WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,551–2,600 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 52 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High ColorFolio - Freelance Designer Theme colorfolio PHP Object Injection Freelance Designer WordPress Theme theme <= 1.3 - Deserialization of untrusted data No login needed ≤ 1.3 CVE-2026-27096 Patchstack
7.1 High WP eMember Plugin wp-emember Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ v10.2.2 CVE-2026-28073 Patchstack
7.2 High SlimStat Analytics Plugin wp-slimstat Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'fh' No login needed ≤ 5.3.5 CVE-2026-1238 Wordfence
8.8 High Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery Plugin nextgen-gallery Local File Inclusion NextGEN Gallery <= 4.0.4 - Authenticated (Author+) Local File Inclusion ≤ 4.0.4 CVE-2026-1463 Wordfence
8.2 High KiviCare Plugin kivicare-clinic-management-system Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via Setup Wizard No login needed ≤ 4.1.2 CVE-2026-2992 Wordfence
7.2 High Post SMTP Plugin post-smtp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'event_type' No login needed ≤ 3.8.0 CVE-2026-3090 Wordfence
7.3 High KiviCare – Clinic & Patient Management System (EHR) Plugin kivicare-clinic-management-system Authentication Bypass Clinic & Patient Management System (EHR) <= 4.1.2 - Unauthenticated Authentication Bypass via Social Login Token No login needed ≤ 4.1.2 CVE-2026-2991 Wordfence
7.5 High WowStore – Store Builder & Product Blocks for WooCommerce Plugin product-blocks SQL Injection Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter No login needed ≤ 4.4.3 CVE-2026-2579 Wordfence
7.1 High Flexmls® IDX Plugin flexmls-idx Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.15.9 Fixed in 3.15.10 CVE-2026-25369 Patchstack
7.5 High NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id No login needed ≤ 9.1.9 CVE-2026-1947 Wordfence
7.6 High UpsellWP Plugin checkout-upsell-and-order-bumps SQL Injection ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-32459 Patchstack
7.6 High WOLF Plugin bulk-editor SQL Injection ≤ 1.0.8.7 Fixed in 1.0.9 CVE-2026-32458 Patchstack
8.5 High CP Contact Form with Paypal Plugin cp-contact-form-with-paypal SQL Injection ≤ 1.3.61 Fixed in 1.3.62 CVE-2026-32433 Patchstack
7.5 High Medilazar Core Plugin medilazar-core Local File Inclusion ≤ 1.4.7 Fixed in 1.4.7 CVE-2026-32426 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.8.13 Fixed in 5.8.14 CVE-2026-32422 Patchstack
7.6 High Meow Gallery Plugin meow-gallery SQL Injection ≤ 5.4.4 Fixed in 5.4.5 CVE-2026-32418 Patchstack
7.2 High Advanced Woo Labels Plugin advanced-woo-labels Remote Code Execution ≤ 2.36 Fixed in 2.37 CVE-2026-32414 Patchstack
7.2 High Client Invoicing by Sprout Invoices Plugin sprout-invoices Local File Inclusion ≤ 20.8.9 Fixed in 20.8.10 CVE-2026-32401 Patchstack
7.5 High Boldman Theme boldman Local File Inclusion ≤ 7.7 Fixed in 7.8 CVE-2026-32400 Patchstack
8.5 High Media LIbrary Assistant Plugin media-library-assistant SQL Injection ≤ 3.32 Fixed in 3.33 CVE-2026-32399 Patchstack
7.5 High Greenly Theme Addons Plugin greenly-addons Local File Inclusion ≤ 8.2 Fixed in 8.2 CVE-2026-32393 Patchstack
7.5 High Greenly Theme greenly Local File Inclusion ≤ 8.1 Fixed in 8.2 CVE-2026-32392 Patchstack
7.5 High WpBookingly Plugin service-booking-manager Local File Inclusion ≤ 1.2.9 Fixed in 1.3.0 CVE-2026-32384 Patchstack
7.5 High Medilink-Core Plugin medilink-core Local File Inclusion ≤ 2.0.7 Fixed in 2.0.7 CVE-2026-32369 Patchstack
8.5 High Geo to Lat Plugin geo-to-lat SQL Injection ≤ 1.0.19 Fixed in 1.1 CVE-2026-32368 Patchstack
8.5 High Collapsing Categories Plugin collapsing-categories SQL Injection ≤ 3.0.9 Fixed in 3.0.12 CVE-2026-32366 Patchstack
8.5 High Collapsing Archives Plugin collapsing-archives SQL Injection ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-32365 Patchstack
7.5 High Turbo Manager Plugin turbo-manager Local File Inclusion ≤ 4.0.8 Fixed in 4.0.8 CVE-2026-32364 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 10.14.15 Fixed in 10.14.16 CVE-2026-32358 Patchstack
8.8 High JetEngine Plugin jet-engine PHP Object Injection Deserialization of untrusted data ≤ 3.8.4.1 Fixed in 3.8.4.1 CVE-2026-32355 Patchstack
8.5 High Fox LMS Plugin fox-lms SQL Injection ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2026-31922 Patchstack
8.5 High WP ERP Plugin erp SQL Injection ≤ 1.16.10 Fixed in 1.16.11 CVE-2026-31917 Patchstack
7.5 High Formidable Forms Plugin formidable Broken Access Control Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse No login needed ≤ 6.28 CVE-2026-2890 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint No login needed ≤ 1.6.9.29 CVE-2026-3045 Wordfence
8.1 High wpDiscuz Plugin wpdiscuz Cross-Site Request Forgery Destructive GET Action Deletes All Comments by Email No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22202 VulnCheck
8.1 High wpDiscuz Plugin wpdiscuz SQL Injection SQL Injection in getAllSubscriptions() No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22193 VulnCheck
7.5 High wpDiscuz Plugin wpdiscuz Denial of Service Unauthenticated Email Notification Flood via wpdCheckNotificationType No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22182 VulnCheck
7.5 High My Sticky Bar Plugin mystickymenu SQL Injection Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action No login needed ≤ 2.8.6 CVE-2026-3657 Wordfence
7.5 High JetBooking Plugin SQL Injection Unauthenticated SQL Injection via 'check_in_date' Parameter No login needed ≤ 4.0.3 CVE-2026-3496 Wordfence
7.2 High Name Directory Plugin name-directory Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'name_directory_name' No login needed ≤ 1.32.1 CVE-2026-3178 Wordfence
7.2 High Checkout Field Editor (Checkout Manager) for WooCommerce Plugin woo-checkout-field-editor-pro Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field No login needed ≤ 2.1.7 CVE-2026-3231 Wordfence
8.8 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation 8.0.0 – 9.0.2 CVE-2026-1992 Wordfence
8.8 High ExactMetrics Plugin google-analytics-dashboard-for-wp Privilege Escalation Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update 7.1.0 – 9.0.2 CVE-2026-1993 Wordfence
7.2 High Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2026-1454 Wordfence
7.5 High Appointment Booking Calendar Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via 'append_where_sql' Parameter No login needed ≤ 1.6.9.27 CVE-2026-1708 Wordfence
8.1 High Divi Booster Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed < 5.0.2 Fixed in 5.0.2 CVE-2026-2626 WPScan
7.1 High DukaPress Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 3.2.4 CVE-2026-2466 WPScan
7.5 High WP Maps Plugin wp-google-map-plugin SQL Injection Unauthenticated SQL Injection via 'location_id' Parameter No login needed ≤ 4.9.1 CVE-2026-3222 Wordfence
8.8 High Royal Addons for Elementor Plugin royal-elementor-addons Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via main.php Upload Bypass ≤ 1.7.1049 CVE-2025-13067 Wordfence
7.5 High Ally – Web Accessibility & Usability Plugin pojo-accessibility SQL Injection Web Accessibility & Usability <= 4.0.3 - Unauthenticated SQL Injection via URL Path No login needed ≤ 4.0.3 CVE-2026-2413 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only