WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,601–2,650 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 53 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Download Monitor Plugin download-monitor Broken Access Control Unauthenticated Download Log Injection No login needed < 5.2.6 Fixed in 5.2.6 CVE-2026-16608 WPScan
6.5 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Subscriber+ User and Unpublished Listing Disclosure < 1.5.5 Fixed in 1.5.5 CVE-2026-16595 WPScan
7.5 High WP Directory Kit Plugin wpdirectorykit Information Disclosure Subscriber+ Plugin Settings and API Key Disclosure No login needed < 1.5.5 Fixed in 1.5.5 CVE-2026-16594 WPScan
6.5 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Subscriber+ Contact Message and User Data Disclosure < 1.5.5 Fixed in 1.5.5 CVE-2026-16590 WPScan
7.7 High WP Directory Kit Plugin wpdirectorykit SQL Injection Subscriber+ SQL Injection via data_fields_list Parameter < 1.5.5 Fixed in 1.5.5 CVE-2026-16589 WPScan
7.5 High Admin Safety Guard Plugin Information Disclosure Unauthenticated User Data Disclosure via 2fa/app/users REST Route No login needed 1.2.7 – < 1.4.0 Fixed in 1.4.0 CVE-2026-16578 WPScan
5.4 Medium Dokan Plugin Broken Access Control Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16574 WPScan
6.5 Medium WP Statistics Plugin wp-statistics Information Disclosure Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers < 14.16.10 Fixed in 14.16.10 CVE-2026-16562 WPScan
6.8 Medium YMC Filter Plugin ymc-smart-filter Cross-Site Scripting Author+ Stored XSS via SVG Icon Upload < 3.12.9 Fixed in 3.12.9 CVE-2026-16559 WPScan
5.4 Medium YMC Filter Plugin ymc-smart-filter Cross-Site Scripting Contributor+ Stored XSS via Layout Builder Schema 3.6.0 – < 3.12.8 Fixed in 3.12.8 CVE-2026-16558 WPScan
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected XSS via Thumbs-Rating likelabel No login needed < 7.9.4 Fixed in 7.9.4 CVE-2026-16535 WPScan
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Price Manipulation Unauthenticated Booking Price Manipulation via tcost Parameter No login needed < 1.5.88 Fixed in 1.5.88 CVE-2026-16282 WPScan
4.8 Medium Newsletters Plugin newsletters-lite Authentication Bypass Unauthenticated API Authentication Bypass via Type Juggling No login needed < 4.16 Fixed in 4.16 CVE-2026-16269 WPScan
8.1 High Newsletters Plugin newsletters-lite PHP Object Injection Unauthenticated PHP Object Injection via Date Form Field No login needed < 4.16 Fixed in 4.16 CVE-2026-16267 WPScan
6.4 Medium Easy Accordion Plugin easy-accordion-free Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute ≤ 3.1.8 CVE-2026-18988 Wordfence
8.9 High WordPress Core Cross-Site Scripting WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible… No login needed Not stated CVE-2026-64638 hackerone
6.5 Medium code-embed Plugin Cross-Site Scripting Contributor Stored Cross-Site Scripting via Remote URL Embed < 2.6.1 CVE-2026-48093 GitHub_M
5.3 Medium shareopenly Plugin shareopenly Cross-Site Scripting ShareOpenly has Cross-Site Scripting (XSS) via Missing esc_url() on Shared URL in Content Output No login needed < 1.2.1 CVE-2026-48094 GitHub_M
5.3 Medium Simple CAPTCHA with Cloudflare Turnstile Plugin simple-cloudflare-turnstile Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed < 1.42.0 Fixed in 1.42.0 CVE-2026-15239 WPScan
5.9 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Price Manipulation Payment Bypass via Attacker-Supplied PayPal Capture Token No login needed < 2.0.1 Fixed in 2.0.1 CVE-2026-15211 WPScan
5.3 Medium WP Events Manager Plugin wp-events-manager Price Manipulation Unauthenticated Payment Bypass and Booking Status Update via IDOR No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-15148 WPScan
6.5 Medium WP Maps Plugin wp-google-map-plugin Denial of Service Subscriber+ Denial of Service < 4.9.7 Fixed in 4.9.7 CVE-2026-16265 WPScan
8.8 High WP Maps Plugin wp-google-map-plugin Local File Inclusion Subscriber+ Local File Inclusion < 4.9.7 Fixed in 4.9.7 CVE-2026-16263 WPScan
7.5 High Estatik Plugin Cross-Site Request Forgery Login CSRF No login needed < 4.3.3 Fixed in 4.3.3 CVE-2026-16262 WPScan
9.8 Critical Ajax Search Lite Plugin ajax-search-lite PHP Object Injection Unauthenticated PHP Object Injection via Search Statistics REST Endpoint No login needed < 4.14.5 Fixed in 4.14.5 CVE-2026-16258 WPScan
7.5 High MStore API Plugin mstore-api Broken Access Control Unauthenticated Product Review Creation No login needed < 4.21.0 Fixed in 4.21.0 CVE-2026-16041 WPScan
6.5 Medium MStore API Plugin mstore-api Information Disclosure Subscriber+ Order and Customer PII Disclosure via IDOR < 4.21.0 Fixed in 4.21.0 CVE-2026-16039 WPScan
9.1 Critical MStore API Plugin mstore-api Price Manipulation Unauthenticated Payment Bypass via Multiple Payment Gateways No login needed < 4.21.0 Fixed in 4.21.0 CVE-2026-16038 WPScan
8.1 High MStore API Plugin mstore-api Privilege Escalation Unauthenticated Account Takeover via Firebase Phone Authentication No login needed < 4.21.0 Fixed in 4.21.0 CVE-2026-16030 WPScan
5.4 Medium Meow Gallery Plugin meow-gallery Cross-Site Scripting Author+ Stored XSS via Attachment Alt-Text < 5.5.2 Fixed in 5.5.2 CVE-2026-15386 WPScan
8.1 High Content Views Plugin content-views-query-and-display-post-page SQL Injection Subscriber+ SQL Injection via preview_request < 4.5 Fixed in 4.5 CVE-2026-15361 WPScan
6.5 Medium Templately Plugin templately Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed < 3.7.1 Fixed in 3.7.1 CVE-2026-15359 WPScan
5.4 Medium BNE Testimonials Plugin bne-testimonials Cross-Site Scripting Contributor+ Stored XSS via Slider Shortcode < 2.0.8.2 Fixed in 2.0.8.2 CVE-2026-15245 WPScan
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Remote Code Execution Shop Manager+ Arbitrary Plugin Installation < 2.0.1 Fixed in 2.0.1 CVE-2026-15215 WPScan
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Information Disclosure Subscriber+ Subscription Detail Disclosure via IDOR < 2.0.1 Fixed in 2.0.1 CVE-2026-15214 WPScan
6.1 Medium wpDiscuz Plugin Cross-Site Scripting Unauthenticated Stored XSS via Image URL Conversion No login needed < 7.6.60 Fixed in 7.6.60 CVE-2026-15032 WPScan
7.5 High Password Protected Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed 2.6.8 – < 2.8.4 Fixed in 2.8.4 CVE-2026-14943 WPScan
6.1 Medium Subscribe2 Plugin subscribe2 Cross-Site Scripting Reflected XSS via email Parameter No login needed < 10.46 Fixed in 10.46 CVE-2026-14331 WPScan
9.8 Critical WP Events Manager Plugin wp-events-manager Price Manipulation Subscriber+ Payment Bypass via 'qty' Parameter No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-14205 WPScan
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary Password Reset via 'tbab-userid' No login needed ≤ 1.2.3 CVE-2026-14364 Wordfence
6.4 Medium Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Slider Attributes ≤ 3.5.43 CVE-2026-12801 Wordfence
6.5 Medium Stream Plugin stream Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via Heartbeat API ≤ 4.2.0 CVE-2026-11907 Wordfence
9.8 Critical TrueBooker Plugin truebooker-appointment-booking Broken Access Control Missing Authorization to Unauthenticated Arbitrary Password Reset via 'truebooker_wp_user_id' No login needed ≤ 1.2.3 CVE-2026-14365 Wordfence
2.7 Low Content Protector (Passster) Plugin Information Disclosure Contributor+ Protected Content Disclosure via Core REST API < 4.3.7 Fixed in 4.3.7 CVE-2025-15674 WPScan
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-16620 WPScan
7.5 High miniOrange 2FA Plugin miniorange-2-factor-authentication Authentication Bypass miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts < 6.2.8 Fixed in 6.2.8 CVE-2026-16619 WPScan
5.3 Medium Event Booking Manager for WooCommerce (Pro) Plugin Price Manipulation Unauthenticated Payment Bypass via Client-Controlled Ticket Price No login needed < 5.0.3 Fixed in 5.0.3 CVE-2026-16067 WPScan
4.8 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default No login needed < 3.14.10 Fixed in 3.14.10 CVE-2026-15256 WPScan
5.3 Medium Security Optimizer – The All-In-One Protection Plugin Other The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password No login needed 1.5.8 – < 1.6.5 Fixed in 1.6.5 CVE-2026-13342 WPScan
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Unauthenticated Payment Bypass via Amount-Blind PayPal Verification No login needed < 6.0.9.5 Fixed in 6.0.9.5 CVE-2026-15208 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only