WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,801–2,850 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 57 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High FluentSMTP Plugin fluent-smtp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs No login needed ≤ 2.2.95 CVE-2026-16636 Wordfence
8.1 High Content Egg Plugin content-egg Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion ≤ 11.3.0 CVE-2026-15979 Wordfence
7.2 High Independent Analytics Plugin independent-analytics Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.15.0 CVE-2026-17506 Wordfence
7.5 High wiseCampaign Plugin wisecampaign Broken Access Control Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API No login needed ≤ 1.1.16 CVE-2026-7529 Wordfence
6.5 Medium Udimi Tools Plugin udimi-optin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action ≤ 3.2 CVE-2026-7456 Wordfence
7.2 High wp-downloadmanager Plugin wp-downloadmanager Arbitrary File Upload Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal ≤ 1.69 CVE-2026-18933 TuranSec
4.7 Medium Smash Balloon Social Photo Feed Plugin instagram-feed Cross-Site Scripting Reflected Cross-Site Scripting via REQUEST_URI Query String No login needed ≤ 6.11.3 CVE-2026-15452 Wordfence
6.5 Medium WP Post Author Plugin wp-post-author SQL Injection Authenticated (Author+) SQL Injection ≤ 3.9.1 CVE-2026-11977 Wordfence
4.9 Medium JoomSport Plugin joomsport-sports-league-results-management SQL Injection Authenticated (Administrator+) SQL Injection via 'order' Parameter ≤ 5.7.9 CVE-2026-11920 Wordfence
8.1 High MailChimp Forms by MailMunch Plugin mailchimp-forms-by-mailmunch Broken Access Control Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action ≤ 3.2.7 CVE-2026-7520 Wordfence
4.9 Medium WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider SQL Injection Authenticated (Administrator+) SQL Injection ≤ 14.3 CVE-2026-11969 Wordfence
7.2 High ShopLentor Plugin woolentor-addons Other Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API ≤ 3.3.7 CVE-2026-6020 Wordfence
9.1 Critical Easy Post Submission Plugin easy-post-submission Broken Access Control Missing Authorization No login needed ≤ 2.3.0 CVE-2026-4431 Wordfence
7.5 High Page and Post Restriction Plugin page-and-post-restriction Broken Access Control Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API No login needed ≤ 1.4.1 CVE-2026-12000 Wordfence
4.3 Medium Xpro Addons Plugin xpro-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function ≤ 1.5.1 CVE-2026-7105 Wordfence
8.1 High Search Analytics for WP Plugin search-analytics Cross-Site Request Forgery No login needed ≤ 1.4.16 CVE-2026-7444 Wordfence
6.4 Medium Simple Yearly Archive Plugin simple-yearly-archive Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.4 CVE-2026-7441 Wordfence
6.4 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6 CVE-2026-6972 Wordfence
4.9 Medium Askeet Plugin askeet SQL Injection Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter ≤ 3.0 CVE-2026-5651 Wordfence
7.5 High TableOn Plugin posts-table-filterable SQL Injection Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter No login needed ≤ 1.0.5.1 CVE-2026-18881 Wordfence
7.2 High Backup Migration Plugin backup-backup Remote Code Execution Authenticated (Administrator+) OS Command Injection via 'file' Parameter ≤ 2.1.1 CVE-2026-7693 Wordfence
8.8 High LightSync Pro Plugin lightsyncpro Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.1.6 CVE-2026-6147 Wordfence
6.1 Medium TranslatePress Plugin translatepress-multilingual Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.5 CVE-2026-17505 Wordfence
6.5 Medium User Access Manager Plugin user-access-manager SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.3.12 CVE-2026-15281 Wordfence
6.1 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.29.18 CVE-2026-17532 Wordfence
6.5 Medium Groundhogg — CRM, Newsletters, and Marketing Automation Plugin groundhogg Broken Access Control Insecure Direct Object Reference ≤ 4.5.2 CVE-2026-11454 Wordfence
4.4 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Cross-Site Scripting Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting ≤ 5.0.5 CVE-2026-5116 Wordfence
8.2 High WPFormify Plugin wpformify Broken Access Control Missing Authorization No login needed ≤ 1.1.1 CVE-2026-6627 Wordfence
7.3 High Material Dashboard Plugin material-dashboard Broken Access Control Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion No login needed ≤ 1.4.10 CVE-2026-6079 Wordfence
6.5 Medium Layouts for WPBakery Plugin layouts-for-wpbakery Broken Access Control Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action No login needed ≤ 1.1.3 CVE-2026-7726 Wordfence
7.5 High AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.4.6 CVE-2026-6639 Wordfence
9.1 Critical Multi Uploader for Gravity Forms Plugin gf-multi-uploader Broken Access Control Missing Authorization to Unauthenticated Arbitrary Media Deletion No login needed ≤ 1.1.8 CVE-2026-5581 Wordfence
4.4 Medium Super Progressive Web Apps Plugin super-progressive-web-apps Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting ≤ 2.2.43 CVE-2026-5108 Wordfence
4.3 Medium MLS Import Plugin Information Disclosure Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item < 7.0.4 Fixed in 7.0.4 CVE-2026-17515 WPScan
7.5 High Contest Gallery Plugin contest-gallery Authentication Bypass Unauthenticated Login-Protection and 2FA Bypass via post_cg_login < 30.0.7 Fixed in 30.0.7 CVE-2026-16055 WPScan
7.5 High miniOrange 2FA Plugin miniorange-2-factor-authentication Authentication Bypass miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding No login needed < 6.2.7 Fixed in 6.2.7 CVE-2026-16036 WPScan
7.5 High WP 2FA Plugin wp-2fa Authentication Bypass Two-Factor Authentication Bypass via Passkeys Provider No login needed < 4.1.0 Fixed in 4.1.0 CVE-2026-15372 WPScan
9.1 Critical Ajax Load More Plugin ajax-load-more SQL Injection Unauthenticated SQL Injection via custom_args No login needed < 8.0.1 Fixed in 8.0.1 CVE-2026-15360 WPScan
9.1 Critical Login/Signup with Phone Number, OTP Verification Plugin Privilege Escalation Unauthenticated Account Takeover via OTP Brute Force No login needed < 1.8.71 Fixed in 1.8.71 CVE-2026-15210 WPScan
3.7 Low DHL for WooCommerce Plugin Information Disclosure Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory No login needed < 4.0.1 Fixed in 4.0.1 CVE-2026-16993 WPScan
5.3 Medium DHL for WooCommerce Plugin Broken Access Control Unauthenticated Shipping Label Download via IDOR No login needed < 4.0.1 Fixed in 4.0.1 CVE-2026-16981 WPScan
8.1 High YayPricing Plugin yaypricing Information Disclosure Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure < 3.5.7 Fixed in 3.5.7 CVE-2026-15230 WPScan
8.1 High Zportals Plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload < 6.3.4 Fixed in 6.3.4 CVE-2026-14553 WPScan
3.5 Low GeoDirectory Plugin geodirectory Cross-Site Scripting Editor+ Stored XSS via Place Categories < 2.8.110 Fixed in 2.8.110 CVE-2025-15677 WPScan
6.5 Medium GeoDirectory Plugin geodirectory Information Disclosure Contributor+ User Email Disclosure via geodir_json_search_users < 2.8.168 Fixed in 2.8.168 CVE-2026-16968 WPScan
5.4 Medium WP Custom HTML Pages Plugin Cross-Site Scripting Author+ Stored XSS ≤ 0.6.2 CVE-2026-16942 WPScan
10.0 Critical Custom Fields for WooCommerce Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal No login needed < 1.5.1 Fixed in 1.5.1 CVE-2026-16940 WPScan
2.7 Low MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint < 5.0.11 Fixed in 5.0.11 CVE-2026-16746 WPScan
7.5 High User Registration & Membership Plugin user-registration Broken Access Control Unauthenticated Account Creation While Registration Disabled No login needed < 5.2.6 Fixed in 5.2.6 CVE-2026-16736 WPScan
4.3 Medium GDPR Cookie Compliance Plugin gdpr-cookie-compliance Cross-Site Request Forgery Cookie Deletion and Forced Logout via CSRF No login needed < 5.1.0 Fixed in 5.1.0 CVE-2026-16613 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only