WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 251–300 of 1,407 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 29
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Livemesh Addons for Beaver Builder Plugin addons-for-beaver-builder Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Missing Authorization ≤ 3.9.2 CVE-2026-3897 Wordfence
5.4 Medium ShopLentor - WooCommerce Builder for Elementor & Gutenberg Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute ≤ 3.3.8 CVE-2026-6287 Wordfence
4.3 Medium Vedrixa Forms Plugin vedrixa-forms-registration-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action ≤ 1.1.1 CVE-2026-8692 Wordfence
9.8 Critical Divi Form Builder Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'role' No login needed ≤ 5.1.2 CVE-2026-5118 Wordfence
6.4 Medium Avada (Fusion) Builder Plugin Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 3.15.2 CVE-2026-1543 Wordfence
9.8 Critical Avada (Fusion) Builder Plugin fusion-builder Remote Code Execution Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler No login needed ≤ 3.15.2 CVE-2026-6279 Wordfence
5.0 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 5.5.1 Fixed in 5.6.1 CVE-2026-45443 Patchstack
7.5 High Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX No login needed < 3.15.0.3 Fixed in 3.15.0.3 CVE-2026-47100 VulnCheck
4.9 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder SQL Injection Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter ≤ 9.1.12 CVE-2026-7046 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode ≤ 5.6.8 CVE-2026-3694 Wordfence
6.5 Medium Taskbuilder – Project Management & Task Management Tool With Kanban Board Plugin taskbuilder SQL Injection Project Management & Task Management Tool With Kanban Board <= 5.0.6 - Authenticated (Subscriber+) Time-Based Blind SQL Injection via 'project_search' Parameter ≤ 5.0.6 CVE-2026-6225 Wordfence
6.5 Medium Avada Builder Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter ≤ 3.15.2 CVE-2026-4782 Wordfence
7.5 High Avada Builder Plugin SQL Injection Unauthenticated SQL Injection via 'product_order' Parameter No login needed ≤ 3.15.1 CVE-2026-4798 Wordfence
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Price Manipulation Unauthenticated Price Manipulation and Insecure Direct Object Reference No login needed ≤ 4.0.1 CVE-2025-14755 Wordfence
6.1 Medium Contact Form Builder Plugin contact-forms-builder Cross-Site Scripting WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php No login needed 1.6.1 CVE-2022-50959 VulnCheck
7.1 High Bricks Builder Theme bricks Cross-Site Scripting No login needed 1.9.2 – 2.2 Fixed in 2.3 CVE-2026-41554 Patchstack
7.5 High Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker SQL Injection Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' No login needed ≤ 1.15.42 CVE-2026-3359 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Path Traversal Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]' No login needed ≤ 1.52.1 CVE-2026-5192 Wordfence
5.3 Medium Forminator – Contact Form, Payment Form & Custom Form Builder Plugin forminator Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter No login needed ≤ 1.52.0 CVE-2026-2729 Wordfence
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names No login needed ≤ 9.1.11 CVE-2026-5063 Wordfence
7.2 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Value No login needed ≤ 2.8.11 CVE-2026-5324 Wordfence
8.1 High Profile Builder Pro Plugin profile-builder-pro PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.14.5 CVE-2026-7647 Wordfence
5.3 Medium App Builder Plugin app-builder Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter No login needed ≤ 5.6.0 CVE-2026-7638 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 4.0.4 CVE-2026-6127 Wordfence
5.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML ≤ 3.5.5 CVE-2026-2951 Wordfence
6.4 Medium Page Builder Gutenberg Blocks Plugin coblocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data ≤ 3.1.16 CVE-2026-4801 Wordfence
5.3 Medium Kubio AI Page Builder Plugin kubio Broken Access Control Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes No login needed ≤ 2.7.2 CVE-2026-5427 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
8.5 High Beaver Builder Plugin beaver-builder-lite-version SQL Injection ≤ 2.10.1.2 Fixed in 2.10.1.5 CVE-2026-40744 Patchstack
5.3 Medium e-shot Plugin e-shot-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX No login needed ≤ 1.0.2 CVE-2026-3642 Wordfence
5.4 Medium Avada (Fusion) Builder Plugin Privilege Escalation Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution ≤ 3.15.1 CVE-2026-1509 Wordfence
4.3 Medium Avada (Fusion) Builder Plugin Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference ≤ 3.15.1 CVE-2026-1541 Wordfence
6.4 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute ≤ 12.8.9 CVE-2026-4895 Wordfence
8.8 High Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' ≤ 1.6.4 CVE-2026-4326 Wordfence
6.4 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 2.0.8 CVE-2026-2509 Wordfence
6.4 Medium Beaver Builder Page Builder – Drag and Drop Website Builder Plugin beaver-builder-lite-version Cross-Site Scripting Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]' ≤ 2.10.1.1 CVE-2026-2481 Wordfence
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.8.1 CVE-2026-39703 Patchstack
6.5 Medium Hello Bar Popup Builder Plugin hellobar Cross-Site Scripting ≤ 1.5.1 CVE-2026-39666 Patchstack
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar ≤ 6.4.9 CVE-2026-3311 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 3.35.5 CVE-2025-14732 Wordfence
6.5 Medium SQL Chart Builder Plugin SQL Injection Unauthenticated SQL Injection No login needed < 2.3.8 Fixed in 2.3.8 CVE-2026-4079 WPScan
4.3 Medium Kadence Blocks — Page Builder Toolkit for Gutenberg Editor Plugin kadence-blocks Broken Access Control Missing Authorization to Authenticated (Contributor+) Media Upload ≤ 3.6.3 CVE-2026-2826 Wordfence
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin ultimate_vc_addons Cross-Site Scripting < 3.21.4 Fixed in 3.21.4 CVE-2026-34889 Patchstack
4.3 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Broken Access Control Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field ≤ 3.15.5 CVE-2026-3139 Wordfence
6.5 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting ≤ 2.7.0 Fixed in 2.7.1 CVE-2026-34887 Patchstack
6.4 Medium Ibtana - WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.5.7 CVE-2026-1834 Wordfence
4.3 Medium Elementor Website Builder Plugin elementor Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template ≤ 3.35.7 CVE-2026-1206 Wordfence
7.1 High Fusion Builder Plugin fusion-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ < 3.15.0 Fixed in 3.15.0 CVE-2026-32542 Patchstack
7.1 High Contact Form & Lead Form Elementor Builder Plugin lead-form-builder Cross-Site Scripting No login needed ≤ <= 2.0.1 Fixed in 2.0.2 CVE-2026-32532 Patchstack
9.9 Critical JetFormBuilder Plugin jetformbuilder Remote Code Execution ≤ <= 3.5.6.1 Fixed in 3.5.6.2 CVE-2026-32525 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only