WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 2,801–2,850 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | FluentSMTP | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs No login needed |
≤ 2.2.95 |
CVE-2026-16636 |
Wordfence | |
| 8.1 High | Content Egg | Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion |
≤ 11.3.0 |
CVE-2026-15979 |
Wordfence | |
| 7.2 High | Independent Analytics | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 2.15.0 |
CVE-2026-17506 |
Wordfence | |
| 7.5 High | wiseCampaign | Broken Access Control Missing Authorization to Unauthenticated Plugin Configuration Modification via REST API No login needed |
≤ 1.1.16 |
CVE-2026-7529 |
Wordfence | |
| 6.5 Medium | Udimi Tools | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Configuration Reset via 'disconnect' AJAX Action |
≤ 3.2 |
CVE-2026-7456 |
Wordfence | |
| 7.2 High | wp-downloadmanager | Arbitrary File Upload Unrestricted File Upload via Missing Extension/MIME Validation and Path Traversal |
≤ 1.69 |
CVE-2026-18933 |
TuranSec | |
| 4.7 Medium | Smash Balloon Social Photo Feed | Cross-Site Scripting Reflected Cross-Site Scripting via REQUEST_URI Query String No login needed |
≤ 6.11.3 |
CVE-2026-15452 |
Wordfence | |
| 6.5 Medium | WP Post Author | SQL Injection Authenticated (Author+) SQL Injection |
≤ 3.9.1 |
CVE-2026-11977 |
Wordfence | |
| 4.9 Medium | JoomSport | SQL Injection Authenticated (Administrator+) SQL Injection via 'order' Parameter |
≤ 5.7.9 |
CVE-2026-11920 |
Wordfence | |
| 8.1 High | MailChimp Forms by MailMunch | Broken Access Control Missing Authorization to Authenticated (Subscriber+) MailMunch Integration Takeover via 'sign_in' AJAX Action |
≤ 3.2.7 |
CVE-2026-7520 |
Wordfence | |
| 4.9 Medium | WP TripAdvisor Review Slider | SQL Injection Authenticated (Administrator+) SQL Injection |
≤ 14.3 |
CVE-2026-11969 |
Wordfence | |
| 7.2 High | ShopLentor | Other Authenticated (Administrator+) Arbitrary Function Execution via 'callback' Parameter via REST API |
≤ 3.3.7 |
CVE-2026-6020 |
Wordfence | |
| 9.1 Critical | Easy Post Submission | Broken Access Control Missing Authorization No login needed |
≤ 2.3.0 |
CVE-2026-4431 |
Wordfence | |
| 7.5 High | Page and Post Restriction | Broken Access Control Unauthenticated Missing Authorization to Sensitive Information Exposure via REST API No login needed |
≤ 1.4.1 |
CVE-2026-12000 |
Wordfence | |
| 4.3 Medium | Xpro Addons | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Creation via get_menu_content_editor() Function |
≤ 1.5.1 |
CVE-2026-7105 |
Wordfence | |
| 8.1 High | Search Analytics for WP | Cross-Site Request Forgery No login needed |
≤ 1.4.16 |
CVE-2026-7444 |
Wordfence | |
| 6.4 Medium | Simple Yearly Archive | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.4 |
CVE-2026-7441 |
Wordfence | |
| 6.4 Medium | SKT Skill Bar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6 |
CVE-2026-6972 |
Wordfence | |
| 4.9 Medium | Askeet | SQL Injection Authenticated (Administrator+) SQL Injection via 'sql_query' Parameter |
≤ 3.0 |
CVE-2026-5651 |
Wordfence | |
| 7.5 High | TableOn | SQL Injection Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter No login needed |
≤ 1.0.5.1 |
CVE-2026-18881 |
Wordfence | |
| 7.2 High | Backup Migration | Remote Code Execution Authenticated (Administrator+) OS Command Injection via 'file' Parameter |
≤ 2.1.1 |
CVE-2026-7693 |
Wordfence | |
| 8.8 High | LightSync Pro | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload |
≤ 2.1.6 |
CVE-2026-6147 |
Wordfence | |
| 6.1 Medium | TranslatePress | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.2.5 |
CVE-2026-17505 |
Wordfence | |
| 6.5 Medium | User Access Manager | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 2.3.12 |
CVE-2026-15281 |
Wordfence | |
| 6.1 Medium | Seraphinite Accelerator | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.29.18 |
CVE-2026-17532 |
Wordfence | |
| 6.5 Medium | Groundhogg — CRM, Newsletters, and Marketing Automation | Broken Access Control Insecure Direct Object Reference |
≤ 4.5.2 |
CVE-2026-11454 |
Wordfence | |
| 4.4 Medium | Contact Form 7 – Dynamic Text Extension | Cross-Site Scripting Dynamic Text Extension <= 5.0.5 - Authenticated (Editor+) Stored Cross-Site Scripting |
≤ 5.0.5 |
CVE-2026-5116 |
Wordfence | |
| 8.2 High | WPFormify | Broken Access Control Missing Authorization No login needed |
≤ 1.1.1 |
CVE-2026-6627 |
Wordfence | |
| 7.3 High | Material Dashboard | Broken Access Control Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion No login needed |
≤ 1.4.10 |
CVE-2026-6079 |
Wordfence | |
| 6.5 Medium | Layouts for WPBakery | Broken Access Control Missing Authorization to Unauthenticated Template Cache Manipulation via 'handle_sync' AJAX Action No login needed |
≤ 1.1.3 |
CVE-2026-7726 |
Wordfence | |
| 7.5 High | AI Chatbot & Workflow Automation by AIWU | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.4.6 |
CVE-2026-6639 |
Wordfence | |
| 9.1 Critical | Multi Uploader for Gravity Forms | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Media Deletion No login needed |
≤ 1.1.8 |
CVE-2026-5581 |
Wordfence | |
| 4.4 Medium | Super Progressive Web Apps | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting |
≤ 2.2.43 |
CVE-2026-5108 |
Wordfence | |
| 4.3 Medium | MLS Import | Information Disclosure Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_item |
< 7.0.4 Fixed in 7.0.4 |
CVE-2026-17515 |
WPScan | |
| 7.5 High | Contest Gallery | Authentication Bypass Unauthenticated Login-Protection and 2FA Bypass via post_cg_login |
< 30.0.7 Fixed in 30.0.7 |
CVE-2026-16055 |
WPScan | |
| 7.5 High | miniOrange 2FA | Authentication Bypass miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding No login needed |
< 6.2.7 Fixed in 6.2.7 |
CVE-2026-16036 |
WPScan | |
| 7.5 High | WP 2FA | Authentication Bypass Two-Factor Authentication Bypass via Passkeys Provider No login needed |
< 4.1.0 Fixed in 4.1.0 |
CVE-2026-15372 |
WPScan | |
| 9.1 Critical | Ajax Load More | SQL Injection Unauthenticated SQL Injection via custom_args No login needed |
< 8.0.1 Fixed in 8.0.1 |
CVE-2026-15360 |
WPScan | |
| 9.1 Critical | Login/Signup with Phone Number, OTP Verification | Privilege Escalation Unauthenticated Account Takeover via OTP Brute Force No login needed |
< 1.8.71 Fixed in 1.8.71 |
CVE-2026-15210 |
WPScan | |
| 3.7 Low | DHL for WooCommerce | Information Disclosure Unauthenticated Shipping Label Disclosure via Unprotected Uploads Directory No login needed |
< 4.0.1 Fixed in 4.0.1 |
CVE-2026-16993 |
WPScan | |
| 5.3 Medium | DHL for WooCommerce | Broken Access Control Unauthenticated Shipping Label Download via IDOR No login needed |
< 4.0.1 Fixed in 4.0.1 |
CVE-2026-16981 |
WPScan | |
| 8.1 High | YayPricing | Information Disclosure Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure |
< 3.5.7 Fixed in 3.5.7 |
CVE-2026-15230 |
WPScan | |
| 8.1 High | Zportals | Arbitrary File Upload Subscriber+ Arbitrary File Upload |
< 6.3.4 Fixed in 6.3.4 |
CVE-2026-14553 |
WPScan | |
| 3.5 Low | GeoDirectory | Cross-Site Scripting Editor+ Stored XSS via Place Categories |
< 2.8.110 Fixed in 2.8.110 |
CVE-2025-15677 |
WPScan | |
| 6.5 Medium | GeoDirectory | Information Disclosure Contributor+ User Email Disclosure via geodir_json_search_users |
< 2.8.168 Fixed in 2.8.168 |
CVE-2026-16968 |
WPScan | |
| 5.4 Medium | WP Custom HTML Pages | Cross-Site Scripting Author+ Stored XSS |
≤ 0.6.2 |
CVE-2026-16942 |
WPScan | |
| 10.0 Critical | Custom Fields for WooCommerce | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal No login needed |
< 1.5.1 Fixed in 1.5.1 |
CVE-2026-16940 |
WPScan | |
| 2.7 Low | MultiVendorX | Information Disclosure Store Owner+ Cross-Store Commission Data Disclosure via commissions REST Endpoint |
< 5.0.11 Fixed in 5.0.11 |
CVE-2026-16746 |
WPScan | |
| 7.5 High | User Registration & Membership | Broken Access Control Unauthenticated Account Creation While Registration Disabled No login needed |
< 5.2.6 Fixed in 5.2.6 |
CVE-2026-16736 |
WPScan | |
| 4.3 Medium | GDPR Cookie Compliance | Cross-Site Request Forgery Cookie Deletion and Forced Logout via CSRF No login needed |
< 5.1.0 Fixed in 5.1.0 |
CVE-2026-16613 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.