WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,551–2,600 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 52 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Contact Form to Any API Plugin contact-form-to-any-api Information Disclosure Unauthenticated Sensitive File Disclosure via Predictable Filename No login needed < 3.0.7 Fixed in 3.0.7 CVE-2026-18946 WPScan
5.5 Medium RSS Aggregator by Feedzy Plugin feedzy-rss-feeds Broken Access Control Author+ Cross-User Import Job Manipulation and Post Deletion < 5.2.6 Fixed in 5.2.6 CVE-2026-18934 WPScan
8.8 High Squeeze Plugin squeeze Arbitrary File Upload Author+ Arbitrary File Upload < 1.7.12 Fixed in 1.7.12 CVE-2026-16985 WPScan
5.8 Medium Term Pages Plugin SQL Injection Unauthenticated SQL Injection via tp_lookup No login needed < 2.0.0 Fixed in 2.0.0 CVE-2026-16949 WPScan
5.4 Medium Hotel Booking Lite Plugin Broken Access Control Subscriber+ Customer Data Modification via IDOR < 6.2.3 Fixed in 6.2.3 CVE-2026-15238 WPScan
5.3 Medium Hotel Booking Lite Plugin Broken Access Control Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint No login needed < 6.2.3 Fixed in 6.2.3 CVE-2026-15237 WPScan
5.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions < 5.116.0 Fixed in 5.116.0 CVE-2026-14941 WPScan
5.3 Medium Podcast Player Plugin podcast-player Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed < 8.3.1 Fixed in 8.3.1 CVE-2026-14860 WPScan
7.5 High HT Contact Form Plugin ht-contactform Information Disclosure Unauthenticated Saved Form Draft Data Disclosure No login needed < 2.9.3 Fixed in 2.9.3 CVE-2026-14206 WPScan
4.8 Medium Advanced Excerpt Plugin advanced-excerpt Cross-Site Scripting Admin+ Stored XSS via Ellipsis Setting < 4.5 Fixed in 4.5 CVE-2026-13701 WPScan
8.1 High AutoNetTV Relay Plugin autonettv-relay Privilege Escalation Unauthenticated Privilege Escalation via Scheduled Sync Cron No login needed < 3.0.14 Fixed in 3.0.14 CVE-2026-13600 WPScan
7.2 High Eventin Plugin wp-event-solution Local File Inclusion Editor+ Local File Inclusion via speaker_template Setting < 4.1.20 Fixed in 4.1.20 CVE-2026-13170 WPScan
2.2 Low LearnPress Plugin learnpress Server-Side Request Forgery Instructor+ Server-Side Request Forgery via openai_apply_image_feature < 4.4.4 Fixed in 4.4.4 CVE-2026-12971 WPScan
4.9 Medium CubeWP Framework Plugin cubewp-framework Information Disclosure Contributor+ Arbitrary Post and User Meta Disclosure via IDOR ≤ 1.1.30 CVE-2026-17018 WPScan
5.4 Medium Saitama Addon Pack Plugin cc-addon-pack Cross-Site Scripting Contributor+ Stored XSS via Post Meta ≤ 1.0.8 CVE-2026-17010 WPScan
4.3 Medium Library Management System Plugin library-management-system SQL Injection Subscriber+ SQL Injection via Filter Value < 3.6.7 Fixed in 3.6.7 CVE-2026-18666 WPScan
7.5 High Login & Register Forms Plugin Information Disclosure Unauthenticated Registered User Email Address Disclosure via Lost Password Response No login needed 3.0.0 – < 4.0.2 Fixed in 4.0.2 CVE-2026-18470 WPScan
8.1 High Login & Register Forms Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset Code Brute Force No login needed 3.2.5 – < 4.0.2 Fixed in 4.0.2 CVE-2026-18469 WPScan
8.1 High Login & Register Forms Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header No login needed 3.2.5 – < 4.0.2 Fixed in 4.0.2 CVE-2026-18468 WPScan
3.7 Low Restore PayPal Standard for WooCommerce Plugin Price Manipulation Payment Bypass via PDT Underpayment No login needed ≤ 3.1.0 CVE-2026-17016 WPScan
5.3 Medium Restore PayPal Standard for WooCommerce Plugin Price Manipulation Payment Bypass via Unvalidated receiver_email No login needed ≤ 3.1.0 CVE-2026-17012 WPScan
8.1 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary Password Reset via Pro Forms No login needed < 3.1.8.8 Fixed in 3.1.8.8 CVE-2026-18030 WPScan
6.1 Medium JetEngine Plugin Cross-Site Scripting Unauthenticated Stored XSS via Form File Upload (SVG) No login needed < 3.8.13.1 Fixed in 3.8.13.1 CVE-2026-17019 WPScan
9.8 Critical Single Sign On For TNG Plugin single-sign-on-for-tng Authentication Bypass Unauthenticated Arbitrary Password Reset No login needed < 2.2.0 Fixed in 2.2.0 CVE-2026-16299 WPScan
9.8 Critical FoodBoxBooker Plugin foodboxbooker Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed < 1.0.7 Fixed in 1.0.7 CVE-2026-16298 WPScan
8.2 High Arvow AI SEO Writer Plugin journalist-ai Authentication Bypass Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling No login needed < 1.5.4 Fixed in 1.5.4 CVE-2026-16257 WPScan
7.5 High Bit File Manager Plugin Information Disclosure Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector No login needed < 6.9.1 Fixed in 6.9.1 CVE-2026-17542 WPScan
7.5 High Bit File Manager Plugin Information Disclosure Unauthenticated File Activity Log Disclosure No login needed < 6.9.1 Fixed in 6.9.1 CVE-2026-17541 WPScan
8.8 High Bit File Manager Plugin Path Traversal Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch < 6.9.1 Fixed in 6.9.1 CVE-2026-17540 WPScan
8.1 High CubeWP Framework Plugin cubewp-framework SQL Injection Subscriber+ SQL Injection via cubewp_remove_relation < 1.1.31 Fixed in 1.1.31 CVE-2026-17017 WPScan
6.1 Medium LWS Optimize Plugin lws-optimize Cross-Site Scripting Unauthenticated Stored XSS via Real User Monitoring No login needed < 4.1.2 Fixed in 4.1.2 CVE-2026-16032 WPScan
9.8 Critical InfiniteWP Client Plugin iwp-client Privilege Escalation Unauthenticated Administrator Account Takeover on Multisite No login needed < 1.13.6 Fixed in 1.13.6 CVE-2026-15038 WPScan
6.5 Medium Cancel Order & Request Woocommerce Plugin Information Disclosure Unauthenticated Order Content Disclosure via Reorder AJAX Actions No login needed < 1.3.4.34 Fixed in 1.3.4.34 CVE-2026-18603 WPScan
9.1 Critical WP Directory Kit Plugin wpdirectorykit SQL Injection Unauthenticated SQL Injection via 'field_search' Parameter No login needed 1.5.4 – < 1.5.5 Fixed in 1.5.5 CVE-2026-18473 WPScan
6.5 Medium WP Maps Pro Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed < 6.1.3 Fixed in 6.1.3 CVE-2026-18465 WPScan
7.5 High WP Maps Pro Plugin Denial of Service Unauthenticated Denial of Service No login needed < 6.1.3 Fixed in 6.1.3 CVE-2026-18464 WPScan
7.5 High WPC Order Tip for WooCommerce Plugin wpc-order-tip Information Disclosure Unauthenticated Order Data Disclosure No login needed < 3.3.1 Fixed in 3.3.1 CVE-2026-18357 WPScan
6.5 Medium Create by Mediavine Plugin Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed < 2.5.4 Fixed in 2.5.4 CVE-2026-18037 WPScan
7.5 High WP Data Access Plugin wp-data-access Information Disclosure Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass No login needed < 5.5.79 Fixed in 5.5.79 CVE-2026-18032 WPScan
8.6 High WordPress File Upload Plugin Arbitrary File Upload Unauthenticated SQL Injection via uniqueuploadid No login needed < 5.1.8 Fixed in 5.1.8 CVE-2026-17044 WPScan
5.3 Medium WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Deletion Unauthenticated Export ZIP File Deletion via delexportzips No login needed < 9.2.07.002 Fixed in 9.2.07.002 CVE-2026-17014 WPScan
3.8 Low Nexter Blocks Plugin the-plus-addons-for-block-editor Content Injection Contributor+ Stored CSS Injection < 5.0.2 Fixed in 5.0.2 CVE-2026-17011 WPScan
6.5 Medium Create by Mediavine Plugin Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed < 2.5.4 Fixed in 2.5.4 CVE-2026-16992 WPScan
7.5 High GeoDirectory Plugin geodirectory Information Disclosure Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint No login needed < 2.8.169 Fixed in 2.8.169 CVE-2026-16988 WPScan
4.3 Medium Solace Extra Plugin solace-extra Cross-Site Request Forgery Subscriber+ Post Meta Update via solace_update_sitebuilder_status < 1.6.1 Fixed in 1.6.1 CVE-2026-16965 WPScan
2.7 Low Slim SEO Plugin slim-seo Information Disclosure Contributor+ Arbitrary Post Meta Disclosure < 4.9.11 Fixed in 4.9.11 CVE-2026-16957 WPScan
9.8 Critical AI Copilot – Content Generator Plugin ai-copilot-content-generator Privilege Escalation Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route No login needed ≤ 1.5.6 CVE-2026-14526 Wordfence
5.0 Medium AI Engine Plugin ai-engine Path Traversal Subscriber+ Arbitrary File Read via Audio Transcription < 3.6.6 Fixed in 3.6.6 CVE-2026-16955 WPScan
4.8 Medium AI Engine Plugin ai-engine Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed < 3.6.4 Fixed in 3.6.4 CVE-2026-16953 WPScan
8.1 High Solace Extra Plugin solace-extra Broken Access Control Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure < 1.6.1 Fixed in 1.6.1 CVE-2026-16948 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only