WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,901–2,950 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 59 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Personal QR Message Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0 CVE-2026-16250 WPScan
9.8 Critical Insert or Embed Articulate Content into Plugin Arbitrary File Upload Editor+ Arbitrary File Upload No login needed ≤ 4.3000000027 CVE-2026-16060 WPScan
6.1 Medium Simple Membership Plugin simple-membership Cross-Site Scripting Unauthenticated Stored XSS via PayPal Subscription Subscriber Name No login needed < 4.7.8 Fixed in 4.7.8 CVE-2026-15931 WPScan
9.4 Critical Simple Membership Plugin simple-membership Privilege Escalation Unauthenticated Administrator Account Takeover via Registration Username Collision No login needed < 4.7.8 Fixed in 4.7.8 CVE-2026-15930 WPScan
6.1 Medium Blog Floating Button Plugin blog-floating-button Cross-Site Scripting Unauthenticated Stored XSS via User-Agent Header No login needed ≤ 1.4.20 CVE-2026-15383 WPScan
4.3 Medium Geo My WP Plugin geo-my-wp Broken Access Control Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR < 4.5.5.3 Fixed in 4.5.5.3 CVE-2026-15260 WPScan
2.7 Low TaxoPress Plugin Information Disclosure Contributor+ Private Post Disclosure via IDOR < 3.51.0 Fixed in 3.51.0 CVE-2026-15231 WPScan
9.1 Critical SoftMarket Plugin Privilege Escalation Unauthenticated Account Takeover via Email Verification Bypass No login needed ≤ 1.0.0 CVE-2026-14557 WPScan
6.1 Medium SVG Support Plugin svg-support Cross-Site Scripting Author+ Stored XSS via .svgz Sanitization Bypass No login needed < 2.5.17 Fixed in 2.5.17 CVE-2026-13340 WPScan
9.1 Critical Super Store Finder Plugin SQL Injection Unauthenticated SQL Injection via ssf_tracking No login needed < 7.11 Fixed in 7.11 CVE-2026-12965 WPScan
9.8 Critical Webinfos Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.2 CVE-2026-12872 WPScan
4.9 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Path Traversal Admin+ Arbitrary File Read < 2.4.3 Fixed in 2.4.3 CVE-2025-15673 WPScan
8.1 High Chama Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed < 1.0.13 Fixed in 1.0.13 CVE-2025-15672 WPScan
9.1 Critical Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Custom Role Privilege Escalation to Administrator via CSV Import No login needed < 2.4.2 Fixed in 2.4.2 CVE-2026-16534 WPScan
9.1 Critical Link Library Plugin link-library SQL Injection Unauthenticated SQL Injection via the Front-End Link Submission Form No login needed < 7.9.3 Fixed in 7.9.3 CVE-2026-16532 WPScan
2.7 Low Classified Listing Plugin classified-listing Information Disclosure Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search < 5.4.4 Fixed in 5.4.4 CVE-2026-16276 WPScan
2.7 Low Classified Listing Plugin classified-listing Information Disclosure Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts < 5.4.4 Fixed in 5.4.4 CVE-2026-16274 WPScan
6.5 Medium Contest Gallery Plugin contest-gallery Broken Access Control Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library < 30.0.7 Fixed in 30.0.7 CVE-2026-16057 WPScan
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Contributor+ Sensitive Data Disclosure via Admin Shortcode < 1.6.12.11 Fixed in 1.6.12.11 CVE-2026-15254 WPScan
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' ≤ 2.7.9.8 CVE-2026-12231 Wordfence
7.5 High Gallery for Google Photos Plugin Information Disclosure Unauthenticated Google OAuth Token Disclosure No login needed < 1.2.1 Fixed in 1.2.1 CVE-2026-15236 WPScan
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint No login needed < 1.6.12.6 Fixed in 1.6.12.6 CVE-2026-16540 WPScan
6.5 Medium WebToffee Cookie Consent Plugin Information Disclosure Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes No login needed < 3.5.3 Fixed in 3.5.3 CVE-2026-13389 WPScan
4.8 Medium Charitable Plugin charitable Cross-Site Scripting Admin+ Stored XSS via Photo Field ALT Text < 1.8.5.3 Fixed in 1.8.5.3 CVE-2025-15675 WPScan
5.4 Medium Frontend File Manager Plugin Cross-Site Request Forgery File Metadata Update via CSRF No login needed ≤ 23.6 CVE-2026-16292 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Arbitrary Notification Deletion via IDOR < 5.9.9.8 Fixed in 5.9.9.8 CVE-2026-16291 WPScan
7.5 High WooCommerce Product Attachment Plugin Broken Access Control Unauthenticated Arbitrary Media Download No login needed < 2.3.3 Fixed in 2.3.3 CVE-2026-16285 WPScan
5.4 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Broken Access Control Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event < 5.3.7 Fixed in 5.3.7 CVE-2026-16064 WPScan
5.4 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress Cross-Site Scripting Author+ Stored XSS via Event Timeline Content < 5.3.7 Fixed in 5.3.7 CVE-2026-16063 WPScan
6.6 Medium Event Booking Manager for WooCommerce Plugin mage-eventpress PHP Object Injection Contributor+ PHP Object Injection via Event Timeline and FAQ Content < 5.3.7 Fixed in 5.3.7 CVE-2026-16062 WPScan
4.6 Medium Narrative Publisher Plugin narrative-so Cross-Site Scripting Contributor+ Stored XSS via narrative_post_script Post Meta ≤ 1.0.7 CVE-2026-16273 WPScan
7.5 High Huge IT Login Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.4 CVE-2026-16261 WPScan
4.3 Medium LWS Optimize Plugin lws-optimize Broken Access Control Subscriber+ Cache Deletion < 3.4 Fixed in 3.4 CVE-2026-16042 WPScan
9.8 Critical Pouco Import Users Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.0 CVE-2026-16256 WPScan
2.7 Low Simple Restrict Plugin simple-restrict Information Disclosure Contributor+ Restricted Content Disclosure via REST API < 1.2.9 Fixed in 1.2.9 CVE-2026-15939 WPScan
5.4 Medium RT Mega Menu Plugin Cross-Site Scripting Subscriber+ Stored XSS via Menu Item CSS < 1.5.2 Fixed in 1.5.2 CVE-2026-15385 WPScan
6.8 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ DOM-Based Stored XSS via uikit Data Attributes < 8.7.13 Fixed in 8.7.13 CVE-2026-14817 WPScan
8.1 High Lenxel WP Theme Privilege Escalation Unauthenticated Account Takeover via Arbitrary Password Reset No login needed ≤ 1.0.31 CVE-2026-12586 WPScan
4.3 Medium Clever Mega Menu for Visual Composer Plugin Broken Access Control Subscriber+ Menu Item Meta Update via save_clever_menu_item ≤ 1.0.1 CVE-2026-11872 WPScan
5.5 Medium Meta Box Plugin meta-box Broken Access Control Contributor+ Arbitrary Attachment Deletion via IDOR < 5.13.1 Fixed in 5.13.1 CVE-2026-15248 WPScan
7.5 High ChatBot for eCommerce – WoowBot Plugin Broken Access Control WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response No login needed < 4.8.4 Fixed in 4.8.4 CVE-2026-15241 WPScan
7.5 High SMS Alert Order Notifications – WooCommerce Plugin Privilege Escalation WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile No login needed < 3.9.8 Fixed in 3.9.8 CVE-2026-15206 WPScan
7.5 High Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control Booking Manager+ Missing Authorization via rtb_reset_notifications No login needed < 2.7.23 Fixed in 2.7.23 CVE-2026-15151 WPScan
4.3 Medium FluentBoards Plugin fluent-boards Information Disclosure Subscriber+ Cross-Board Task Disclosure via IDOR < 1.95.3 Fixed in 1.95.3 CVE-2026-14938 WPScan
5.4 Medium JetEngine Plugin Cross-Site Scripting Contributor+ Stored XSS via jet_engine Shortcode < 3.8.12 Fixed in 3.8.12 CVE-2026-14864 WPScan
6.1 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Reflected XSS via Posts Grid Widget No login needed < 51.1.76 Fixed in 51.1.76 CVE-2026-14841 WPScan
7.5 High CubeWP Framework Plugin cubewp-framework Path Traversal Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter No login needed ≤ 1.1.30 CVE-2026-13339 Wordfence
9.8 Critical WooCommerce - Social Login Plugin Authentication Bypass Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT No login needed ≤ 2.8.7 CVE-2026-8457 Wordfence
7.5 High User Access Manager Plugin user-access-manager Path Traversal Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter No login needed ≤ 2.3.15 CVE-2026-18352 Wordfence
6.1 Medium Responsive Thumbnail Slider Plugin wp-responsive-thumbnail-slider Cross-Site Scripting Reflected Cross-Site Scripting via 'id' Parameter No login needed < 1.1.53 Fixed in 1.1.53 CVE-2026-18344 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only