WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 2,551–2,600 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Contact Form to Any API | Information Disclosure Unauthenticated Sensitive File Disclosure via Predictable Filename No login needed |
< 3.0.7 Fixed in 3.0.7 |
CVE-2026-18946 |
WPScan | |
| 5.5 Medium | RSS Aggregator by Feedzy | Broken Access Control Author+ Cross-User Import Job Manipulation and Post Deletion |
< 5.2.6 Fixed in 5.2.6 |
CVE-2026-18934 |
WPScan | |
| 8.8 High | Squeeze | Arbitrary File Upload Author+ Arbitrary File Upload |
< 1.7.12 Fixed in 1.7.12 |
CVE-2026-16985 |
WPScan | |
| 5.8 Medium | Term Pages | SQL Injection Unauthenticated SQL Injection via tp_lookup No login needed |
< 2.0.0 Fixed in 2.0.0 |
CVE-2026-16949 |
WPScan | |
| 5.4 Medium | Hotel Booking Lite | Broken Access Control Subscriber+ Customer Data Modification via IDOR |
< 6.2.3 Fixed in 6.2.3 |
CVE-2026-15238 |
WPScan | |
| 5.3 Medium | Hotel Booking Lite | Broken Access Control Unauthenticated Payment Record Creation via Checkout Payments REST Endpoint No login needed |
< 6.2.3 Fixed in 6.2.3 |
CVE-2026-15237 |
WPScan | |
| 5.4 Medium | Customer Reviews for WooCommerce | Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions |
< 5.116.0 Fixed in 5.116.0 |
CVE-2026-14941 |
WPScan | |
| 5.3 Medium | Podcast Player | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
< 8.3.1 Fixed in 8.3.1 |
CVE-2026-14860 |
WPScan | |
| 7.5 High | HT Contact Form | Information Disclosure Unauthenticated Saved Form Draft Data Disclosure No login needed |
< 2.9.3 Fixed in 2.9.3 |
CVE-2026-14206 |
WPScan | |
| 4.8 Medium | Advanced Excerpt | Cross-Site Scripting Admin+ Stored XSS via Ellipsis Setting |
< 4.5 Fixed in 4.5 |
CVE-2026-13701 |
WPScan | |
| 8.1 High | AutoNetTV Relay | Privilege Escalation Unauthenticated Privilege Escalation via Scheduled Sync Cron No login needed |
< 3.0.14 Fixed in 3.0.14 |
CVE-2026-13600 |
WPScan | |
| 7.2 High | Eventin | Local File Inclusion Editor+ Local File Inclusion via speaker_template Setting |
< 4.1.20 Fixed in 4.1.20 |
CVE-2026-13170 |
WPScan | |
| 2.2 Low | LearnPress | Server-Side Request Forgery Instructor+ Server-Side Request Forgery via openai_apply_image_feature |
< 4.4.4 Fixed in 4.4.4 |
CVE-2026-12971 |
WPScan | |
| 4.9 Medium | CubeWP Framework | Information Disclosure Contributor+ Arbitrary Post and User Meta Disclosure via IDOR |
≤ 1.1.30 |
CVE-2026-17018 |
WPScan | |
| 5.4 Medium | Saitama Addon Pack | Cross-Site Scripting Contributor+ Stored XSS via Post Meta |
≤ 1.0.8 |
CVE-2026-17010 |
WPScan | |
| 4.3 Medium | Library Management System | SQL Injection Subscriber+ SQL Injection via Filter Value |
< 3.6.7 Fixed in 3.6.7 |
CVE-2026-18666 |
WPScan | |
| 7.5 High | Login & Register Forms | Information Disclosure Unauthenticated Registered User Email Address Disclosure via Lost Password Response No login needed |
3.0.0 – < 4.0.2 Fixed in 4.0.2 |
CVE-2026-18470 |
WPScan | |
| 8.1 High | Login & Register Forms | Privilege Escalation Unauthenticated Account Takeover via Password Reset Code Brute Force No login needed |
3.2.5 – < 4.0.2 Fixed in 4.0.2 |
CVE-2026-18469 |
WPScan | |
| 8.1 High | Login & Register Forms | Privilege Escalation Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header No login needed |
3.2.5 – < 4.0.2 Fixed in 4.0.2 |
CVE-2026-18468 |
WPScan | |
| 3.7 Low | Restore PayPal Standard for WooCommerce | Price Manipulation Payment Bypass via PDT Underpayment No login needed |
≤ 3.1.0 |
CVE-2026-17016 |
WPScan | |
| 5.3 Medium | Restore PayPal Standard for WooCommerce | Price Manipulation Payment Bypass via Unvalidated receiver_email No login needed |
≤ 3.1.0 |
CVE-2026-17012 |
WPScan | |
| 8.1 High | Bricksforge | Broken Access Control Unauthenticated Arbitrary Password Reset via Pro Forms No login needed |
< 3.1.8.8 Fixed in 3.1.8.8 |
CVE-2026-18030 |
WPScan | |
| 6.1 Medium | JetEngine | Cross-Site Scripting Unauthenticated Stored XSS via Form File Upload (SVG) No login needed |
< 3.8.13.1 Fixed in 3.8.13.1 |
CVE-2026-17019 |
WPScan | |
| 9.8 Critical | Single Sign On For TNG | Authentication Bypass Unauthenticated Arbitrary Password Reset No login needed |
< 2.2.0 Fixed in 2.2.0 |
CVE-2026-16299 |
WPScan | |
| 9.8 Critical | FoodBoxBooker | Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed |
< 1.0.7 Fixed in 1.0.7 |
CVE-2026-16298 |
WPScan | |
| 8.2 High | Arvow AI SEO Writer | Authentication Bypass Unauthenticated Arbitrary Post Creation via Webhook Secret Type-Juggling No login needed |
< 1.5.4 Fixed in 1.5.4 |
CVE-2026-16257 |
WPScan | |
| 7.5 High | Bit File Manager | Information Disclosure Subscriber+ Sensitive Data Disclosure via bitapps_fm_connector No login needed |
< 6.9.1 Fixed in 6.9.1 |
CVE-2026-17542 |
WPScan | |
| 7.5 High | Bit File Manager | Information Disclosure Unauthenticated File Activity Log Disclosure No login needed |
< 6.9.1 Fixed in 6.9.1 |
CVE-2026-17541 |
WPScan | |
| 8.8 High | Bit File Manager | Path Traversal Subscriber+ Arbitrary File Read and Deletion via Connector Command Request-Source Mismatch |
< 6.9.1 Fixed in 6.9.1 |
CVE-2026-17540 |
WPScan | |
| 8.1 High | CubeWP Framework | SQL Injection Subscriber+ SQL Injection via cubewp_remove_relation |
< 1.1.31 Fixed in 1.1.31 |
CVE-2026-17017 |
WPScan | |
| 6.1 Medium | LWS Optimize | Cross-Site Scripting Unauthenticated Stored XSS via Real User Monitoring No login needed |
< 4.1.2 Fixed in 4.1.2 |
CVE-2026-16032 |
WPScan | |
| 9.8 Critical | InfiniteWP Client | Privilege Escalation Unauthenticated Administrator Account Takeover on Multisite No login needed |
< 1.13.6 Fixed in 1.13.6 |
CVE-2026-15038 |
WPScan | |
| 6.5 Medium | Cancel Order & Request Woocommerce | Information Disclosure Unauthenticated Order Content Disclosure via Reorder AJAX Actions No login needed |
< 1.3.4.34 Fixed in 1.3.4.34 |
CVE-2026-18603 |
WPScan | |
| 9.1 Critical | WP Directory Kit | SQL Injection Unauthenticated SQL Injection via 'field_search' Parameter No login needed |
1.5.4 – < 1.5.5 Fixed in 1.5.5 |
CVE-2026-18473 |
WPScan | |
| 6.5 Medium | WP Maps Pro | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
< 6.1.3 Fixed in 6.1.3 |
CVE-2026-18465 |
WPScan | |
| 7.5 High | WP Maps Pro | Denial of Service Unauthenticated Denial of Service No login needed |
< 6.1.3 Fixed in 6.1.3 |
CVE-2026-18464 |
WPScan | |
| 7.5 High | WPC Order Tip for WooCommerce | Information Disclosure Unauthenticated Order Data Disclosure No login needed |
< 3.3.1 Fixed in 3.3.1 |
CVE-2026-18357 |
WPScan | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-18037 |
WPScan | |
| 7.5 High | WP Data Access | Information Disclosure Unauthenticated Sensitive Data Disclosure via Autocomplete Column Authorization Bypass No login needed |
< 5.5.79 Fixed in 5.5.79 |
CVE-2026-18032 |
WPScan | |
| 8.6 High | WordPress File Upload | Arbitrary File Upload Unauthenticated SQL Injection via uniqueuploadid No login needed |
< 5.1.8 Fixed in 5.1.8 |
CVE-2026-17044 |
WPScan | |
| 5.3 Medium | WP Photo Album Plus | Arbitrary File Deletion Unauthenticated Export ZIP File Deletion via delexportzips No login needed |
< 9.2.07.002 Fixed in 9.2.07.002 |
CVE-2026-17014 |
WPScan | |
| 3.8 Low | Nexter Blocks | Content Injection Contributor+ Stored CSS Injection |
< 5.0.2 Fixed in 5.0.2 |
CVE-2026-17011 |
WPScan | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-16992 |
WPScan | |
| 7.5 High | GeoDirectory | Information Disclosure Unauthenticated Pending/Draft Listing Disclosure via markers REST Endpoint No login needed |
< 2.8.169 Fixed in 2.8.169 |
CVE-2026-16988 |
WPScan | |
| 4.3 Medium | Solace Extra | Cross-Site Request Forgery Subscriber+ Post Meta Update via solace_update_sitebuilder_status |
< 1.6.1 Fixed in 1.6.1 |
CVE-2026-16965 |
WPScan | |
| 2.7 Low | Slim SEO | Information Disclosure Contributor+ Arbitrary Post Meta Disclosure |
< 4.9.11 Fixed in 4.9.11 |
CVE-2026-16957 |
WPScan | |
| 9.8 Critical | AI Copilot – Content Generator | Privilege Escalation Content Generator <= 1.5.6 - Unauthenticated Privilege Escalation via Custom Workflow Route No login needed |
≤ 1.5.6 |
CVE-2026-14526 |
Wordfence | |
| 5.0 Medium | AI Engine | Path Traversal Subscriber+ Arbitrary File Read via Audio Transcription |
< 3.6.6 Fixed in 3.6.6 |
CVE-2026-16955 |
WPScan | |
| 4.8 Medium | AI Engine | Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed |
< 3.6.4 Fixed in 3.6.4 |
CVE-2026-16953 |
WPScan | |
| 8.1 High | Solace Extra | Broken Access Control Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure |
< 1.6.1 Fixed in 1.6.1 |
CVE-2026-16948 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.