WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 251–300 of 1,407 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Livemesh Addons for Beaver Builder | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Missing Authorization |
≤ 3.9.2 |
CVE-2026-3897 |
Wordfence | |
| 5.4 Medium | ShopLentor - WooCommerce Builder for Elementor & Gutenberg | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute |
≤ 3.3.8 |
CVE-2026-6287 |
Wordfence | |
| 4.3 Medium | Vedrixa Forms | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Structure Modification via wefb_save_form_structure AJAX Action |
≤ 1.1.1 |
CVE-2026-8692 |
Wordfence | |
| 9.8 Critical | Divi Form Builder | Privilege Escalation Unauthenticated Privilege Escalation via 'role' No login needed |
≤ 5.1.2 |
CVE-2026-5118 |
Wordfence | |
| 6.4 Medium | Avada (Fusion) Builder | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Shortcodes |
≤ 3.15.2 |
CVE-2026-1543 |
Wordfence | |
| 9.8 Critical | Avada (Fusion) Builder | Remote Code Execution Unauthenticated Remote Code Execution via PHP Function Injection via 'render_logics' Shortcode Attribute via Widget AJAX Handler No login needed |
≤ 3.15.2 |
CVE-2026-6279 |
Wordfence | |
| 5.0 Medium | PDF for Elementor Forms + Drag And Drop Template Builder | Broken Access Control |
≤ 5.5.1 Fixed in 5.6.1 |
CVE-2026-45443 |
Patchstack | |
| 7.5 High | Funnel Builder for WooCommerce Checkout | Broken Access Control Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX No login needed |
< 3.15.0.3 Fixed in 3.15.0.3 |
CVE-2026-47100 |
VulnCheck | |
| 4.9 Medium | NEX-Forms – Ultimate Forms | SQL Injection Ultimate Forms Plugin for WordPress <= 9.1.12 - Authenticated (Administrator+) SQL Injection via 'table' Parameter |
≤ 9.1.12 |
CVE-2026-7046 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_button Shortcode |
≤ 5.6.8 |
CVE-2026-3694 |
Wordfence | |
| 6.5 Medium | Taskbuilder – Project Management & Task Management Tool With Kanban Board | SQL Injection Project Management & Task Management Tool With Kanban Board <= 5.0.6 - Authenticated (Subscriber+) Time-Based Blind SQL Injection via 'project_search' Parameter |
≤ 5.0.6 |
CVE-2026-6225 |
Wordfence | |
| 6.5 Medium | Avada Builder | Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter |
≤ 3.15.2 |
CVE-2026-4782 |
Wordfence | |
| 7.5 High | Avada Builder | SQL Injection Unauthenticated SQL Injection via 'product_order' Parameter No login needed |
≤ 3.15.1 |
CVE-2026-4798 |
Wordfence | |
| 5.3 Medium | Cost Calculator Builder | Price Manipulation Unauthenticated Price Manipulation and Insecure Direct Object Reference No login needed |
≤ 4.0.1 |
CVE-2025-14755 |
Wordfence | |
| 6.1 Medium | Contact Form Builder | Cross-Site Scripting WordPress Contact Form Builder 1.6.1 Cross-Site Scripting via code_generator.php No login needed |
1.6.1 |
CVE-2022-50959 |
VulnCheck | |
| 7.1 High | Bricks Builder | Cross-Site Scripting No login needed |
1.9.2 – 2.2 Fixed in 2.3 |
CVE-2026-41554 |
Patchstack | |
| 7.5 High | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | SQL Injection Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' No login needed |
≤ 1.15.42 |
CVE-2026-3359 |
Wordfence | |
| 7.5 High | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Path Traversal Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]' No login needed |
≤ 1.52.1 |
CVE-2026-5192 |
Wordfence | |
| 5.3 Medium | Forminator – Contact Form, Payment Form & Custom Form Builder | Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.52.0 - Missing Authorization to Unauthenticated Stripe PaymentIntent Reuse / Underpayment Bypass via 'paymentid' Parameter No login needed |
≤ 1.52.0 |
CVE-2026-2729 |
Wordfence | |
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via POST Parameter Key Names No login needed |
≤ 9.1.11 |
CVE-2026-5063 |
Wordfence | |
| 7.2 High | Brizy – Page Builder | Cross-Site Scripting Page Builder <= 2.8.11 - Unauthenticated Stored Cross-Site Scripting via FileUpload Field Value No login needed |
≤ 2.8.11 |
CVE-2026-5324 |
Wordfence | |
| 8.1 High | Profile Builder Pro | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 3.14.5 |
CVE-2026-7647 |
Wordfence | |
| 5.3 Medium | App Builder | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter No login needed |
≤ 5.6.0 |
CVE-2026-7638 |
Wordfence | |
| 6.4 Medium | Elementor Website Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API |
≤ 4.0.4 |
CVE-2026-6127 |
Wordfence | |
| 5.4 Medium | Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor | Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML |
≤ 3.5.5 |
CVE-2026-2951 |
Wordfence | |
| 6.4 Medium | Page Builder Gutenberg Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data |
≤ 3.1.16 |
CVE-2026-4801 |
Wordfence | |
| 5.3 Medium | Kubio AI Page Builder | Broken Access Control Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes No login needed |
≤ 2.7.2 |
CVE-2026-5427 |
Wordfence | |
| 5.3 Medium | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed |
6.1.21 |
CVE-2026-4160 |
Wordfence | |
| 8.5 High | Beaver Builder | SQL Injection |
≤ 2.10.1.2 Fixed in 2.10.1.5 |
CVE-2026-40744 |
Patchstack | |
| 5.3 Medium | e-shot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Settings Modification via AJAX No login needed |
≤ 1.0.2 |
CVE-2026-3642 |
Wordfence | |
| 5.4 Medium | Avada (Fusion) Builder | Privilege Escalation Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution |
≤ 3.15.1 |
CVE-2026-1509 |
Wordfence | |
| 4.3 Medium | Avada (Fusion) Builder | Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Insecure Direct Object Reference |
≤ 3.15.1 |
CVE-2026-1541 |
Wordfence | |
| 6.4 Medium | Greenshift | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via disablelazy Attribute |
≤ 12.8.9 |
CVE-2026-4895 |
Wordfence | |
| 8.8 High | Vertex Addons for Elementor | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation and Activation via 'afeb_activate_required_plugins' |
≤ 1.6.4 |
CVE-2026-4326 |
Wordfence | |
| 6.4 Medium | Page Builder: Pagelayer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes |
≤ 2.0.8 |
CVE-2026-2509 |
Wordfence | |
| 6.4 Medium | Beaver Builder Page Builder – Drag and Drop Website Builder | Cross-Site Scripting Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]' |
≤ 2.10.1.1 |
CVE-2026-2481 |
Wordfence | |
| 6.5 Medium | WPBITS Addons For Elementor Page Builder | Cross-Site Scripting |
≤ 1.8.1 |
CVE-2026-39703 |
Patchstack | |
| 6.5 Medium | Hello Bar Popup Builder | Cross-Site Scripting |
≤ 1.5.1 |
CVE-2026-39666 |
Patchstack | |
| 6.4 Medium | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar |
≤ 6.4.9 |
CVE-2026-3311 |
Wordfence | |
| 6.4 Medium | Elementor Website Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API |
≤ 3.35.5 |
CVE-2025-14732 |
Wordfence | |
| 6.5 Medium | SQL Chart Builder | SQL Injection Unauthenticated SQL Injection No login needed |
< 2.3.8 Fixed in 2.3.8 |
CVE-2026-4079 |
WPScan | |
| 4.3 Medium | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Broken Access Control Missing Authorization to Authenticated (Contributor+) Media Upload |
≤ 3.6.3 |
CVE-2026-2826 |
Wordfence | |
| 6.5 Medium | Ultimate Addons for WPBakery Page Builder | Cross-Site Scripting |
< 3.21.4 Fixed in 3.21.4 |
CVE-2026-34889 |
Patchstack | |
| 4.3 Medium | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Broken Access Control Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field |
≤ 3.15.5 |
CVE-2026-3139 |
Wordfence | |
| 6.5 Medium | Kubio AI Page Builder | Cross-Site Scripting |
≤ 2.7.0 Fixed in 2.7.1 |
CVE-2026-34887 |
Patchstack | |
| 6.4 Medium | Ibtana - WordPress Website Builder | Cross-Site Scripting WordPress Website Builder <= 1.2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.2.5.7 |
CVE-2026-1834 |
Wordfence | |
| 4.3 Medium | Elementor Website Builder | Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template |
≤ 3.35.7 |
CVE-2026-1206 |
Wordfence | |
| 7.1 High | Fusion Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ < 3.15.0 Fixed in 3.15.0 |
CVE-2026-32542 |
Patchstack | |
| 7.1 High | Contact Form & Lead Form Elementor Builder | Cross-Site Scripting No login needed |
≤ <= 2.0.1 Fixed in 2.0.2 |
CVE-2026-32532 |
Patchstack | |
| 9.9 Critical | JetFormBuilder | Remote Code Execution |
≤ <= 3.5.6.1 Fixed in 3.5.6.2 |
CVE-2026-32525 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.