WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 2,501–2,550 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | WP Photo Album Plus | Cross-Site Scripting Reflected XSS via lbstart No login needed |
< 9.2.07.002 Fixed in 9.2.07.002 |
CVE-2026-17013 |
WPScan | |
| 8.1 High | Form Maker by 10Web | SQL Injection Subscriber+ SQL Injection via display_name |
< 1.15.45 Fixed in 1.15.45 |
CVE-2026-16977 |
WPScan | |
| 5.3 Medium | WP Travel Engine | Information Disclosure Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart No login needed |
< 6.8.5 Fixed in 6.8.5 |
CVE-2026-16737 |
WPScan | |
| 9.1 Critical | TeraWallet - Wallet for WooCommerce | Broken Access Control Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up No login needed |
< 1.6.10 Fixed in 1.6.10 |
CVE-2026-16538 |
WPScan | |
| 7.1 High | Blubrry PowerPress | Server-Side Request Forgery Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL |
< 11.17.1 Fixed in 11.17.1 |
CVE-2026-16294 |
WPScan | |
| 7.5 High | Total Upkeep | Information Disclosure Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret No login needed |
< 1.17.3 Fixed in 1.17.3 |
CVE-2026-16253 |
WPScan | |
| 5.4 Medium | Welcart e-Commerce | Cross-Site Scripting Author+ Stored XSS via Product Name |
< 2.11.34 Fixed in 2.11.34 |
CVE-2026-16066 |
WPScan | |
| 9.8 Critical | WPMU DEV Dashboard | Remote Code Execution Remote Code Execution via Hub Install Action No login needed |
< 5.0.1 Fixed in 5.0.1 |
CVE-2026-16051 |
WPScan | |
| 4.3 Medium | Cookie Consent | Information Disclosure Subscriber+ Consent Settings Update and Consent Log Disclosure |
< 0.0.10 Fixed in 0.0.10 |
CVE-2026-15388 |
WPScan | |
| 5.4 Medium | Patterns Kit | Cross-Site Scripting Contributor+ Stored XSS via YouTube Popup Link |
≤ 1.0.3 |
CVE-2026-15249 |
WPScan | |
| 9.8 Critical | Gift Cards For WooCommerce Pro | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
< 4.2.10 Fixed in 4.2.10 |
CVE-2026-15039 |
WPScan | |
| 7.5 High | Import WP | Information Disclosure Unauthenticated Sensitive Information Exposure via Export File Download No login needed |
< 2.14.23 Fixed in 2.14.23 |
CVE-2026-14925 |
WPScan | |
| 4.3 Medium | WP Crowdfunding | Broken Access Control Subscriber+ Campaign Creation via Missing Authorization |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14859 |
WPScan | |
| 4.3 Medium | WP Crowdfunding | Information Disclosure Subscriber+ Order Data Disclosure via IDOR |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14858 |
WPScan | |
| 4.3 Medium | WP Crowdfunding | Broken Access Control Subscriber+ Campaign Update Modification via IDOR |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14857 |
WPScan | |
| 8.8 High | KiviCare | SQL Injection Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint |
< 4.5.2 Fixed in 4.5.2 |
CVE-2026-13613 |
WPScan | |
| 4.3 Medium | KiviCare | Information Disclosure Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDOR |
< 4.5.2 Fixed in 4.5.2 |
CVE-2026-13612 |
WPScan | |
| 4.3 Medium | Eventin | Information Disclosure Contributor+ Order Information Disclosure via IDOR |
4.1.9 – < 4.1.20 Fixed in 4.1.20 |
CVE-2026-13177 |
WPScan | |
| 8.2 High | Eventin | Broken Access Control Unauthenticated Account Creation via Waiting List Endpoint No login needed |
< 4.1.20 Fixed in 4.1.20 |
CVE-2026-13171 |
WPScan | |
| 6.5 Medium | Eventin | Information Disclosure Contributor+ Customer PII Disclosure via REST API |
< 4.1.20 Fixed in 4.1.20 |
CVE-2026-13168 |
WPScan | |
| 6.5 Medium | LearnPress | Information Disclosure Subscriber+ Sensitive Information Exposure via AI Assistant |
< 4.4.4 Fixed in 4.4.4 |
CVE-2026-12976 |
WPScan | |
| 8.1 High | Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect | Authentication Bypass Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback No login needed |
≤ 1.4.3 |
CVE-2026-18961 |
Wordfence | |
| 8.8 High | Frontend Admin by DynamiApps | Broken Access Control Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token |
≤ 3.29.9 |
CVE-2026-15606 |
Wordfence | |
| 8.1 High | GeoDirectory | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'post_type' Parameter via Query-String Bypass in geodir_save_post + geodir_delete_revision |
≤ 2.8.169 |
CVE-2026-19091 |
Wordfence | |
| 7.5 High | InstaWP Connect | Information Disclosure Unauthenticated Cryptographic Key Disclosure No login needed |
≤ 0.1.3.6 |
CVE-2026-13457 |
Wordfence | |
| 9.8 Critical | Formidable Digital Signatures | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Signature Field No login needed |
≤ 3.0.6 |
CVE-2026-16230 |
Wordfence | |
| 8.8 High | AcyMailing | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Account Takeover via Notification Template Update |
≤ 10.11.1 |
CVE-2026-15426 |
Wordfence | |
| 4.3 Medium | Ray Enterprise Translation | Broken Access Control Subscriber+ Language Addition and Deletion |
≤ 1.7.3 |
CVE-2026-14549 |
WPScan | |
| 6.5 Medium | Ray Enterprise Translation | Broken Access Control Subscriber+ Arbitrary API Token Update |
≤ 1.7.3 |
CVE-2026-14548 |
WPScan | |
| 6.4 Medium | Kirki - Freeform Page Builder, Website Builder & Customizer | Cross-Site Scripting Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_meta Shortcode |
≤ 6.2.0 |
CVE-2026-16974 |
Wordfence | |
| 6.5 Medium | sucuri-wordpress-plugin | Path Traversal Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php |
≤ 2.7.3 |
CVE-2026-73033 |
VulnCheck | |
| 5.4 Medium | WP Umbrella | Cross-Site Request Forgery No login needed |
2.24.2 – 2.26.2 Fixed in 2.27.0 |
CVE-2026-66642 |
Patchstack | |
| 9.8 Critical | Product Input Fields for WooCommerce | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
2.0.0 – < 2.0.2 Fixed in 2.0.2 |
CVE-2026-19089 |
WPScan | |
| 6.5 Medium | Copy & Delete Posts | Broken Access Control Authenticated Arbitrary Post Deletion via Missing Object-Level Authorization |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-19077 |
WPScan | |
| 5.3 Medium | Advanced Classifieds & Directory Pro | Information Disclosure Unauthenticated Non-Public Listing Custom Field Disclosure No login needed |
< 3.4.3 Fixed in 3.4.3 |
CVE-2026-19074 |
WPScan | |
| 8.8 High | CheckView | Authentication Bypass Administrator Account Creation via REST API Authentication Bypass No login needed |
2.0.29 – < 2.3.2 Fixed in 2.3.2 |
CVE-2026-18786 |
WPScan | |
| 4.3 Medium | FoodBoxBooker | Broken Access Control Subscriber+ Arbitrary User Profile Update |
< 1.0.8 Fixed in 1.0.8 |
CVE-2026-18200 |
WPScan | |
| 6.8 Medium | s2Member | Cross-Site Scripting Contributor+ Stored XSS via Shortcode |
< 260805 Fixed in 260805 |
CVE-2026-15047 |
WPScan | |
| 4.8 Medium | Salon Booking System – Free Version | Broken Access Control Free Version <= 10.30.33 - Unauthenticated Google Calendar Connection Hijack via OAuth Callback No login needed |
≤ 10.30.33 |
CVE-2026-17023 |
WPScan | |
| 8.8 High | Autopay / Blue Media for WooCommerce | Cross-Site Scripting Unauthenticated Stored XSS via CSS Editor No login needed |
< 5.0.1 Fixed in 5.0.1 |
CVE-2026-14293 |
WPScan | |
| 4.1 Medium | Vitepos | SQL Injection Admin+ SQL Injection via product-details-report |
< 3.6.0 Fixed in 3.6.0 |
CVE-2026-14238 |
WPScan | |
| 7.2 High | Vitepos | Privilege Escalation Outlet Manager+ Privilege Escalation |
3.4.0 – < 3.6.0, < 3.5.0 Fixed in 3.6.0 |
CVE-2026-14237 |
WPScan | |
| 3.8 Low | Amelia Pro | Information Disclosure Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR |
9.0 – < 9.7 Fixed in 9.7 |
CVE-2026-14211 |
WPScan | |
| 9.1 Critical | ProSolution WP Client | SQL Injection Unauthenticated Blind SQLi via 'jobID' Parameter No login needed |
< 2.0.6 Fixed in 2.0.6 |
CVE-2026-19053 |
WPScan | |
| 8.6 High | ProSolution WP Client | SQL Injection Unauthenticated SQLi and Plugin Data Deletion via 'removesite' Cookie No login needed |
< 2.0.9 Fixed in 2.0.9 |
CVE-2026-19049 |
WPScan | |
| 7.5 High | Salon Booking System – Free Version | Information Disclosure Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking Wizard No login needed |
< 10.30.34 Fixed in 10.30.34 |
CVE-2026-17022 |
WPScan | |
| 5.3 Medium | Salon Booking System – Free Version | Broken Access Control Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total Tampering No login needed |
< 10.30.34 Fixed in 10.30.34 |
CVE-2026-17021 |
WPScan | |
| 4.3 Medium | Salon Booking System – Free Version | Information Disclosure Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclosure |
≤ 10.31.0 |
CVE-2026-17020 |
WPScan | |
| 5.3 Medium | Pinpoint Booking System | Price Manipulation Unauthenticated Arbitrary Booking Price Manipulation No login needed |
≤ 2.9.9.7.1 |
CVE-2026-15229 |
WPScan | |
| 5.4 Medium | Block User Account | Authentication Bypass Subscriber+ Account Block Bypass via Application Passwords |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-18960 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.