WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,651–2,700 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 54 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Price Manipulation Unauthenticated Payment Bypass via Price Manipulation No login needed < 2.3.3 Fixed in 2.3.3 CVE-2026-15149 WPScan
5.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Price Manipulation Unauthenticated Payment Bypass and Booking Confirmation via IDOR No login needed < 2.7.23 Fixed in 2.7.23 CVE-2026-15147 WPScan
7.5 High CoCart Plugin cart-rest-api-for-woocommerce Price Manipulation Unauthenticated Arbitrary Price Manipulation No login needed < 4.9.0 Fixed in 4.9.0 CVE-2026-10524 WPScan
5.3 Medium Simple Membership Plugin simple-membership Price Manipulation Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification No login needed < 4.7.7 Fixed in 4.7.7 CVE-2026-14936 WPScan
5.3 Medium Easy Booking Plugin woocommerce-easy-booking-system Other Unauthenticated Minimum Booking Duration Bypass No login needed < 3.5.0 Fixed in 3.5.0 CVE-2026-14831 WPScan
5.9 Medium GetPaid Plugin Price Manipulation Unauthenticated Worldpay Payment Bypass via Insufficient IPN Verification No login needed < 2.8.55 Fixed in 2.8.55 CVE-2026-12901 WPScan
5.3 Medium WP Travel Engine Plugin wp-travel-engine Price Manipulation Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount Verification No login needed < 6.8.2 Fixed in 6.8.2 CVE-2026-12501 WPScan
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Price Manipulation Unauthenticated PayPal Payment Bypass No login needed < 2.3.2 Fixed in 2.3.2 CVE-2026-15152 WPScan
5.3 Medium Events Made Easy Plugin events-made-easy Price Manipulation Unauthenticated Payment Bypass No login needed < 3.1.2 Fixed in 3.1.2 CVE-2026-14842 WPScan
2.7 Low Easy Appointments Plugin easy-appointments Other Contributor+ Shortcode Allowlist Bypass < 3.12.28 Fixed in 3.12.28 CVE-2026-14225 WPScan
10.0 Critical Premium SEO Plugin Remote Code Execution Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) No login needed Not stated CVE-2026-14812 WPScan
7.5 High Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Price Manipulation Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order No login needed < 2.0.20 Fixed in 2.0.20 CVE-2026-13399 WPScan
4.3 Medium Tutor LMS Plugin tutor Information Disclosure Subscriber+ Paid Course Content Disclosure via Enrollment Check Bypass < 3.9.14 Fixed in 3.9.14 CVE-2026-14306 WPScan
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed < 7.0.2 Fixed in 7.0.2 CVE-2026-12584 WPScan
5.9 Medium Formidable Forms Plugin formidable Price Manipulation Unauthenticated Payment Bypass via PayPal APPROVAL_PENDING Subscription Status No login needed < 6.32.1 Fixed in 6.32.1 CVE-2026-11361 WPScan
7.5 High Integrate PhonePe with WooCommerce Plugin Price Manipulation Unauthenticated Payment Bypass via Transaction ID Reuse No login needed ≤ 1.2.1 CVE-2026-10599 WPScan
6.8 Medium Dataverse Integration Plugin Information Disclosure Contributor+ Server-Side Template Injection (SSTI) to Information Disclosure < 2.91 Fixed in 2.91 CVE-2026-5336 WPScan
8.6 High Creative Mail Plugin SQL Injection Unauthenticated SQLi No login needed 1.6.5 – 1.6.9 CVE-2026-3430 WPScan
7.1 High WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Cross-Site Scripting No login needed ≤ 5.5.6 Fixed in 5.5.7 CVE-2026-66711 Patchstack
8.1 High e2pdf Plugin e2pdf Local File Inclusion No login needed ≤ 1.32.40 Fixed in 1.32.43 CVE-2026-66710 Patchstack
9.1 Critical CTX Feed Plugin webappick-product-feed-for-woocommerce Remote Code Execution ≤ 6.6.42 Fixed in 6.6.43 CVE-2026-66709 Patchstack
8.2 High Total Upkeep Plugin boldgrid-backup Broken Access Control No login needed ≤ 1.17.2 Fixed in 1.17.3 CVE-2026-66708 Patchstack
7.1 High Facebook for WooCommerce Plugin facebook-for-woocommerce Cross-Site Scripting No login needed ≤ 3.7.5 Fixed in 3.7.6 CVE-2026-66707 Patchstack
5.9 Medium Subscribe to Comments Plugin subscribe-to-comments Cross-Site Scripting ≤ 2.3.1 CVE-2026-66706 Patchstack
7.1 High Facebook Plugin official-facebook-pixel Cross-Site Scripting No login needed ≤ 5.2.1 Fixed in 5.2.2 CVE-2026-66705 Patchstack
6.5 Medium MailOptin Plugin mailoptin Cross-Site Scripting ≤ 1.2.78.0 Fixed in 1.2.78.1 CVE-2026-66703 Patchstack
7.1 High Rank Math SEO Plugin seo-by-rank-math Cross-Site Scripting No login needed ≤ 1.0.274.1 Fixed in 1.0.275 CVE-2026-66702 Patchstack
5.3 Medium Profile Builder Plugin profile-builder Broken Access Control No login needed ≤ 3.16.5 Fixed in 3.16.6 CVE-2026-66701 Patchstack
5.3 Medium Dokan Plugin dokan-lite Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66699 Patchstack
4.3 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Information Disclosure Sensitive Data Exposure ≤ 3.7.8 Fixed in 3.7.8.1 CVE-2026-66696 Patchstack
6.5 Medium W3 Total Cache Plugin w3-total-cache Path Traversal No login needed ≤ 2.10.2 Fixed in 2.10.3 CVE-2026-66695 Patchstack
7.1 High Thrive Architect Plugin thrive-visual-editor Cross-Site Scripting No login needed ≤ 10.9.3.1 Fixed in 10.9.3.2 CVE-2026-66694 Patchstack
4.3 Medium Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66692 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.16.5 Fixed in 4.16.5.1 CVE-2026-66690 Patchstack
6.5 Medium Ultimate Addons for Elementor Plugin ultimate-elementor Cross-Site Scripting ≤ 1.45.2 Fixed in 1.45.2.1 CVE-2026-66688 Patchstack
6.5 Medium Plugins Garbage Collector (Database Cleanup) Plugin plugins-garbage-collector Cross-Site Request Forgery No login needed ≤ 0.14 CVE-2026-66686 Patchstack
5.3 Medium Featured Video Plus Plugin featured-video-plus Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-66685 Patchstack
5.3 Medium Export Import Menus Plugin export-import-menus Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.2 CVE-2026-66684 Patchstack
5.3 Medium Custom CSS and JavaScript Plugin custom-css-and-javascript Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.16 CVE-2026-66683 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery No login needed ≤ 7.1.14 CVE-2026-66681 Patchstack
4.3 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Broken Access Control ≤ 6.1.1 CVE-2026-66678 Patchstack
10.0 Critical Type Hub Plugin typehub Arbitrary File Upload No login needed ≤ 2.0.6 CVE-2026-66665 Patchstack
7.1 High SEO Plugin by Squirrly SEO Plugin squirrly-seo Cross-Site Scripting No login needed ≤ 14.2.0 Fixed in 14.2.1 CVE-2026-66664 Patchstack
7.1 High WP Data Access Plugin wp-data-access Cross-Site Scripting No login needed ≤ 5.5.79 Fixed in 5.5.80 CVE-2026-66663 Patchstack
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation No login needed ≤ 3.29.10 CVE-2026-66662 Patchstack
7.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Broken Access Control ≤ 3.29.10 CVE-2026-66470 Patchstack
7.1 High Events Manager Plugin events-manager Cross-Site Scripting No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2026-66457 Patchstack
6.5 Medium Legal Text Connector of the IT-Recht Kanzlei Plugin legal-texts-connector-it-recht-kanzlei Broken Access Control No login needed ≤ 1.0.13 Fixed in 1.0.14 CVE-2026-66452 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Authentication Bypass Broken Authentication No login needed ≤ 4.1.9 Fixed in 4.1.10 CVE-2026-66451 Patchstack
9.3 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload SQL Injection No login needed ≤ 5.1.7 Fixed in 5.1.8 CVE-2026-66447 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only