WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 2,851–2,900 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | MultiVendorX | Broken Access Control Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization |
< 5.0.11 Fixed in 5.0.11 |
CVE-2026-16605 |
WPScan | |
| 7.5 High | Content Protector (Passster) | Information Disclosure Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute No login needed |
< 4.3.6 Fixed in 4.3.6 |
CVE-2026-16604 |
WPScan | |
| 7.5 High | Content Protector (Passster) | Information Disclosure Unauthenticated Category-Locked Content Disclosure via Core REST API No login needed |
< 4.3.6 Fixed in 4.3.6 |
CVE-2026-16603 |
WPScan | |
| 7.5 High | Content Protector (Passster) | Information Disclosure Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint No login needed |
< 4.3.6 Fixed in 4.3.6 |
CVE-2026-16602 |
WPScan | |
| 6.1 Medium | Orbit Fox by ThemeIsle | Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed |
3.0.0 – < 3.0.8 Fixed in 3.0.8 |
CVE-2026-16583 |
WPScan | |
| 7.5 High | Bit Form | Cross-Site Scripting Unauthenticated Stored XSS via SVG Signature Upload No login needed |
< 3.2.0 Fixed in 3.2.0 |
CVE-2026-16573 |
WPScan | |
| 7.5 High | Sunshine Photo Cart | Information Disclosure Unauthenticated Private Gallery Comment Disclosure No login needed |
< 3.6.12 Fixed in 3.6.12 |
CVE-2026-16561 |
WPScan | |
| 4.9 Medium | PrettyLinks | SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter |
≤ 3.6.20 |
CVE-2026-5062 |
Wordfence | |
| 6.5 Medium | Relevanssi | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 2.30.2, ≤ 4.27.1 |
CVE-2026-15941 |
Wordfence | |
| 6.5 Medium | Cost Calculator Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure |
≤ 3.6.17 |
CVE-2026-7753 |
Wordfence | |
| 9.3 Critical | Membership Plugin – Kadence Memberships | Privilege Escalation Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover No login needed |
≤ 4.0.0 |
CVE-2026-9273 |
Wordfence | |
| 6.5 Medium | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | SQL Injection Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter |
≤ 1.17.4 |
CVE-2026-11421 |
Wordfence | |
| 6.1 Medium | Football Pool | Cross-Site Scripting Authenticated (Subscriber+) Reflected Cross-Site Scripting No login needed |
≤ 2.13.4 |
CVE-2026-8790 |
Wordfence | |
| 8.8 High | Smart Popup by Supsystic | Privilege Escalation Unauthenticated Privilege Escalation to Administrator |
≤ 1.12.0 |
CVE-2026-18322 |
Wordfence | |
| 7.5 High | VikAppointments – Services Booking Calendar | SQL Injection Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection No login needed |
≤ 1.2.19 |
CVE-2026-15918 |
Wordfence | |
| 7.2 High | VikRentItems Flexible Rental Management System | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.2.1 |
CVE-2026-16143 |
Wordfence | |
| 8.8 High | Dokan | Broken Access Control Missing Authorization to Authenticated (Vendor+) Privilege Escalation |
<=5.0.2 |
CVE-2026-8761 |
Wordfence | |
| 6.5 Medium | Bit Assist | Arbitrary File Upload Unauthenticated Arbitrary File Upload via Response Endpoint No login needed |
< 1.8.2 Fixed in 1.8.2 |
CVE-2026-16548 |
WPScan | |
| 5.9 Medium | REST API Log | Information Disclosure Unauthenticated Sensitive Log Data Disclosure via Download Endpoint No login needed |
< 1.7.1 Fixed in 1.7.1 |
CVE-2026-16547 |
WPScan | |
| 4.3 Medium | Wired Impact Volunteer Management | Broken Access Control Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp |
< 2.8.2 Fixed in 2.8.2 |
CVE-2026-16546 |
WPScan | |
| 4.7 Medium | Clearfy | Open Redirect Open Redirect via Cyrlitera 404 Handler No login needed |
< 2.4.3 Fixed in 2.4.3 |
CVE-2026-16296 |
WPScan | |
| 4.3 Medium | Clearfy | Information Disclosure Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher |
< 2.4.3 Fixed in 2.4.3 |
CVE-2026-16295 |
WPScan | |
| 6.8 Medium | Blubrry PowerPress | Cross-Site Scripting Contributor+ Stored XSS via Podcast Episode Chapters URL |
< 11.16.11 Fixed in 11.16.11 |
CVE-2026-16293 |
WPScan | |
| 2.7 Low | Brizy - Page Builder | Broken Access Control Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR |
< 2.8.19 Fixed in 2.8.19 |
CVE-2026-16070 |
WPScan | |
| 6.8 Medium | Brizy - Page Builder | Cross-Site Scripting Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point |
< 2.8.19 Fixed in 2.8.19 |
CVE-2026-16069 |
WPScan | |
| 3.5 Low | Brizy - Page Builder | Cross-Site Scripting Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset |
< 2.8.19 Fixed in 2.8.19 |
CVE-2026-16068 |
WPScan | |
| 4.3 Medium | Contest Gallery | Information Disclosure Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts |
< 30.0.7 Fixed in 30.0.7 |
CVE-2026-16056 |
WPScan | |
| 4.3 Medium | miniOrange 2FA | Broken Access Control Subscriber+ Arbitrary-Recipient OTP Send |
< 6.2.7 Fixed in 6.2.7 |
CVE-2026-16035 |
WPScan | |
| 9.3 Critical | Easy Dropbox Integration | Broken Access Control Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX No login needed |
< 2.2.0 Fixed in 2.2.0 |
CVE-2026-15958 |
WPScan | |
| 4.8 Medium | Nested Pages | Cross-Site Scripting Editor+ Stored XSS via Post Title |
< 3.2.15 Fixed in 3.2.15 |
CVE-2026-15233 |
WPScan | |
| 6.8 Medium | Visualizer: Tables and Charts Manager | Server-Side Request Forgery Contributor+ Server-Side Request Forgery via JSON Import |
< 4.0.6 Fixed in 4.0.6 |
CVE-2026-14939 |
WPScan | |
| 6.8 Medium | Database for Contact Form 7, WPforms, Elementor forms | SQL Injection Authenticated SQL Injection via id Parameter |
< 1.5.5 Fixed in 1.5.5 |
CVE-2026-14872 |
WPScan | |
| 5.4 Medium | Paid Member Subscriptions | Broken Access Control Subscriber+ Cross-User Subscription Hijack via process_checkout |
< 3.0.8 Fixed in 3.0.8 |
CVE-2026-14848 |
WPScan | |
| 4.8 Medium | Quiz And Survey Master | Cross-Site Scripting Contributor+ Stored XSS via Polar Question |
< 11.2.2 Fixed in 11.2.2 |
CVE-2026-14824 |
WPScan | |
| 6.5 Medium | The GDPR Framework | Broken Access Control Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam No login needed |
< 2.4.0 Fixed in 2.4.0 |
CVE-2026-14816 |
WPScan | |
| 4.3 Medium | wpForo Forum | Broken Access Control Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment |
< 3.1.3 Fixed in 3.1.3 |
CVE-2026-12698 |
WPScan | |
| 3.7 Low | MonsterInsights | Authentication Bypass Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass No login needed |
< 11.1.0 Fixed in 11.1.0 |
CVE-2026-11366 |
WPScan | |
| 5.8 Medium | EmbedPress | Server-Side Request Forgery Unauthenticated Blind SSRF No login needed |
< 4.6.1 Fixed in 4.6.1 |
CVE-2026-10526 |
WPScan | |
| 8.0 High | Create Block | Remote Code Execution Admin+ PHP Code Injection via Pattern Save (Multisite) |
< 2.10.0 Fixed in 2.10.0 |
CVE-2026-16623 |
WPScan | |
| 9.8 Critical | ImproveSEO | Arbitrary File Upload Unauthenticated Arbitrary File Upload Leading to Remote Code Execution No login needed |
≤ 2.0.11 |
CVE-2026-16618 |
WPScan | |
| 5.3 Medium | Simple Google Calendar Outlook Events Widget | Server-Side Request Forgery Unauthenticated SSRF via calendar_id No login needed |
< 3.1.0 Fixed in 3.1.0 |
CVE-2026-16536 |
WPScan | |
| 5.4 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Broken Access Control |
≤ 2.0.15 Fixed in 2.0.16 |
CVE-2026-28147 |
Patchstack | |
| 8.6 High | LogMyTrip | SQL Injection Unauthenticated SQL Injection via 'tid' Cookie No login needed |
≤ 1.9 |
CVE-2026-16572 |
WPScan | |
| 4.3 Medium | Dokan | Broken Access Control Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API |
< 5.0.9 Fixed in 5.0.9 |
CVE-2026-16565 |
WPScan | |
| 4.3 Medium | Dokan | Broken Access Control Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint |
< 5.0.9 Fixed in 5.0.9 |
CVE-2026-16564 |
WPScan | |
| 6.5 Medium | Academy LMS | Information Disclosure Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint |
< 3.8.3 Fixed in 3.8.3 |
CVE-2026-16563 |
WPScan | |
| 8.1 High | SM Page Duplicator | SQL Injection Editor+ SQL Injection via Page Duplication |
≤ 1.0.0 |
CVE-2026-16539 |
WPScan | |
| 9.8 Critical | Chama | Broken Access Control Unauthenticated Arbitrary User Password Reset No login needed |
< 1.0.13 Fixed in 1.0.13 |
CVE-2026-16300 |
WPScan | |
| 4.1 Medium | Clearfy | PHP Object Injection Admin+ PHP Object Injection via Settings Import |
< 2.4.3 Fixed in 2.4.3 |
CVE-2026-16297 |
WPScan | |
| 4.3 Medium | ProfileGrid | Information Disclosure Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group |
< 6.0.0.0 Fixed in 6.0.0.0 |
CVE-2026-16289 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.