WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 2,601–2,650 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Download Monitor | Broken Access Control Unauthenticated Download Log Injection No login needed |
< 5.2.6 Fixed in 5.2.6 |
CVE-2026-16608 |
WPScan | |
| 6.5 Medium | WP Directory Kit | Information Disclosure Subscriber+ User and Unpublished Listing Disclosure |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16595 |
WPScan | |
| 7.5 High | WP Directory Kit | Information Disclosure Subscriber+ Plugin Settings and API Key Disclosure No login needed |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16594 |
WPScan | |
| 6.5 Medium | WP Directory Kit | Information Disclosure Subscriber+ Contact Message and User Data Disclosure |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16590 |
WPScan | |
| 7.7 High | WP Directory Kit | SQL Injection Subscriber+ SQL Injection via data_fields_list Parameter |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-16589 |
WPScan | |
| 7.5 High | Admin Safety Guard | Information Disclosure Unauthenticated User Data Disclosure via 2fa/app/users REST Route No login needed |
1.2.7 – < 1.4.0 Fixed in 1.4.0 |
CVE-2026-16578 |
WPScan | |
| 5.4 Medium | Dokan | Broken Access Control Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint |
< 5.0.11 Fixed in 5.0.11 |
CVE-2026-16574 |
WPScan | |
| 6.5 Medium | WP Statistics | Information Disclosure Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers |
< 14.16.10 Fixed in 14.16.10 |
CVE-2026-16562 |
WPScan | |
| 6.8 Medium | YMC Filter | Cross-Site Scripting Author+ Stored XSS via SVG Icon Upload |
< 3.12.9 Fixed in 3.12.9 |
CVE-2026-16559 |
WPScan | |
| 5.4 Medium | YMC Filter | Cross-Site Scripting Contributor+ Stored XSS via Layout Builder Schema |
3.6.0 – < 3.12.8 Fixed in 3.12.8 |
CVE-2026-16558 |
WPScan | |
| 6.1 Medium | Link Library | Cross-Site Scripting Reflected XSS via Thumbs-Rating likelabel No login needed |
< 7.9.4 Fixed in 7.9.4 |
CVE-2026-16535 |
WPScan | |
| 5.3 Medium | Appointment Hour Booking | Price Manipulation Unauthenticated Booking Price Manipulation via tcost Parameter No login needed |
< 1.5.88 Fixed in 1.5.88 |
CVE-2026-16282 |
WPScan | |
| 4.8 Medium | Newsletters | Authentication Bypass Unauthenticated API Authentication Bypass via Type Juggling No login needed |
< 4.16 Fixed in 4.16 |
CVE-2026-16269 |
WPScan | |
| 8.1 High | Newsletters | PHP Object Injection Unauthenticated PHP Object Injection via Date Form Field No login needed |
< 4.16 Fixed in 4.16 |
CVE-2026-16267 |
WPScan | |
| 6.4 Medium | Easy Accordion | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute |
≤ 3.1.8 |
CVE-2026-18988 |
Wordfence | |
| 8.9 High | WordPress | Cross-Site Scripting WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible… No login needed | Not stated | CVE-2026-64638 |
hackerone | |
| 6.5 Medium | code-embed | Cross-Site Scripting Contributor Stored Cross-Site Scripting via Remote URL Embed |
< 2.6.1 |
CVE-2026-48093 |
GitHub_M | |
| 5.3 Medium | shareopenly | Cross-Site Scripting ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output No login needed |
< 1.2.1 |
CVE-2026-48094 |
GitHub_M | |
| 5.3 Medium | Simple CAPTCHA with Cloudflare Turnstile | Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed |
< 1.42.0 Fixed in 1.42.0 |
CVE-2026-15239 |
WPScan | |
| 5.9 Medium | Subscriptions for WooCommerce | Price Manipulation Payment Bypass via Attacker-Supplied PayPal Capture Token No login needed |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15211 |
WPScan | |
| 5.3 Medium | WP Events Manager | Price Manipulation Unauthenticated Payment Bypass and Booking Status Update via IDOR No login needed |
< 2.2.5 Fixed in 2.2.5 |
CVE-2026-15148 |
WPScan | |
| 6.5 Medium | WP Maps | Denial of Service Subscriber+ Denial of Service |
< 4.9.7 Fixed in 4.9.7 |
CVE-2026-16265 |
WPScan | |
| 8.8 High | WP Maps | Local File Inclusion Subscriber+ Local File Inclusion |
< 4.9.7 Fixed in 4.9.7 |
CVE-2026-16263 |
WPScan | |
| 7.5 High | Estatik | Cross-Site Request Forgery Login CSRF No login needed |
< 4.3.3 Fixed in 4.3.3 |
CVE-2026-16262 |
WPScan | |
| 9.8 Critical | Ajax Search Lite | PHP Object Injection Unauthenticated PHP Object Injection via Search Statistics REST Endpoint No login needed |
< 4.14.5 Fixed in 4.14.5 |
CVE-2026-16258 |
WPScan | |
| 7.5 High | MStore API | Broken Access Control Unauthenticated Product Review Creation No login needed |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16041 |
WPScan | |
| 6.5 Medium | MStore API | Information Disclosure Subscriber+ Order and Customer PII Disclosure via IDOR |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16039 |
WPScan | |
| 9.1 Critical | MStore API | Price Manipulation Unauthenticated Payment Bypass via Multiple Payment Gateways No login needed |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16038 |
WPScan | |
| 8.1 High | MStore API | Privilege Escalation Unauthenticated Account Takeover via Firebase Phone Authentication No login needed |
< 4.21.0 Fixed in 4.21.0 |
CVE-2026-16030 |
WPScan | |
| 5.4 Medium | Meow Gallery | Cross-Site Scripting Author+ Stored XSS via Attachment Alt-Text |
< 5.5.2 Fixed in 5.5.2 |
CVE-2026-15386 |
WPScan | |
| 8.1 High | Content Views | SQL Injection Subscriber+ SQL Injection via preview_request |
< 4.5 Fixed in 4.5 |
CVE-2026-15361 |
WPScan | |
| 6.5 Medium | Templately | Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2026-15359 |
WPScan | |
| 5.4 Medium | BNE Testimonials | Cross-Site Scripting Contributor+ Stored XSS via Slider Shortcode |
< 2.0.8.2 Fixed in 2.0.8.2 |
CVE-2026-15245 |
WPScan | |
| 8.8 High | Subscriptions for WooCommerce | Remote Code Execution Shop Manager+ Arbitrary Plugin Installation |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15215 |
WPScan | |
| 4.3 Medium | Subscriptions for WooCommerce | Information Disclosure Subscriber+ Subscription Detail Disclosure via IDOR |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15214 |
WPScan | |
| 6.1 Medium | wpDiscuz | Cross-Site Scripting Unauthenticated Stored XSS via Image URL Conversion No login needed |
< 7.6.60 Fixed in 7.6.60 |
CVE-2026-15032 |
WPScan | |
| 7.5 High | Password Protected | Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed |
2.6.8 – < 2.8.4 Fixed in 2.8.4 |
CVE-2026-14943 |
WPScan | |
| 6.1 Medium | Subscribe2 | Cross-Site Scripting Reflected XSS via email Parameter No login needed |
< 10.46 Fixed in 10.46 |
CVE-2026-14331 |
WPScan | |
| 9.8 Critical | WP Events Manager | Price Manipulation Subscriber+ Payment Bypass via 'qty' Parameter No login needed |
< 2.2.5 Fixed in 2.2.5 |
CVE-2026-14205 |
WPScan | |
| 9.8 Critical | TrueBooker | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' No login needed |
≤ 1.2.3 |
CVE-2026-14364 |
Wordfence | |
| 6.4 Medium | Ultra Addons for Contact Form 7 | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes |
≤ 3.5.43 |
CVE-2026-12801 |
Wordfence | |
| 6.5 Medium | Stream | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API |
≤ 4.2.0 |
CVE-2026-11907 |
Wordfence | |
| 9.8 Critical | TrueBooker | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' No login needed |
≤ 1.2.3 |
CVE-2026-14365 |
Wordfence | |
| 2.7 Low | Content Protector (Passster) | Information Disclosure Contributor+ Protected Content Disclosure via Core REST API |
< 4.3.7 Fixed in 4.3.7 |
CVE-2025-15674 |
WPScan | |
| 7.5 High | WPC Name Your Price for WooCommerce | Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed |
< 2.2.5 Fixed in 2.2.5 |
CVE-2026-16620 |
WPScan | |
| 7.5 High | miniOrange 2FA | Authentication Bypass miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts |
< 6.2.8 Fixed in 6.2.8 |
CVE-2026-16619 |
WPScan | |
| 5.3 Medium | Event Booking Manager for WooCommerce (Pro) | Price Manipulation Unauthenticated Payment Bypass via Client-Controlled Ticket Price No login needed |
< 5.0.3 Fixed in 5.0.3 |
CVE-2026-16067 |
WPScan | |
| 4.8 Medium | Ninja Forms | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default No login needed |
< 3.14.10 Fixed in 3.14.10 |
CVE-2026-15256 |
WPScan | |
| 5.3 Medium | Security Optimizer – The All-In-One Protection | Other The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password No login needed |
1.5.8 – < 1.6.5 Fixed in 1.6.5 |
CVE-2026-13342 |
WPScan | |
| 5.3 Medium | RegistrationMagic | Price Manipulation Unauthenticated Payment Bypass via Amount-Blind PayPal Verification No login needed |
< 6.0.9.5 Fixed in 6.0.9.5 |
CVE-2026-15208 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.