WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,751–2,800 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 56 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium FiboSearch Plugin ajax-search-for-woocommerce Cross-Site Scripting ≤ 1.33.0 Fixed in 1.34.0 CVE-2026-28179 Patchstack
6.5 Medium Powerkit Plugin powerkit Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-28178 Patchstack
7.1 High Popup Maker Plugin popup-maker Cross-Site Scripting No login needed ≤ 1.23.0 Fixed in 1.24.0 CVE-2026-28177 Patchstack
7.1 High Tracking Code Manager Plugin tracking-code-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6.0 Fixed in 2.7.0 CVE-2026-28172 Patchstack
5.3 Medium YITH WooCommerce Zoom Magnifier Plugin yith-woocommerce-zoom-magnifier Information Disclosure Sensitive Data Exposure No login needed ≤ 2.52.0 Fixed in 2.52.1 CVE-2026-28169 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Path Traversal Arbitrary File Download ≤ 2.0.14 Fixed in 2.0.15 CVE-2026-28146 Patchstack
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.56.0 Fixed in 1.56.1 CVE-2026-28143 Patchstack
7.1 High NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-28141 Patchstack
7.5 High JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.6.4.1 Fixed in 3.6.4.2 CVE-2026-28140 Patchstack
9.8 Critical Ajax Search Lite Plugin ajax-search-lite PHP Object Injection No login needed ≤ 4.14.4 Fixed in 4.14.5 CVE-2026-28139 Patchstack
8.8 High Forminator Plugin forminator Privilege Escalation ≤ 1.56.0 Fixed in 1.56.0.1 CVE-2026-28111 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.13.1 Fixed in 3.8.13.2 CVE-2026-28082 Patchstack
9.8 Critical Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Privilege Escalation No login needed ≤ 1.5.19 Fixed in 1.5.19.1 CVE-2026-28005 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-25403 Patchstack
7.5 High Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.7.8 Fixed in 4.7.9 CVE-2026-66712 Patchstack
4.3 Medium RealHomes Memberships Plugin inspiry-memberships Price Manipulation Subscriber+ Membership Payment Bypass < 3.1.0 Fixed in 3.1.0 CVE-2026-15246 WPScan
6.4 Medium UsersWP Plugin userswp Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Badge Widget Variable Substitution ≤ 1.2.69 CVE-2026-18501 Wordfence
7.5 High Breakdance Plugin breakdance Broken Access Control No login needed < 2.7 Fixed in 2.7 CVE-2026-65551 Patchstack
5.3 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Content Injection Unauthenticated SMTP Header Injection No login needed ≤ 8.3.15 CVE-2026-0673 Wordfence
4.3 Medium Accelerate Theme accelerate Broken Access Control Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation ≤ 1.5.3 CVE-2025-9266 Wordfence
5.3 Medium Ad Inserter Plugin ad-inserter Broken Access Control Missing Authorization to Block Visibility Bypass via ai_ajax No login needed ≤ 2.8.16 CVE-2026-11983 Wordfence
7.2 High FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More Plugin formgent Cross-Site Scripting Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.9.2 CVE-2025-15028 Wordfence
6.4 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 5.3.2 CVE-2026-5391 Wordfence
6.4 Medium PostX Plugin ultimate-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comments Block ≤ 5.0.13 CVE-2026-5158 Wordfence
6.5 Medium Google Authenticator Plugin google-authenticator Cross-Site Request Forgery Google Authenticator < 0.56 - 2FA Secret Overwrite via CSRF No login needed < 0.56 Fixed in 0.56 CVE-2026-14204 WPScan
5.4 Medium SEO Redirection Plugin – 301 Redirect Manager Plugin seo-redirection Information Disclosure Subscriber+ Redirect Rule Disclosure < 9.19 Fixed in 9.19 CVE-2026-13703 WPScan
7.5 High Essential Blocks Plugin Information Disclosure Unauthenticated Non-Public Custom Post Type Content Disclosure via queries Endpoint No login needed < 6.4.0 Fixed in 6.4.0 CVE-2026-13154 WPScan
7.5 High Essential Blocks Plugin Information Disclosure Unauthenticated WooCommerce Sales Data Disclosure via REST products Endpoint No login needed < 6.4.0 Fixed in 6.4.0 CVE-2026-13153 WPScan
9.1 Critical WPCargo Track & Trace Plugin wpcargo SQL Injection Unauthenticated SQL Injection via wpcargo_tracking_number No login needed < 8.0.4 Fixed in 8.0.4 CVE-2026-12713 WPScan
6.1 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed < 5.0.2 Fixed in 5.0.2 CVE-2025-15678 WPScan
5.4 Medium Child Pages Card Plugin child-pages-card Cross-Site Scripting Contributor+ Stored XSS via Shortcode Attributes < 1.09 Fixed in 1.09 CVE-2026-18395 WPScan
5.4 Medium Slick Slider Plugin Cross-Site Scripting Contributor+ Stored XSS via Gallery Shortcode < 0.5.3 Fixed in 0.5.3 CVE-2026-16537 WPScan
6.5 Medium Welcart e-Commerce Plugin usc-e-shop SQL Injection Editor+ SQL Injection via CSV Import < 2.11.32 Fixed in 2.11.32 CVE-2026-16065 WPScan
8.2 High Checkimate Plugin Broken Access Control Unauthenticated License Deactivation via Hardcoded Secret No login needed ≤ 1.0.13 CVE-2026-14829 WPScan
6.1 Medium EONSR AEO Agent Plugin eonsr-aeo-agent Cross-Site Scripting Unauthenticated Stored XSS via Scheduled Post Creation No login needed ≤ 3.7.9 CVE-2026-11588 WPScan
7.5 High Events Manager Plugin events-manager Information Disclosure Unauthenticated Pending Upload Disclosure via events-manager/v1/uploads No login needed < 7.4 Fixed in 7.4 CVE-2026-18050 WPScan
6.5 Medium AI Engine Plugin ai-engine Information Disclosure Editor+ Sensitive Information Disclosure of API Key and Bearer Tokens < 3.6.4 Fixed in 3.6.4 CVE-2026-16954 WPScan
7.5 High Stripe Payment Forms by WP Full Pay Plugin wp-full-stripe-free Price Manipulation Unauthenticated Payment Intent Amount Manipulation No login needed < 8.5.2 Fixed in 8.5.2 CVE-2026-16734 WPScan
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group No login needed < 6.0.0.0 Fixed in 6.0.0.0 CVE-2026-16290 WPScan
8.2 High Newsletters Plugin newsletters-lite Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via SNS Bounce Handler No login needed < 4.16 Fixed in 4.16 CVE-2026-16268 WPScan
9.1 Critical Drag and Drop Multiple File Upload for WooCommerce Plugin drag-and-drop-multiple-file-upload-for-woocommerce Arbitrary File Upload Unauthenticated File Deletion via Nonce Oracle No login needed < 1.1.8 Fixed in 1.1.8 CVE-2026-16054 WPScan
5.3 Medium Estatik Real Estate Plugin Authentication Bypass Unauthenticated Arbitrary-Recipient Mail Relay via Request Form No login needed < 4.3.3 Fixed in 4.3.3 CVE-2026-14547 WPScan
5.3 Medium Tourmaster Plugin Information Disclosure Unauthenticated Sensitive Data Disclosure via Order Export No login needed < 5.4.9 Fixed in 5.4.9 CVE-2026-14240 WPScan
5.3 Medium PeproDev WooCommerce Receipt Uploader Plugin Information Disclosure Unauthenticated Image Attachment Disclosure via IDOR No login needed ≤ 2.8.0 CVE-2026-14314 WPScan
5.3 Medium PeproDev WooCommerce Receipt Uploader Plugin Broken Access Control Unauthenticated Order Receipt Tampering via IDOR No login needed ≤ 2.8.0 CVE-2026-14313 WPScan
7.2 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.2.6 CVE-2026-18510 Wordfence
6.4 Medium Slider, Gallery, and Carousel by MetaSlider Plugin ml-slider Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'delay' Post Meta Setting ≤ 3.111.0 CVE-2026-18400 Wordfence
8.1 High WPMU DEV Dashboard Plugin Authentication Bypass Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint No login needed ≤ 5.0.0 CVE-2026-15459 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field No login needed ≤ 1.56.1 CVE-2026-18325 Wordfence
8.8 High File Manager Plugin file-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read and Deletion via 'cmd' Query Parameter 6.0 – 6.9 CVE-2026-15991 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only