WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Business Directory Plugin business-directory-plugin Broken Access Control No login needed ≤ 6.4.26 Fixed in 6.4.27 CVE-2026-84758 Patchstack
6.5 Medium Mail Mint Plugin mail-mint Broken Access Control No login needed ≤ 1.31.0 Fixed in 1.31.1 CVE-2026-84755 Patchstack
6.5 Medium WPFunnels Plugin wpfunnels Broken Access Control No login needed ≤ 3.12.13 Fixed in 3.13.0 CVE-2026-84754 Patchstack
6.5 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.61 Fixed in 1.0.62 CVE-2026-84215 Patchstack
6.5 Medium Product Variations Swatches for WooCommerce Plugin product-variations-swatches-for-woocommerce Cross-Site Scripting ≤ 1.1.18 Fixed in 1.1.19 CVE-2026-81282 Patchstack
6.5 Medium Graphene Theme graphene Cross-Site Scripting ≤ 2.9.4 Fixed in 2.9.6 CVE-2026-81281 Patchstack
6.5 Medium Pre-Orders for WooCommerce Plugin pre-orders-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3 CVE-2026-84849 Patchstack
5.8 Medium Enfold Theme enfold Cross-Site Scripting No login needed ≤ 8.0 Fixed in 8.1 CVE-2026-84815 Patchstack
6.4 Medium SEOWriting Plugin seowriting Cross-Site Scripting SEOWriting WordPress Plugin 1.12.5 Stored XSS via iframe onload ≤ 1.12.5 CVE-2026-75134 VulnCheck
5.3 Medium Notification Bar Plugin Information Disclosure Unauthenticated Subscriber Data Disclosure No login needed ≤ 1.1.8 CVE-2025-15481 WPScan
5.4 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 6.1.3 Fixed in 6.1.5 CVE-2026-84217 Patchstack
5.3 Medium Rentsyst Plugin rentsyst Broken Access Control No login needed ≤ 2.1.5 CVE-2026-84835 Patchstack
5.4 Medium Grand Tour Theme grandtour Cross-Site Request Forgery No login needed ≤ 5.5.1 CVE-2026-66652 Patchstack
5.3 Medium WP Go Maps Plugin wp-google-maps Denial of Service Denial of Service Attack No login needed ≤ 10.1.08 Fixed in 10.1.09 CVE-2026-84780 Patchstack
5.3 Medium Really Simple SSL Plugin really-simple-ssl Denial of Service Denial of Service Attack No login needed ≤ 9.8.0 Fixed in 9.8.1 CVE-2026-84775 Patchstack
5.5 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery ≤ 2.4.14 Fixed in 2.4.14.1 CVE-2026-84772 Patchstack
5.3 Medium PublishPress Permissions Plugin press-permit-core Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.3 Fixed in 4.8.4 CVE-2026-84771 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2026-84760 Patchstack
6.5 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting ≤ 3.8.2 Fixed in 3.8.3 CVE-2026-83562 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Broken Access Control No login needed ≤ 4.1.22 Fixed in 4.1.23 CVE-2026-82223 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-84781 Patchstack
5.4 Medium Post SMTP Plugin post-smtp Broken Access Control Settings Change 4.0.0 – beta.1 Fixed in 4.0.1 CVE-2026-81278 Patchstack
6.5 Medium Kalles Addons Plugin kalles-addons Cross-Site Scripting ≤ 1.0.6 CVE-2026-81778 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-81762 Patchstack
6.3 Medium OwnerRez API Plugin ownerrez Broken Access Control ≤ 1.2.6 Fixed in 1.3.0 CVE-2026-81758 Patchstack
5.4 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Server-Side Request Forgery No login needed ≤ 8.15.0 CVE-2026-82852 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Information Disclosure Sensitive Data Exposure ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-81280 Patchstack
5.3 Medium bbPress Plugin bbpress Broken Access Control No login needed ≤ 2.6.14 CVE-2026-74010 Patchstack
5.3 Medium Forminator Plugin forminator Other Other vulnerability Type No login needed ≤ 1.57.1 Fixed in 1.57.2 CVE-2026-82220 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Broken Access Control ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-81761 Patchstack
5.4 Medium WpEvently Plugin mage-eventpress Broken Access Control ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-81759 Patchstack
4.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.5.9 Fixed in 2.6.0 CVE-2026-81299 Patchstack
4.3 Medium ACF Extended Plugin acf-extended Broken Access Control ≤ 0.9.2.6 Fixed in 0.9.2.7 CVE-2026-81284 Patchstack
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Authentication Bypass Bypass vulnerability No login needed ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-81777 Patchstack
5.4 Medium Spiffy Plugin Cross-Site Scripting WordPress plugin (Spiffy Plugin) before 5.0.9 is affected by Stored Cross-Site Scripting in Event Title field. An authenticated attacker with the lowest privileged role (contribut… Not stated CVE-2026-39071 mitre
4.8 Medium Bit Assist Plugin Cross-Site Scripting WordPress plugin (Bit Assist) before 1.7.2 is affected by Stored Cross-Site Scripting in Call-To-Action feature. An authenticated attacker with the privileged role (admin) can exp… Not stated CVE-2026-39070 mitre
5.3 Medium Kali Forms Plugin kali-forms Broken Access Control No login needed ≤ 2.4.23 Fixed in 2.4.24 CVE-2026-81276 Patchstack
5.3 Medium Ditty Plugin ditty-news-ticker Broken Access Control No login needed ≤ 3.1.67 Fixed in 3.1.69 CVE-2026-81274 Patchstack
4.9 Medium FluentPlayer Pro Plugin fluent-player-pro Broken Access Control ≤ 1.3.2 Fixed in 1.4.0 CVE-2026-81272 Patchstack
6.8 Medium Fluent Boards Pro Plugin fluent-boards-pro Arbitrary File Deletion ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78275 Patchstack
6.5 Medium Fluent Boards Pro Plugin fluent-boards-pro Cross-Site Scripting ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78273 Patchstack
5.4 Medium Push Notification for Post and BuddyPress Plugin push-notification-for-post-and-buddypress Broken Access Control ≤ 3.20 Fixed in 3.21 CVE-2026-81279 Patchstack
6.4 Medium Password Protect WordPress Lite Plugin password-protect-page Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.21 CVE-2025-9878 Wordfence
6.5 Medium AutomatorWP Plugin automatorwp Broken Access Control ≤ 5.8.3 Fixed in 5.8.4 CVE-2026-78266 Patchstack
6.5 Medium Style Kits Plugin analogwp-templates Broken Access Control ≤ 2.6.5 Fixed in 2.6.6 CVE-2026-27364 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.8.6 Fixed in 1.8.7 CVE-2026-78290 Patchstack
4.3 Medium Hash Form Plugin hash-form Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2026-78280 Patchstack
5.4 Medium Fluent Support Pro Plugin fluent-support-pro Cross-Site Request Forgery No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2026-78279 Patchstack
5.3 Medium Fluent Boards Pro Plugin fluent-boards-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-78278 Patchstack
4.9 Medium FluentCRM Pro Plugin fluentcampaign-pro Server-Side Request Forgery ≤ 3.1.12 Fixed in 3.1.13 CVE-2026-78277 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only