WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,701–2,750 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 55 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WPIDE – File Manager & Code Editor Plugin wpide Cross-Site Scripting File Manager & Code Editor plugin <= 3.5.7 - Cross Site Scripting (XSS) No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2026-66440 Patchstack
7.1 High Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting No login needed ≤ 3.2.0.3 Fixed in 3.2.1 CVE-2026-66439 Patchstack
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Authentication Bypass Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication No login needed ≤ 1.9.0 Fixed in 2.0.0 CVE-2026-66425 Patchstack
9.8 Critical AI ANN Theme ann PHP Object Injection No login needed ≤ 1.29.0 CVE-2026-65581 Patchstack
9.8 Critical Agricola Theme agricola PHP Object Injection No login needed ≤ 1.21.0 CVE-2026-65579 Patchstack
9.8 Critical Agora Theme agora PHP Object Injection No login needed ≤ 1.9 CVE-2026-65578 Patchstack
9.8 Critical Advice Theme advice PHP Object Injection No login needed ≤ 1.18.0 CVE-2026-65577 Patchstack
9.8 Critical Adrena Theme adrena PHP Object Injection No login needed ≤ 1.2.14 CVE-2026-65576 Patchstack
9.8 Critical Accalia Theme accalia PHP Object Injection No login needed ≤ 1.5.3 CVE-2026-65575 Patchstack
9.8 Critical Abogado Theme abogado PHP Object Injection No login needed ≤ 1.18 CVE-2026-65574 Patchstack
9.8 Critical Abelle Theme abelle PHP Object Injection No login needed ≤ 1.22 CVE-2026-65573 Patchstack
9.8 Critical A.Williams Theme alisha-williams PHP Object Injection No login needed ≤ 1.3.1 CVE-2026-65572 Patchstack
9.8 Critical 69 Clothing Theme clothing69 PHP Object Injection No login needed ≤ 1.2.11.1 CVE-2026-65571 Patchstack
8.1 High Login with phone number Plugin login-with-phone-number Authentication Bypass Bypass vulnerability No login needed ≤ 1.8.70 Fixed in 1.8.71 CVE-2026-65570 Patchstack
8.5 High WP Job Portal Plugin wp-job-portal SQL Injection ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-65569 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.3.3 Fixed in 5.2.3.4 CVE-2026-65565 Patchstack
7.1 High Houzez Property Feed Plugin houzez-property-feed Cross-Site Scripting No login needed ≤ 2.5.48 Fixed in 2.5.49 CVE-2026-65560 Patchstack
7.2 High Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Privilege Escalation ≤ 4.6.0 Fixed in 4.6.1 CVE-2026-65559 Patchstack
9.8 Critical WPBruiser {no- Captcha anti-Spam} Plugin goodbye-captcha PHP Object Injection No login needed ≤ 3.1.43 CVE-2026-65556 Patchstack
7.1 High AnsPress – Question and answer Plugin anspress-question-answer Broken Access Control Question and answer plugin 4.4.4 - Broken Access Control 4.4.4 CVE-2026-65554 Patchstack
10.0 Critical Spider Analyser – WordPress搜索引擎蜘蛛分析插件 Plugin spider-analyser Remote Code Execution WordPress搜索引擎蜘蛛分析插件 plugin <= 2.1.3 - Remote Code Execution (RCE) No login needed ≤ 2.1.3 CVE-2026-65553 Patchstack
9.8 Critical Export User Data Plugin export-user-data PHP Object Injection No login needed ≤ 2.2.6 CVE-2026-65552 Patchstack
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit PHP Object Injection ≤ 3.2.10 Fixed in 3.2.11 CVE-2026-65549 Patchstack
9.9 Critical Betheme Theme betheme Remote Code Execution ≤ 28.4.2 CVE-2026-65548 Patchstack
8.5 High Creative Mail Plugin creative-mail-by-constant-contact SQL Injection ≤ 1.6.9 CVE-2026-65547 Patchstack
9.3 Critical Qode Tours Plugin qode-tours SQL Injection No login needed ≤ 3.1.3.1 CVE-2026-65546 Patchstack
7.1 High AI Engine Plugin ai-engine Cross-Site Scripting No login needed ≤ 3.6.8 Fixed in 3.6.9 CVE-2026-65545 Patchstack
7.1 High Super Socializer Plugin super-socializer Cross-Site Scripting No login needed ≤ 7.14.5 CVE-2026-65544 Patchstack
7.5 High Vimeo Plugin vimeo Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.2 CVE-2026-65543 Patchstack
8.8 High Super Socializer Plugin super-socializer Authentication Bypass Broken Authentication No login needed ≤ 7.14.5 CVE-2026-65542 Patchstack
7.3 High Staff Training Plugin staff-training Broken Access Control No login needed ≤ 1.0.7 CVE-2026-65541 Patchstack
7.5 High Formidable Forms Signature Online Contract Automation Plugin forms-signature-formidable-online-contract-automation Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-65523 Patchstack
9.3 Critical WP OAuth Server Plugin miniorange-oauth-20-server SQL Injection No login needed ≤ 6.2.0 Fixed in 6.2.1 CVE-2026-65520 Patchstack
7.1 High Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2026-65517 Patchstack
7.1 High AffiliateWP Plugin affiliate-wp Cross-Site Scripting No login needed ≤ 2.35.0 Fixed in 2.35.1 CVE-2026-65515 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting No login needed ≤ 1.6.12.10 Fixed in 1.6.12.11 CVE-2026-65513 Patchstack
7.1 High wpDataTables Plugin wpdatatables Cross-Site Scripting No login needed ≤ 7.5.1 Fixed in 7.5.2 CVE-2026-65509 Patchstack
9.3 Critical Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection No login needed ≤ 1.6.12.10 Fixed in 1.6.12.11 CVE-2026-65508 Patchstack
9.8 Critical AIWU Plugin ai-copilot-content-generator Privilege Escalation No login needed ≤ 1.5.6 Fixed in 1.5.8 CVE-2026-65507 Patchstack
7.5 High BOX NOW Delivery Croatia Plugin box-now-delivery-croatia Broken Access Control No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2026-65504 Patchstack
5.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Authentication Bypass Captcha Bypass No login needed ≤ 8.7.13 Fixed in 8.7.14 CVE-2026-65502 Patchstack
7.1 High SiteGuard WP Plugin siteguard Cross-Site Scripting No login needed ≤ 1.8.6 Fixed in 1.8.7 CVE-2026-61982 Patchstack
7.1 High Ninja Tables Plugin ninja-tables Cross-Site Scripting No login needed ≤ 5.2.9 Fixed in 5.2.10 CVE-2026-61964 Patchstack
7.1 High Media LIbrary Assistant Plugin media-library-assistant Cross-Site Scripting No login needed ≤ 3.38 Fixed in 3.39 CVE-2026-61963 Patchstack
7.1 High EmbedPress Plugin embedpress Cross-Site Scripting No login needed ≤ 4.5.6 Fixed in 4.6.0 CVE-2026-61961 Patchstack
6.5 Medium Business Directory Plugin business-directory-plugin Cross-Site Scripting ≤ 6.4.24 Fixed in 6.4.25 CVE-2026-61959 Patchstack
5.3 Medium SureCart Plugin surecart Broken Access Control No login needed ≤ 4.6.2 Fixed in 4.6.3 CVE-2026-32548 Patchstack
5.3 Medium CAPTCHA 4WP Plugin advanced-nocaptcha-recaptcha Authentication Bypass Captcha Bypass No login needed ≤ 7.6.0 CVE-2026-32469 Patchstack
7.2 High PublishPress Capabilities Plugin capability-manager-enhanced Privilege Escalation ≤ 2.45.0 Fixed in 2.50.0 CVE-2026-28183 Patchstack
5.3 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 8.9.0 Fixed in 8.9.1 CVE-2026-28180 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only