WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 6,408 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High Charitable Plugin charitable SQL Injection ≤ 1.8.12.1 Fixed in 1.8.12.2 CVE-2026-81287 Patchstack
7.5 High Keep Backup Daily Plugin keep-backup-daily Information Disclosure Keep Backup Daily WordPress Plugin < 2.1.4 Sensitive Information Exposure via kbd_cron_process No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-75133 VulnCheck
8.1 High ProfilePress Plugin wp-user-avatar Remote Code Execution ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE No login needed < 4.17.2 Fixed in 4.17.2 CVE-2026-66047 VulnCheck
7.5 High Simple Payment Plugin simple-payment Broken Access Control No login needed ≤ 2.5.2 Fixed in 2.5.3 CVE-2026-81767 Patchstack
7.1 High JetEngine Plugin jet-engine Cross-Site Scripting No login needed ≤ 3.8.14.2 Fixed in 3.8.14.3 CVE-2026-81760 Patchstack
7.2 High Rank Math SEO Plugin seo-by-rank-math Remote Code Execution ≤ 1.0.276 Fixed in 1.0.277 CVE-2026-81757 Patchstack
7.5 High Smush Image Compression and Optimization Plugin wp-smushit Denial of Service Denial of Service Attack No login needed ≤ 4.2.0 Fixed in 4.3.0 CVE-2026-81285 Patchstack
8.5 High WPBulky Plugin wpbulky-wp-bulk-edit-post-types SQL Injection ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-82227 Patchstack
8.5 High Suggestion Engine for WooCommerce Plugin woo-suggestion-engine SQL Injection ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-81277 Patchstack
8.1 High FluentBooking Pro Plugin fluent-booking-pro Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-81273 Patchstack
8.8 High GeoDirectory Plugin geodirectory Cross-Site Request Forgery No login needed ≤ 2.8.176 Fixed in 2.8.177 CVE-2026-81271 Patchstack
7.5 High SureFeedback Client Site Plugin projecthuddle-child-site Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.12 Fixed in 1.2.13 CVE-2026-80433 Patchstack
7.1 High WP w3all phpBB Plugin wp-w3all-phpbb-integration Cross-Site Scripting No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-78293 Patchstack
7.1 High CozyStay Theme cozystay Cross-Site Scripting No login needed ≤ 1.10.0 Fixed in 1.10.1 CVE-2026-78289 Patchstack
8.5 High Like Button Rating Plugin likebtn-like-button SQL Injection ≤ 2.6.61 Fixed in 2.6.62 CVE-2026-78285 Patchstack
7.1 High Music Player for WooCommerce Plugin music-player-for-woocommerce Cross-Site Scripting No login needed ≤ 1.8.9 Fixed in 1.9.0 CVE-2026-78283 Patchstack
7.1 High CP Media Player Plugin audio-and-video-player Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-78281 Patchstack
7.2 High Fluent Boards Pro Plugin fluent-boards-pro PHP Object Injection ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78276 Patchstack
7.2 High FluentCRM Pro Plugin fluentcampaign-pro Privilege Escalation ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78271 Patchstack
7.1 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting No login needed ≤ 5.4.1 Fixed in 5.4.2 CVE-2026-78261 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
8.5 High ACPT (Pro) - Custom Post Types Plugin advanced-custom-post-type SQL Injection Custom Post Types Plugin for WordPress plugin <= 2.0.63 - SQL Injection ≤ 2.0.63 CVE-2026-32564 Patchstack
8.5 High Kadence Shop Kit Plugin kadence-shop-kit SQL Injection ≤ 3.0.6 Fixed in 3.0.6.1 CVE-2026-32550 Patchstack
8.6 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Broken Access Control No login needed ≤ 0.4.62 Fixed in 0.4.63 CVE-2026-27330 Patchstack
7.1 High Stripe Payments Plugin stripe-payments Cross-Site Scripting No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-78282 Patchstack
7.5 High Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads Plugin siteleads Information Disclosure SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-78268 Patchstack
7.1 High Toolset Blocks Plugin toolset-blocks Cross-Site Scripting No login needed ≤ 1.6.26 Fixed in 1.6.27 CVE-2026-78264 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting No login needed ≤ 5.29.2.1 Fixed in 5.29.3 CVE-2026-78263 Patchstack
7.3 High WPLegalPages Plugin wplegalpages Authentication Bypass Broken Authentication No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2026-78259 Patchstack
8.8 High Booking Hub Plugin booking-hub Privilege Escalation ≤ 1.3.0 CVE-2026-32561 Patchstack
8.8 High MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator Plugin magicai-wp Local File Inclusion AI Text, Image, Chat, Code, and Voice Generator plugin <= 1.4 - Local File Inclusion ≤ 1.4 CVE-2026-32560 Patchstack
7.1 High Boost Plugin boost Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2026-32556 Patchstack
8.6 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Arbitrary File Deletion No login needed ≤ 3.7.42 Fixed in 3.7.43 CVE-2026-78284 Patchstack
8.1 High Måne Theme mane Local File Inclusion No login needed ≤ 1.7 CVE-2026-66670 Patchstack
7.1 High Urna Theme urna Cross-Site Scripting No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2026-66610 Patchstack
7.5 High WP Cafe Pro Plugin wpcafe-pro Information Disclosure Sensitive Data Exposure No login needed < 3.0.15 Fixed in 3.0.15 CVE-2026-66585 Patchstack
8.5 High WP Project Manager Pro Plugin wedevs-project-manager-business SQL Injection ≤ 4.0.1 CVE-2026-32478 Patchstack
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
7.1 High Brave Conversion Engine (PRO) Plugin bravepopup-pro Cross-Site Scripting No login needed ≤ 0.8.6 Fixed in 0.8.7 CVE-2026-32476 Patchstack
8.5 High ProLancer Element Plugin prolancer-element SQL Injection ≤ 1.4.8 CVE-2026-32471 Patchstack
7.1 High ProLancer Element Plugin prolancer-element Broken Access Control ≤ 1.4.8 CVE-2026-28190 Patchstack
8.6 High WooCommerce File Approval Plugin woocommerce-file-approval Arbitrary File Deletion No login needed ≤ 10.7 CVE-2026-28171 Patchstack
7.5 High Super Forms Plugin super-forms Path Traversal Arbitrary File Download No login needed ≤ 6.3.315 CVE-2026-28167 Patchstack
7.1 High Tourmaster Plugin tourmaster Cross-Site Scripting No login needed ≤ 5.4.9 CVE-2026-28166 Patchstack
7.1 High Events Made Easy Plugin events-made-easy Cross-Site Scripting No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2026-28162 Patchstack
7.5 High Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More Plugin notification-master Broken Access Control Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 CVE-2026-28153 Patchstack
8.1 High Tonda Core Plugin tonda-core Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28152 Patchstack
8.1 High Tonda Theme tonda Local File Inclusion No login needed < 2.6 Fixed in 2.6 CVE-2026-28151 Patchstack
8.1 High Verdure Core Plugin verdure-core Local File Inclusion No login needed ≤ 1.2 CVE-2026-66671 Patchstack
7.6 High FluentCRM Pro Plugin fluentcampaign-pro SQL Injection ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78270 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only