WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 2,901–2,950 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.8 Critical | Personal QR Message | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.0 |
CVE-2026-16250 |
WPScan | |
| 9.8 Critical | Insert or Embed Articulate Content into | Arbitrary File Upload Editor+ Arbitrary File Upload No login needed |
≤ 4.3000000027 |
CVE-2026-16060 |
WPScan | |
| 6.1 Medium | Simple Membership | Cross-Site Scripting Unauthenticated Stored XSS via PayPal Subscription Subscriber Name No login needed |
< 4.7.8 Fixed in 4.7.8 |
CVE-2026-15931 |
WPScan | |
| 9.4 Critical | Simple Membership | Privilege Escalation Unauthenticated Administrator Account Takeover via Registration Username Collision No login needed |
< 4.7.8 Fixed in 4.7.8 |
CVE-2026-15930 |
WPScan | |
| 6.1 Medium | Blog Floating Button | Cross-Site Scripting Unauthenticated Stored XSS via User-Agent Header No login needed |
≤ 1.4.20 |
CVE-2026-15383 |
WPScan | |
| 4.3 Medium | Geo My WP | Broken Access Control Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR |
< 4.5.5.3 Fixed in 4.5.5.3 |
CVE-2026-15260 |
WPScan | |
| 2.7 Low | TaxoPress | Information Disclosure Contributor+ Private Post Disclosure via IDOR |
< 3.51.0 Fixed in 3.51.0 |
CVE-2026-15231 |
WPScan | |
| 9.1 Critical | SoftMarket | Privilege Escalation Unauthenticated Account Takeover via Email Verification Bypass No login needed |
≤ 1.0.0 |
CVE-2026-14557 |
WPScan | |
| 6.1 Medium | SVG Support | Cross-Site Scripting Author+ Stored XSS via .svgz Sanitization Bypass No login needed |
< 2.5.17 Fixed in 2.5.17 |
CVE-2026-13340 |
WPScan | |
| 9.1 Critical | Super Store Finder | SQL Injection Unauthenticated SQL Injection via ssf_tracking No login needed |
< 7.11 Fixed in 7.11 |
CVE-2026-12965 |
WPScan | |
| 9.8 Critical | Webinfos | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.2 |
CVE-2026-12872 |
WPScan | |
| 4.9 Medium | Import and export users and customers | Path Traversal Admin+ Arbitrary File Read |
< 2.4.3 Fixed in 2.4.3 |
CVE-2025-15673 |
WPScan | |
| 8.1 High | Chama | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
< 1.0.13 Fixed in 1.0.13 |
CVE-2025-15672 |
WPScan | |
| 9.1 Critical | Import and export users and customers | Privilege Escalation Custom Role Privilege Escalation to Administrator via CSV Import No login needed |
< 2.4.2 Fixed in 2.4.2 |
CVE-2026-16534 |
WPScan | |
| 9.1 Critical | Link Library | SQL Injection Unauthenticated SQL Injection via the Front-End Link Submission Form No login needed |
< 7.9.3 Fixed in 7.9.3 |
CVE-2026-16532 |
WPScan | |
| 2.7 Low | Classified Listing | Information Disclosure Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search |
< 5.4.4 Fixed in 5.4.4 |
CVE-2026-16276 |
WPScan | |
| 2.7 Low | Classified Listing | Information Disclosure Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts |
< 5.4.4 Fixed in 5.4.4 |
CVE-2026-16274 |
WPScan | |
| 6.5 Medium | Contest Gallery | Broken Access Control Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library |
< 30.0.7 Fixed in 30.0.7 |
CVE-2026-16057 |
WPScan | |
| 6.5 Medium | Simply Schedule Appointments | Information Disclosure Contributor+ Sensitive Data Disclosure via Admin Shortcode |
< 1.6.12.11 Fixed in 1.6.12.11 |
CVE-2026-15254 |
WPScan | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'exad_infobox_image' |
≤ 2.7.9.8 |
CVE-2026-12231 |
Wordfence | |
| 7.5 High | Gallery for Google Photos | Information Disclosure Unauthenticated Google OAuth Token Disclosure No login needed |
< 1.2.1 Fixed in 1.2.1 |
CVE-2026-15236 |
WPScan | |
| 7.5 High | Simply Schedule Appointments | Information Disclosure Unauthenticated Appointment Data Disclosure and Mass Deletion via purge Endpoint No login needed |
< 1.6.12.6 Fixed in 1.6.12.6 |
CVE-2026-16540 |
WPScan | |
| 6.5 Medium | WebToffee Cookie Consent | Information Disclosure Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes No login needed |
< 3.5.3 Fixed in 3.5.3 |
CVE-2026-13389 |
WPScan | |
| 4.8 Medium | Charitable | Cross-Site Scripting Admin+ Stored XSS via Photo Field ALT Text |
< 1.8.5.3 Fixed in 1.8.5.3 |
CVE-2025-15675 |
WPScan | |
| 5.4 Medium | Frontend File Manager | Cross-Site Request Forgery File Metadata Update via CSRF No login needed |
≤ 23.6 |
CVE-2026-16292 |
WPScan | |
| 4.3 Medium | ProfileGrid | Broken Access Control Subscriber+ Arbitrary Notification Deletion via IDOR |
< 5.9.9.8 Fixed in 5.9.9.8 |
CVE-2026-16291 |
WPScan | |
| 7.5 High | WooCommerce Product Attachment | Broken Access Control Unauthenticated Arbitrary Media Download No login needed |
< 2.3.3 Fixed in 2.3.3 |
CVE-2026-16285 |
WPScan | |
| 5.4 Medium | Event Booking Manager for WooCommerce | Broken Access Control Contributor+ Arbitrary Post Modification via mpwem_quick_edit_event |
< 5.3.7 Fixed in 5.3.7 |
CVE-2026-16064 |
WPScan | |
| 5.4 Medium | Event Booking Manager for WooCommerce | Cross-Site Scripting Author+ Stored XSS via Event Timeline Content |
< 5.3.7 Fixed in 5.3.7 |
CVE-2026-16063 |
WPScan | |
| 6.6 Medium | Event Booking Manager for WooCommerce | PHP Object Injection Contributor+ PHP Object Injection via Event Timeline and FAQ Content |
< 5.3.7 Fixed in 5.3.7 |
CVE-2026-16062 |
WPScan | |
| 4.6 Medium | Narrative Publisher | Cross-Site Scripting Contributor+ Stored XSS via narrative_post_script Post Meta |
≤ 1.0.7 |
CVE-2026-16273 |
WPScan | |
| 7.5 High | Huge IT Login | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 1.0.4 |
CVE-2026-16261 |
WPScan | |
| 4.3 Medium | LWS Optimize | Broken Access Control Subscriber+ Cache Deletion |
< 3.4 Fixed in 3.4 |
CVE-2026-16042 |
WPScan | |
| 9.8 Critical | Pouco Import Users | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.0.0 |
CVE-2026-16256 |
WPScan | |
| 2.7 Low | Simple Restrict | Information Disclosure Contributor+ Restricted Content Disclosure via REST API |
< 1.2.9 Fixed in 1.2.9 |
CVE-2026-15939 |
WPScan | |
| 5.4 Medium | RT Mega Menu | Cross-Site Scripting Subscriber+ Stored XSS via Menu Item CSS |
< 1.5.2 Fixed in 1.5.2 |
CVE-2026-15385 |
WPScan | |
| 6.8 Medium | Element Pack Elementor Addons | Cross-Site Scripting Contributor+ DOM-Based Stored XSS via uikit Data Attributes |
< 8.7.13 Fixed in 8.7.13 |
CVE-2026-14817 |
WPScan | |
| 8.1 High | Lenxel WP | Privilege Escalation Unauthenticated Account Takeover via Arbitrary Password Reset No login needed |
≤ 1.0.31 |
CVE-2026-12586 |
WPScan | |
| 4.3 Medium | Clever Mega Menu for Visual Composer | Broken Access Control Subscriber+ Menu Item Meta Update via save_clever_menu_item |
≤ 1.0.1 |
CVE-2026-11872 |
WPScan | |
| 5.5 Medium | Meta Box | Broken Access Control Contributor+ Arbitrary Attachment Deletion via IDOR |
< 5.13.1 Fixed in 5.13.1 |
CVE-2026-15248 |
WPScan | |
| 7.5 High | ChatBot for eCommerce – WoowBot | Broken Access Control WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_response No login needed |
< 4.8.4 Fixed in 4.8.4 |
CVE-2026-15241 |
WPScan | |
| 7.5 High | SMS Alert Order Notifications – WooCommerce | Privilege Escalation WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile No login needed |
< 3.9.8 Fixed in 3.9.8 |
CVE-2026-15206 |
WPScan | |
| 7.5 High | Five Star Restaurant Reservations | Broken Access Control Booking Manager+ Missing Authorization via rtb_reset_notifications No login needed |
< 2.7.23 Fixed in 2.7.23 |
CVE-2026-15151 |
WPScan | |
| 4.3 Medium | FluentBoards | Information Disclosure Subscriber+ Cross-Board Task Disclosure via IDOR |
< 1.95.3 Fixed in 1.95.3 |
CVE-2026-14938 |
WPScan | |
| 5.4 Medium | JetEngine | Cross-Site Scripting Contributor+ Stored XSS via jet_engine Shortcode |
< 3.8.12 Fixed in 3.8.12 |
CVE-2026-14864 |
WPScan | |
| 6.1 Medium | King Addons for Elementor | Cross-Site Scripting Reflected XSS via Posts Grid Widget No login needed |
< 51.1.76 Fixed in 51.1.76 |
CVE-2026-14841 |
WPScan | |
| 7.5 High | CubeWP Framework | Path Traversal Unauthenticated Arbitrary File Read via prev_icon/next_icon Parameter No login needed |
≤ 1.1.30 |
CVE-2026-13339 |
Wordfence | |
| 9.8 Critical | WooCommerce - Social Login | Authentication Bypass Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT No login needed |
≤ 2.8.7 |
CVE-2026-8457 |
Wordfence | |
| 7.5 High | User Access Manager | Path Traversal Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter No login needed |
≤ 2.3.15 |
CVE-2026-18352 |
Wordfence | |
| 6.1 Medium | Responsive Thumbnail Slider | Cross-Site Scripting Reflected Cross-Site Scripting via 'id' Parameter No login needed |
< 1.1.53 Fixed in 1.1.53 |
CVE-2026-18344 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.