WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,601–2,650 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 53 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WPGraphQL Plugin wp-graphql Denial of Service WordPress Plugin WPGraphQL 1.3.5 Denial of Service No login needed 1.3.5 CVE-2021-47959 VulnCheck
4.9 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder SQL Injection Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter ≤ 9.1.12 CVE-2026-7046 Wordfence
8.1 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Deletion No login needed ≤ 2.5.2 CVE-2026-4030 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Export No login needed ≤ 2.5.2 CVE-2026-4029 Wordfence
7.5 High Database Backup Plugin wp-db-backup Broken Access Control Missing Authorization to Unauthenticated Database Backup Interception No login needed ≤ 2.5.2 CVE-2026-4031 Wordfence
4.3 Medium LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Plugin learnpress Price Manipulation WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter ≤ 4.3.5 CVE-2026-7648 Wordfence
5.5 Medium ultimate-member Plugin Local File Inclusion WordPress Plugin ultimate-member 2.1.3 Local File Inclusion 2.1.3 CVE-2020-37169 VulnCheck
8.1 High coreActivity: Activity Logging Plugin coreactivity PHP Object Injection Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field No login needed ≤ 3.0 CVE-2026-7635 Wordfence
7.1 High MonsterInsights Plugin google-analytics-for-wordpress Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset ≤ 10.1.2 CVE-2026-5371 Wordfence
5.3 Medium Hustle Plugin wordpress-popup Broken Access Control No login needed ≤ 7.8.10.1 Fixed in 7.8.10.2 CVE-2026-25431 Patchstack
7.7 High WP Travel Plugin wp-travel SQL Injection ≤ 11.4.0 Fixed in 11.5.0 CVE-2026-45218 Patchstack
5.3 Medium WP EasyPay Plugin wp-easy-pay Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.0 Fixed in 4.4.0 CVE-2026-45215 Patchstack
8.5 High Xpro Elementor Addons Plugin xpro-elementor-addons SQL Injection ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-45214 Patchstack
7.6 High BEAR Plugin woo-bulk-editor SQL Injection ≤ 1.1.7.1 Fixed in 1.1.8 CVE-2026-45213 Patchstack
5.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control No login needed ≤ 1.4.0.3 Fixed in 1.4.0.4 CVE-2026-45212 Patchstack
8.5 High APIExperts Square for WooCommerce Plugin woosquare SQL Injection ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-45211 Patchstack
5.4 Medium Broadstreet Ads Plugin broadstreet Broken Access Control ≤ 1.52.2 Fixed in 1.53.2 CVE-2026-45210 Patchstack
8.5 High Views for WPForms Plugin views-for-wpforms-lite SQL Injection ≤ 3.4.6 Fixed in 3.4.7 CVE-2026-42742 Patchstack
8.5 High Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend Plugin views-for-ninja-forms SQL Injection Display & Edit Ninja Forms Submissions on your site frontend plugin <= 3.3.2 - SQL Injection ≤ 3.3.2 Fixed in 3.3.3 CVE-2026-42741 Patchstack
8.2 High Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.53 Fixed in 1.0.54 CVE-2026-39432 Patchstack
6.1 Medium Tm – WordPress Redirection Plugin tm-wordpress-redirection Cross-Site Request Forgery WordPress Redirection <= 1.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2026-7561 Wordfence
6.4 Medium Picture Gallery Plugin picture-gallery Cross-Site Scripting WordPress Picture Gallery 1.4.2 Stored XSS via Edit Content URL 1.4.2 CVE-2021-47951 VulnCheck
5.4 Medium Payments Plugin GetPaid Plugin invoicing Content Injection WordPress GetPaid Plugin 2.4.6 HTML Injection via Help Text 2.4.6 CVE-2021-47948 VulnCheck
8.2 High Survey & Poll Plugin SQL Injection WordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params No login needed 1.5.7.3 CVE-2021-47941 VulnCheck
9.8 Critical Download From Files Plugin download-from-files Arbitrary File Upload WordPress Download From Files 1.48 Arbitrary File Upload No login needed ≤ 1.48 CVE-2021-47940 VulnCheck
9.8 Critical MStore API Plugin mstore-api Arbitrary File Upload WordPress MStore API 2.0.6 Arbitrary File Upload No login needed 2.0.6 CVE-2021-47933 VulnCheck
6.4 Medium Filterable Portfolio Gallery Plugin fg-gallery Cross-Site Scripting WordPress Plugin Filterable Portfolio Gallery 1.0 Stored XSS 1.0 CVE-2021-47929 VulnCheck
6.4 Medium WP Symposium Pro Plugin wp-symposium-pro Cross-Site Scripting WordPress Plugin WP Symposium Pro 2021.10 Stored XSS via wps_admin_forum_add_name 2021.10 CVE-2021-47927 VulnCheck
6.4 Medium Ultimate Product Catalogue Plugin ultimate-product-catalogue Cross-Site Scripting WordPress Plugin Ultimate Product Catalogue 5.8.2 Stored XSS via price 5.8.2 CVE-2021-47924 VulnCheck
6.4 Medium Slider by Soliloquy Plugin soliloquy-lite Cross-Site Scripting WordPress Plugin Slider by Soliloquy 2.6.2 Stored XSS 2.6.2 CVE-2021-47922 VulnCheck
6.4 Medium AccessPress Social Icons Plugin accesspress-social-icons Cross-Site Scripting WordPress Plugin AccessPress Social Icons 1.8.2 Stored XSS 1.8.2 CVE-2021-47910 VulnCheck
5.4 Medium WordPress Plugin AAWP Plugin Cross-Site Scripting WordPress Plugin AAWP 3.16 Reflected XSS via tab Parameter 3.16 CVE-2022-50970 VulnCheck
6.4 Medium IP2Location Country Blocker Plugin ip2location-country-blocker Cross-Site Scripting WordPress Plugin IP2Location Country Blocker 2.26.7 Stored XSS 2.26.7 CVE-2022-50961 VulnCheck
6.1 Medium International Sms For Contact Form Plugin cf7-international-sms-integration Cross-Site Scripting WordPress International Sms Contact Form 7 Integration 1.2 XSS No login needed 1.2 CVE-2022-50960 VulnCheck
6.1 Medium Contact Form Builder Plugin contact-forms-builder Cross-Site Scripting WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php No login needed 1.6.1 CVE-2022-50959 VulnCheck
6.1 Medium Jetpack Plugin jetpack Cross-Site Scripting WordPress Plugin Jetpack 9.1 Cross Site Scripting via grunion-form-view.php No login needed 9.1 CVE-2022-50958 VulnCheck
6.2 Medium amministrazione-aperta Plugin amministrazione-aperta Path Traversal WordPress Plugin amministrazione-aperta 3.7.3 Local File Read No login needed 3.7.3 CVE-2022-50956 VulnCheck
4.3 Medium Curtain Plugin curtain Cross-Site Request Forgery WordPress Plugin Curtain 1.0.2 Cross-site Request Forgery 1.0.2 CVE-2022-50955 VulnCheck
6.2 Medium cab-fare-calculator Plugin cab-fare-calculator Local File Inclusion WordPress Plugin cab-fare-calculator 1.0.3 Local File Inclusion No login needed 1.0.3 CVE-2022-50954 VulnCheck
6.4 Medium Videos sync PDF Plugin Cross-Site Scripting WordPress Plugin Videos sync PDF 1.7.4 Stored XSS 1.7.4 CVE-2022-50949 VulnCheck
6.4 Medium Testimonial Slider and Showcase Plugin testimonial-slider-and-showcase Cross-Site Scripting WordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS 2.2.6 CVE-2022-50947 VulnCheck
6.4 Medium Netroics Blog Posts Grid Plugin netroics-blog-posts-grid Cross-Site Scripting WordPress Plugin Netroics Blog Posts Grid 1.0 Stored XSS 1.0 CVE-2022-50946 VulnCheck
6.4 Medium E2Pdf – Export Pdf Tool Plugin e2pdf Cross-Site Scripting Export Pdf Tool for WordPress <= 1.32.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.32.17 CVE-2026-7650 Wordfence
7.1 High Bricks Builder Theme bricks Cross-Site Scripting No login needed 1.9.2 – 2.2 Fixed in 2.3 CVE-2026-41554 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2026-27415 Patchstack
5.3 Medium PDF Poster Plugin pdf-poster Broken Access Control No login needed ≤ 2.4.1 Fixed in 2.5.0 CVE-2026-27416 Patchstack
5.9 Medium WEN Logo Slider Plugin wen-logo-slider Cross-Site Scripting ≤ 3.4.0 Fixed in 3.5 CVE-2025-62127 Patchstack
5.3 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Broken Access Control No login needed < 5.6.8 Fixed in 5.6.8 CVE-2025-66105 Patchstack
7.6 High Team Member Plugin team-showcase-supreme SQL Injection ≤ 8.5 Fixed in 8.6 CVE-2025-68060 Patchstack
5.4 Medium WPGraphQL Plugin wp-graphql Cross-Site Request Forgery No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-68604 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only