WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,851–2,900 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 58 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing Authorization < 5.0.11 Fixed in 5.0.11 CVE-2026-16605 WPScan
7.5 High Content Protector (Passster) Plugin Information Disclosure Unauthenticated Protected Content Disclosure via Content-Lock Block data-content Attribute No login needed < 4.3.6 Fixed in 4.3.6 CVE-2026-16604 WPScan
7.5 High Content Protector (Passster) Plugin Information Disclosure Unauthenticated Category-Locked Content Disclosure via Core REST API No login needed < 4.3.6 Fixed in 4.3.6 CVE-2026-16603 WPScan
7.5 High Content Protector (Passster) Plugin Information Disclosure Unauthenticated Non-Public Post Content Disclosure via Captcha REST Endpoint No login needed < 4.3.6 Fixed in 4.3.6 CVE-2026-16602 WPScan
6.1 Medium Orbit Fox by ThemeIsle Plugin Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed 3.0.0 – < 3.0.8 Fixed in 3.0.8 CVE-2026-16583 WPScan
7.5 High Bit Form Plugin bit-form Cross-Site Scripting Unauthenticated Stored XSS via SVG Signature Upload No login needed < 3.2.0 Fixed in 3.2.0 CVE-2026-16573 WPScan
7.5 High Sunshine Photo Cart Plugin sunshine-photo-cart Information Disclosure Unauthenticated Private Gallery Comment Disclosure No login needed < 3.6.12 Fixed in 3.6.12 CVE-2026-16561 WPScan
4.9 Medium PrettyLinks Plugin pretty-link SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 3.6.20 CVE-2026-5062 Wordfence
6.5 Medium Relevanssi Plugin relevanssi SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.30.2, ≤ 4.27.1 CVE-2026-15941 Wordfence
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure ≤ 3.6.17 CVE-2026-7753 Wordfence
9.3 Critical Membership Plugin – Kadence Memberships Plugin restrict-content Privilege Escalation Kadence Memberships <= 4.0.0 - Unauthenticated Password Reset Link Poisoning to Account Takeover No login needed ≤ 4.0.0 CVE-2026-9273 Wordfence
6.5 Medium ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support Plugin erp SQL Injection Authenticated (Custom+) SQL Injection via 'erpadvancefilter' Parameter ≤ 1.17.4 CVE-2026-11421 Wordfence
6.1 Medium Football Pool Plugin football-pool Cross-Site Scripting Authenticated (Subscriber+) Reflected Cross-Site Scripting No login needed ≤ 2.13.4 CVE-2026-8790 Wordfence
8.8 High Smart Popup by Supsystic Plugin popup-by-supsystic Privilege Escalation Unauthenticated Privilege Escalation to Administrator ≤ 1.12.0 CVE-2026-18322 Wordfence
7.5 High VikAppointments – Services Booking Calendar Plugin vikappointments SQL Injection Services Booking Calendar <= 1.2.19 - Unauthenticated SQL Injection No login needed ≤ 1.2.19 CVE-2026-15918 Wordfence
7.2 High VikRentItems Flexible Rental Management System Plugin vikrentitems Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2026-16143 Wordfence
8.8 High Dokan Plugin dokan-lite Broken Access Control Missing Authorization to Authenticated (Vendor+) Privilege Escalation <=5.0.2 CVE-2026-8761 Wordfence
6.5 Medium Bit Assist Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload via Response Endpoint No login needed < 1.8.2 Fixed in 1.8.2 CVE-2026-16548 WPScan
5.9 Medium REST API Log Plugin wp-rest-api-log Information Disclosure Unauthenticated Sensitive Log Data Disclosure via Download Endpoint No login needed < 1.7.1 Fixed in 1.7.1 CVE-2026-16547 WPScan
4.3 Medium Wired Impact Volunteer Management Plugin wired-impact-volunteer-management Broken Access Control Subscriber+ Arbitrary RSVP Removal via wivm_remove_rsvp < 2.8.2 Fixed in 2.8.2 CVE-2026-16546 WPScan
4.7 Medium Clearfy Plugin Open Redirect Open Redirect via Cyrlitera 404 Handler No login needed < 2.4.3 Fixed in 2.4.3 CVE-2026-16296 WPScan
4.3 Medium Clearfy Plugin Information Disclosure Subscriber+ Sensitive Information Disclosure via Factory Page-Action Dispatcher < 2.4.3 Fixed in 2.4.3 CVE-2026-16295 WPScan
6.8 Medium Blubrry PowerPress Plugin Cross-Site Scripting Contributor+ Stored XSS via Podcast Episode Chapters URL < 11.16.11 Fixed in 11.16.11 CVE-2026-16293 WPScan
2.7 Low Brizy - Page Builder Plugin Broken Access Control Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR < 2.8.19 Fixed in 2.8.19 CVE-2026-16070 WPScan
6.8 Medium Brizy - Page Builder Plugin Cross-Site Scripting Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point < 2.8.19 Fixed in 2.8.19 CVE-2026-16069 WPScan
3.5 Low Brizy - Page Builder Plugin Cross-Site Scripting Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Code Asset < 2.8.19 Fixed in 2.8.19 CVE-2026-16068 WPScan
4.3 Medium Contest Gallery Plugin contest-gallery Information Disclosure Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts < 30.0.7 Fixed in 30.0.7 CVE-2026-16056 WPScan
4.3 Medium miniOrange 2FA Plugin miniorange-2-factor-authentication Broken Access Control Subscriber+ Arbitrary-Recipient OTP Send < 6.2.7 Fixed in 6.2.7 CVE-2026-16035 WPScan
9.3 Critical Easy Dropbox Integration Plugin Broken Access Control Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAX No login needed < 2.2.0 Fixed in 2.2.0 CVE-2026-15958 WPScan
4.8 Medium Nested Pages Plugin wp-nested-pages Cross-Site Scripting Editor+ Stored XSS via Post Title < 3.2.15 Fixed in 3.2.15 CVE-2026-15233 WPScan
6.8 Medium Visualizer: Tables and Charts Manager Plugin Server-Side Request Forgery Contributor+ Server-Side Request Forgery via JSON Import < 4.0.6 Fixed in 4.0.6 CVE-2026-14939 WPScan
6.8 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries SQL Injection Authenticated SQL Injection via id Parameter < 1.5.5 Fixed in 1.5.5 CVE-2026-14872 WPScan
5.4 Medium Paid Member Subscriptions Plugin Broken Access Control Subscriber+ Cross-User Subscription Hijack via process_checkout < 3.0.8 Fixed in 3.0.8 CVE-2026-14848 WPScan
4.8 Medium Quiz And Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS via Polar Question < 11.2.2 Fixed in 11.2.2 CVE-2026-14824 WPScan
6.5 Medium The GDPR Framework Plugin gdpr-framework Broken Access Control Unauthenticated Consent Record Forgery and Do Not Sell Requests Spam No login needed < 2.4.0 Fixed in 2.4.0 CVE-2026-14816 WPScan
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Subscriber+ Account Status and Reputation Manipulation via Profile Update Mass Assignment < 3.1.3 Fixed in 3.1.3 CVE-2026-12698 WPScan
3.7 Low MonsterInsights Plugin google-analytics-for-wordpress Authentication Bypass Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-11366 WPScan
5.8 Medium EmbedPress Plugin embedpress Server-Side Request Forgery Unauthenticated Blind SSRF No login needed < 4.6.1 Fixed in 4.6.1 CVE-2026-10526 WPScan
8.0 High Create Block Plugin Remote Code Execution Admin+ PHP Code Injection via Pattern Save (Multisite) < 2.10.0 Fixed in 2.10.0 CVE-2026-16623 WPScan
9.8 Critical ImproveSEO Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload Leading to Remote Code Execution No login needed ≤ 2.0.11 CVE-2026-16618 WPScan
5.3 Medium Simple Google Calendar Outlook Events Widget Plugin simple-google-icalendar-widget Server-Side Request Forgery Unauthenticated SSRF via calendar_id No login needed < 3.1.0 Fixed in 3.1.0 CVE-2026-16536 WPScan
5.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.15 Fixed in 2.0.16 CVE-2026-28147 Patchstack
8.6 High LogMyTrip Plugin SQL Injection Unauthenticated SQL Injection via 'tid' Cookie No login needed ≤ 1.9 CVE-2026-16572 WPScan
4.3 Medium Dokan Plugin Broken Access Control Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API < 5.0.9 Fixed in 5.0.9 CVE-2026-16565 WPScan
4.3 Medium Dokan Plugin Broken Access Control Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint < 5.0.9 Fixed in 5.0.9 CVE-2026-16564 WPScan
6.5 Medium Academy LMS Plugin academy Information Disclosure Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint < 3.8.3 Fixed in 3.8.3 CVE-2026-16563 WPScan
8.1 High SM Page Duplicator Plugin SQL Injection Editor+ SQL Injection via Page Duplication ≤ 1.0.0 CVE-2026-16539 WPScan
9.8 Critical Chama Plugin Broken Access Control Unauthenticated Arbitrary User Password Reset No login needed < 1.0.13 Fixed in 1.0.13 CVE-2026-16300 WPScan
4.1 Medium Clearfy Plugin PHP Object Injection Admin+ PHP Object Injection via Settings Import < 2.4.3 Fixed in 2.4.3 CVE-2026-16297 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group < 6.0.0.0 Fixed in 6.0.0.0 CVE-2026-16289 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only