WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,651–2,700 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 54 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Information Disclosure Sensitive Data Exposure No login needed ≤ 3.20.8 Fixed in 3.21.0 CVE-2026-25468 Patchstack
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.12.0 Fixed in 4.13.0 CVE-2026-27329 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed < 1.7.1053 Fixed in 1.7.1053 CVE-2026-25436 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting < 1.7.1053 Fixed in 1.7.1053 CVE-2026-27421 Patchstack
7.5 High WordPress Plugin Backup Migration Plugin Information Disclosure WordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup Download No login needed 1.2.8 CVE-2023-54346 VulnCheck
9.3 Critical WebinarIgnition Plugin webinar-ignition SQL Injection No login needed ≤ 4.08.253 CVE-2026-40797 Patchstack
6.4 Medium Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem Plugin gutenverse Server-Side Request Forgery Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Server-Side Request Forgery via 'imageUrl' ≤ 3.5.3 CVE-2026-2948 Wordfence
6.4 Medium Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem Plugin gutenverse Cross-Site Scripting Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'separatorIconSVG' ≤ 3.5.3 CVE-2026-2868 Wordfence
7.5 High AWP Classifieds Plugin another-wordpress-classifieds-plugin SQL Injection Unauthenticated SQL Injection via 'regions' No login needed ≤ 4.4.5 CVE-2026-5100 Wordfence
7.1 High User Registration Plugin user-registration Cross-Site Scripting No login needed ≤ 5.1.5 Fixed in 5.1.6 CVE-2026-42652 Patchstack
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control ≤ 2.19.22 Fixed in 2.19.23 CVE-2026-42648 Patchstack
7.6 High TaxoPress Plugin simple-tags SQL Injection ≤ 3.44.0 Fixed in 3.45.0 CVE-2026-42646 Patchstack
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.11.0 Fixed in 1.12.0 CVE-2026-42645 Patchstack
5.3 Medium BetterDocs Plugin betterdocs Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.10 Fixed in 4.3.11 CVE-2026-42644 Patchstack
5.9 Medium Image Widget Plugin image-widget Cross-Site Scripting ≤ 4.4.11 Fixed in 4.4.12 CVE-2026-42643 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed ≤ 4.14.5 Fixed in 4.14.6 CVE-2026-42642 Patchstack
5.4 Medium Share This Image Plugin share-this-image Server-Side Request Forgery No login needed ≤ 2.14 Fixed in 2.15 CVE-2026-42641 Patchstack
6.5 Medium WP User Frontend Plugin wp-user-frontend Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-42412 Patchstack
7.3 High SureForms Pro Plugin sureforms-pro Broken Access Control No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-42377 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-42410 Patchstack
9.8 Critical Directorist Social Login Plugin directorist-social-login Privilege Escalation No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-22337 Patchstack
9.3 Critical Directorist Booking Plugin directorist-booking SQL Injection No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-22336 Patchstack
7.7 High Templately Plugin templately Information Disclosure Sensitive Data Exposure ≤ 3.6.1 Fixed in 3.6.2 CVE-2026-42379 Patchstack
9.9 Critical FunnelFormsPro Plugin funnelforms-pro Remote Code Execution ≤ 3.8.1 CVE-2026-39440 Patchstack
6.5 Medium Rescue Shortcodes Plugin rescue-shortcodes Cross-Site Scripting ≤ 3.3 Fixed in 3.4 CVE-2025-62110 Patchstack
4.3 Medium ACF Galerie 4 Plugin acf-galerie-4 Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-62104 Patchstack
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed < 7.13.2 Fixed in 7.13.2 CVE-2025-58922 Patchstack
9.8 Critical Sendmachine Plugin sendmachine Privilege Escalation Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests No login needed ≤ 1.0.20 CVE-2026-6235 Wordfence
7.2 High Responsive Slider by MetaSlider Plugin ml-slider PHP Object Injection ≤ 3.106.0 Fixed in 3.107.0 CVE-2026-39467 Patchstack
4.7 Medium wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin Cross-Site Scripting WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import No login needed ≤ 6.5.0.4 CVE-2026-5721 Wordfence
7.6 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection ≤ 3.7.1 CVE-2025-63029 Patchstack
7.5 High Accept Cryptocurrencies with Plisio Plugin plisio-payment-gateway-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 2.0.5 CVE-2026-6372 Patchstack
5.9 Medium Mini Ajax Cart for WooCommerce Plugin mini-ajax-woo-cart Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-6370 Patchstack
6.5 Medium YouTube Showcase Plugin youtube-showcase Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-15636 Patchstack
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Request Forgery No login needed ≤ 1.6.0 CVE-2025-15635 Patchstack
4.3 Medium Userpro Plugin userpro Cross-Site Request Forgery No login needed ≤ 5.1.11 Fixed in 5.1.11 CVE-2025-53444 Patchstack
4.3 Medium MyRewards Plugin woorewards Broken Access Control ≤ 5.7.3 Fixed in 5.7.4 CVE-2026-40786 Patchstack
8.1 High FluentBoards Plugin fluent-boards Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.91.2 Fixed in 1.91.3 CVE-2026-40784 Patchstack
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2026-40778 Patchstack
8.1 High Contact Form by WPForms Plugin wpforms-lite Cross-Site Request Forgery No login needed ≤ 1.10.0.2 Fixed in 1.10.0.3 CVE-2026-40764 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed ≤ 1.7.1056 Fixed in 1.7.1057 CVE-2026-40763 Patchstack
7.6 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 8.4.2 Fixed in 8.5.0 CVE-2026-40745 Patchstack
8.5 High Beaver Builder Plugin beaver-builder-lite-version SQL Injection ≤ 2.10.1.2 Fixed in 2.10.1.5 CVE-2026-40744 Patchstack
5.3 Medium Nelio AB Testing Plugin nelio-ab-testing Information Disclosure Sensitive Data Exposure No login needed ≤ 8.2.8 Fixed in 8.3.0 CVE-2026-40742 Patchstack
5.4 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-40740 Patchstack
5.3 Medium COMPE Plugin compe-woo-compare-products Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-40737 Patchstack
6.5 Medium Categories Images Plugin categories-images Cross-Site Scripting ≤ 3.3.1 Fixed in 3.3.2 CVE-2026-40734 Patchstack
5.3 Medium ThemeGrill Demo Importer Plugin themegrill-demo-importer Broken Access Control No login needed ≤ 2.0.0.6 Fixed in 2.0.0.7 CVE-2026-40730 Patchstack
4.3 Medium 3D viewer – Embed 3D Models Plugin 3d-viewer Broken Access Control Embed 3D Models plugin <= 1.8.5 - Broken Access Control ≤ 1.8.5 Fixed in 1.8.6 CVE-2026-40729 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only