WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,801–2,850 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 57 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter ≤ 1.7.1058 CVE-2026-6504 Wordfence
5.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter No login needed ≤ 5.1.5 CVE-2026-6145 Wordfence
5.3 Medium MW WP Form Plugin mw-wp-form Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'post_id' Query Parameter No login needed ≤ 5.1.2 CVE-2026-6206 Wordfence
6.4 Medium CC Child Pages Plugin cc-child-pages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'more' Parameter ≤ 2.1.1 CVE-2026-6174 Wordfence
6.5 Medium Media Sync Plugin media-sync Path Traversal Authenticated (Author+) Path Traversal via 'sub_dir' and 'media_items' Parameters ≤ 1.4.9 CVE-2026-6670 Wordfence
6.4 Medium Meta Field Block Plugin display-a-meta-field-as-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tagName' Block Attribute ≤ 1.5.2 CVE-2026-6252 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode ≤ 5.6.8 CVE-2026-3694 Wordfence
4.3 Medium LatePoint Plugin latepoint Cross-Site Request Forgery Cross-Site Request Forgery via 'customer_cabinet__request_cancellation' AJAX Route No login needed ≤ 5.3.2 CVE-2026-5365 Wordfence
6.5 Medium Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin taskbuilder SQL Injection Project Management & Task Management Tool With Kanban Board <= 5.0.6 - Authenticated (Subscriber+) Time-Based Blind SQL Injection via 'project_search' Parameter ≤ 5.0.6 CVE-2026-6225 Wordfence
6.5 Medium Essential Addons for Elementor – Popular Elementor Templates & Widgets Plugin essential-addons-for-elementor-lite Privilege Escalation Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user ≤ 6.5.13 CVE-2026-5193 Wordfence
5.4 Medium WP Encryption - One Click SSL & Force HTTPS Plugin Broken Access Control One Click SSL & Force HTTPS <= 7.8.5.10 - Missing Authorization to Authenticated (Subscriber+) SSL Setup Tampering ≤ 7.8.5.10 CVE-2026-3829 Wordfence
6.1 Medium MapGeo - Interactive Geo Maps Plugin Cross-Site Scripting Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter No login needed ≤ 1.6.27 CVE-2025-15345 Wordfence
6.1 Medium GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'failed_orders' No login needed ≤ 1.4.0 CVE-2026-6417 Wordfence
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget ≤ 6.4.11 CVE-2026-5243 Wordfence
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'arrows' Parameter ≤ 1.12.4 CVE-2026-5361 Wordfence
4.3 Medium LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Plugin learnpress Price Manipulation WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter ≤ 4.3.5 CVE-2026-7648 Wordfence
4.3 Medium My Calendar Plugin my-calendar Broken Access Control Authenticated (Custom+) Missing Authorization to Unauthorized Event Publication via 'event_approved' Parameter ≤ 3.7.9 CVE-2026-7525 Wordfence
6.5 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection via 'filter_search' Parameter ≤ 2.0.7 CVE-2026-5486 Wordfence
6.4 Medium WHOIS Domain Check Plugin powies-whois Cross-Site Scripting Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting 0.9.31 CVE-2020-37225 VulnCheck
5.5 Medium Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Cross-Site Scripting WOOF / Products Filter Professional for WooCommerce 1.2.3 Persistent XSS 1.2.3 CVE-2020-37174 VulnCheck
5.5 Medium ultimate-member Plugin Local File Inclusion WordPress Plugin ultimate-member 2.1.3 Local File Inclusion 2.1.3 CVE-2020-37169 VulnCheck
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Group Settings Modification ≤ 5.9.8.4 CVE-2026-4607 Wordfence
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection Authenticated (Subscriber+) SQL Injection via 'rid' Parameter ≤ 5.9.8.4 CVE-2026-4608 Wordfence
4.3 Medium RTMKit Addons for Elementor Plugin rometheme-for-elementor Broken Access Control Authenticated (Author+) Missing Authorization to Widget Configuration Modification ≤ 2.0.2 CVE-2026-3426 Wordfence
6.5 Medium Avada Builder Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter ≤ 3.15.2 CVE-2026-4782 Wordfence
5.3 Medium Hostinger Reach Plugin hostinger-reach Broken Access Control Missing Authorization to Authenticated (Subscriber+) Integration API Key Update ≤ 1.3.8 CVE-2026-2515 Wordfence
6.4 Medium Snow Monkey Blocks Plugin snow-monkey-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-slick' Attribute ≤ 24.1.11 CVE-2026-3004 Wordfence
5.5 Medium WPC Badge Management for WooCommerce Plugin wpc-badge-management Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute ≤ 3.1.6 CVE-2025-14767 Wordfence
5.3 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter No login needed ≤ 3.9.9 CVE-2026-6965 Wordfence
5.3 Medium ilGhera Support System for WooCommerce Plugin wc-support-system Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.3.0 CVE-2025-14033 Wordfence
5.4 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Broken Access Control Missing Authorization to Authenticated (Subscriber+) Delete Arbitrary B2S Post Records via 'postId' Parameter ≤ 8.9.0 CVE-2026-7051 Wordfence
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute ≤ 6.2.1 CVE-2026-6828 Wordfence
4.4 Medium Broadstreet Plugin broadstreet Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.53.1 CVE-2025-9989 Wordfence
6.4 Medium Cost of Goods: Product Cost & Profit Calculator for WooCommerce Plugin cost-of-goods-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2026-6962 Wordfence
5.3 Medium Broadstreet Plugin broadstreet Information Disclosure Authenticated (Subscriber+) Information Disclosure No login needed ≤ 1.53.1 CVE-2025-9987 Wordfence
6.5 Medium Charitable Plugin charitable SQL Injection Authenticated (Custom+) SQL Injection via 's' Search Parameter ≤ 1.8.10.4 CVE-2026-7619 Wordfence
4.3 Medium Broadstreet Plugin broadstreet Broken Access Control Missing Authorization to Authenticated (Subscriber+) Advertiser Creation ≤ 1.53.1 CVE-2025-9988 Wordfence
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Price Manipulation Unauthenticated Price Manipulation and Insecure Direct Object Reference No login needed ≤ 4.0.1 CVE-2025-14755 Wordfence
6.5 Medium Advanced Custom Fields: Extended Plugin acf-extended Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.9.2.3 CVE-2025-15463 Wordfence
5.3 Medium Hustle Plugin wordpress-popup Broken Access Control No login needed ≤ 7.8.10.1 Fixed in 7.8.10.2 CVE-2026-25431 Patchstack
5.3 Medium WP EasyPay Plugin wp-easy-pay Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.0 Fixed in 4.4.0 CVE-2026-45215 Patchstack
5.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control No login needed ≤ 1.4.0.3 Fixed in 1.4.0.4 CVE-2026-45212 Patchstack
5.4 Medium Broadstreet Ads Plugin broadstreet Broken Access Control ≤ 1.52.2 Fixed in 1.53.2 CVE-2026-45210 Patchstack
4.4 Medium Continually Plugin continually Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'continually_embed_code' Parameter ≤ 4.3.1 CVE-2026-6813 Wordfence
4.4 Medium FastBots Plugin fastbots-ai-chatbots Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.0.12 CVE-2026-6800 Wordfence
4.3 Medium Motors – Car Dealership & Classified Listings Plugin motors-car-dealership-classified-listings Broken Access Control Car Dealership & Classified Listings Plugin <= 1.4.103 - Missing Authorization to Authenticated (Subscriber+) Payment Bypass via 'stm_payment_status' Parameter ≤ 1.4.103 CVE-2026-1934 Wordfence
6.4 Medium BJ Lazy Load Plugin bj-lazy-load Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom HTML Block ≤ 1.0.9 CVE-2026-2300 Wordfence
6.1 Medium WP Google Maps Integration Plugin wp-google-maps-integration Cross-Site Scripting Reflected Cross-Site Scripting via 'page' Parameter No login needed ≤ 1.2 CVE-2026-7464 Wordfence
6.4 Medium scratchblocks for WP Plugin scratchblocks-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'element' Shortcode Attribute ≤ 1.0.1 CVE-2026-6247 Wordfence
6.5 Medium Eight Day Week Print Workflow Plugin eight-day-week-print-workflow SQL Injection Authenticated (Subscriber+) SQL Injection via 'title' Parameter ≤ 1.2.6 CVE-2026-5028 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only