026-18200 WPScan
6.8 Medium s2Member Plugin s2member Cross-Site Scripting Contributor+ Stored XSS via Shortcode < 260805 Fixed in 260805 CVE-2026-15047 WPScan
4.8 Medium Salon Booking System – Free Version Plugin Broken Access Control Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback No login needed ≤ 10.30.33 CVE-2026-17023 WPScan
8.8 High Autopay / Blue Media for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored XSS via CSS Editor No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-14293 WPScan
4.1 Medium Vitepos Plugin vitepos-lite SQL Injection Admin+ SQL Injection via product-details-report < 3.6.0 Fixed in 3.6.0 CVE-2026-14238 WPScan
7.2 High Vitepos Plugin vitepos-lite Privilege Escalation Outlet Manager+ Privilege Escalation 3.4.0 – < 3.6.0, < 3.5.0 Fixed in 3.6.0 CVE-2026-14237 WPScan
3.8 Low Amelia Pro Plugin Information Disclosure Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR 9.0 – < 9.7 Fixed in 9.7 CVE-2026-14211 WPScan
9.1 Critical ProSolution WP Client Plugin prosolution-wp-client SQL Injection Unauthenticated Blind SQLi via 'jobID' Parameter No login needed < 2.0.6 Fixed in 2.0.6 CVE-2026-19053 WPScan
8.6 High ProSolution WP Client Plugin prosolution-wp-client SQL Injection Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie No login needed < 2.0.9 Fixed in 2.0.9 CVE-2026-19049 WPScan
7.5 High Salon Booking System – Free Version Plugin Information Disclosure Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard No login needed < 10.30.34 Fixed in 10.30.34 CVE-2026-17022 WPScan
5.3 Medium Salon Booking System – Free Version Plugin Broken Access Control Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering No login needed < 10.30.34 Fixed in 10.30.34 CVE-2026-17021 WPScan
4.3 Medium Salon Booking System – Free Version Plugin Information Disclosure Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure ≤ 10.31.0 CVE-2026-17020 WPScan
5.3 Medium Pinpoint Booking System Plugin Price Manipulation Unauthenticated Arbitrary Booking Price Manipulation No login needed ≤ 2.9.9.7.1 CVE-2026-15229 WPScan
5.4 Medium Block User Account Plugin block-user-account Authentication Bypass Subscriber+ Account Block Bypass via Application Passwords < 2.0.1 Fixed in 2.0.1 CVE-2026-18960 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only