WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 251–300 of 8,917 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | Loops & Logic | Broken Access Control No login needed |
≤ 4.2.4 Fixed in 4.3.0 |
CVE-2026-95604 |
Patchstack | |
| 7.2 High | Reycob Product Import Export | PHP Object Injection |
≤ 2.3.0 Fixed in 2.4.0 |
CVE-2026-95603 |
Patchstack | |
| 7.6 High | Ultimeter | SQL Injection |
≤ 3.0.8 Fixed in 3.1.0 |
CVE-2026-95593 |
Patchstack | |
| 7.1 High | Tainacan | SQL Injection |
≤ 1.2.0 Fixed in 1.3.0 |
CVE-2026-95590 |
Patchstack | |
| 7.1 High | Calculated Fields Form | Cross-Site Scripting No login needed |
≤ 5.5.1.1 Fixed in 5.5.1.2 |
CVE-2026-95529 |
Patchstack | |
| 7.1 High | Core Web Vitals & PageSpeed Booster | Cross-Site Scripting No login needed |
≤ 1.0.31 Fixed in 1.0.32 |
CVE-2026-95528 |
Patchstack | |
| 7.6 High | Easy Digital Downloads | SQL Injection |
≤ 3.7.0 Fixed in 3.7.1 |
CVE-2026-95522 |
Patchstack | |
| 7.1 High | Ninja Forms | Cross-Site Scripting No login needed |
≤ 3.15.3 Fixed in 3.15.4 |
CVE-2026-95515 |
Patchstack | |
| 7.5 High | Online Booking & Scheduling Calendar for WordPress by vcita | Broken Access Control No login needed |
≤ 4.6.0 Fixed in 4.6.3 |
CVE-2026-95513 |
Patchstack | |
| 8.1 High | PublishPress Capabilities | Cross-Site Request Forgery No login needed |
≤ 2.50.1 Fixed in 2.51.0 |
CVE-2026-94487 |
Patchstack | |
| 7.1 High | Razorpay Payment Button | Cross-Site Scripting No login needed |
≤ 2.4.9 Fixed in 2.5.0 |
CVE-2026-94179 |
Patchstack | |
| 7.1 High | Mang Board WP | Cross-Site Scripting No login needed |
≤ 2.4.1 Fixed in 2.4.2 |
CVE-2026-94176 |
Patchstack | |
| 7.6 High | Email Log | SQL Injection |
≤ 2.63 Fixed in 2.64 |
CVE-2026-94174 |
Patchstack | |
| 8.5 High | WP EasyCart | SQL Injection |
≤ 5.9.4 Fixed in 6.0.0 |
CVE-2026-94124 |
Patchstack | |
| 7.1 High | WP Photo Album Plus | Cross-Site Scripting No login needed |
≤ 9.3.02.002 Fixed in 9.3.02.003 |
CVE-2026-93774 |
Patchstack | |
| 8.5 High | Mollie Forms | SQL Injection |
≤ 2.11.0 Fixed in 2.11.1 |
CVE-2026-93773 |
Patchstack | |
| 7.1 High | WPS Limit Login | Cross-Site Scripting No login needed |
≤ 1.5.9.3 Fixed in 1.5.9.4 |
CVE-2026-93622 |
Patchstack | |
| 8.5 High | Live Copy Paste for Elementor | SQL Injection |
≤ 1.5.10 Fixed in 1.5.11 |
CVE-2026-93527 |
Patchstack | |
| 7.1 High | Event Tickets | Cross-Site Scripting No login needed |
≤ 5.29.4 Fixed in 5.29.5 |
CVE-2026-93526 |
Patchstack | |
| 7.5 High | Rename wp-login.php to anything you want | SQL Injection Unauthenticated SQL Injection via 'log' (Username) Parameter No login needed |
≤ 2.0.1 |
CVE-2026-93368 |
Wordfence | |
| 8.1 High | WC Fields Factory | Broken Access Control Subscriber+ Arbitrary Post Meta Manipulation via AJAX |
< 4.1.11 Fixed in 4.1.11 |
CVE-2026-93508 |
WPScan | |
| 8.2 High | WP Recipe Maker | Denial of Service Unauthenticated DoS via Unbounded User Meta Insertion No login needed |
9.8.0 – < 10.8.2 Fixed in 10.8.2 |
CVE-2026-86608 |
WPScan | |
| 8.2 High | Divi Dash | Denial of Service Unauthenticated Denial of Service via IP Address Spoofing No login needed |
< 1.0.7 Fixed in 1.0.7 |
CVE-2026-14321 |
WPScan | |
| 8.6 High | JetFormBuilder Stripe Gateway | SQL Injection Unauthenticated Blind SQLi via Payment Token No login needed |
< 1.1.0 Fixed in 1.1.0 |
CVE-2022-4997 |
WPScan | |
| 7.6 High | HashBar – WordPress Notification Bar | SQL Injection WordPress Notification Bar plugin <= 2.0.3 - SQL Injection |
≤ 2.0.3 Fixed in 2.0.4 |
CVE-2026-94117 |
Patchstack | |
| 7.3 High | Taxi Booking Manager for WooCommerce | Authentication Bypass Broken Authentication No login needed |
< 2.0.8 Fixed in 2.0.8 |
CVE-2026-93928 |
Patchstack | |
| 7.5 High | WP Travel Engine | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute |
≤ 6.8.0 |
CVE-2026-9231 |
Wordfence | |
| 7.2 High | WPC Product Bundles for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter No login needed |
≤ 8.6.6 |
CVE-2026-93836 |
Wordfence | |
| 7.2 High | WP Yelp Review Slider | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) No login needed |
≤ 9.2 |
CVE-2026-93778 |
Wordfence | |
| 8.1 High | WP Ultimate Review | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter |
≤ 2.4.2 |
CVE-2026-92235 |
Wordfence | |
| 7.1 High | WP Table Builder | Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter |
≤ 2.2.1 |
CVE-2026-6922 |
Wordfence | |
| 8.8 High | BM Content Builder | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
< 3.17.1 Fixed in 3.17.1 |
CVE-2025-1281 |
Wordfence | |
| 8.1 High | HUSKY | Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed |
≤ 1.4.4 |
CVE-2026-92969 |
Wordfence | |
| 7.5 High | Ninja Forms | PHP Object Injection Unauthenticated PHP Object Injection via CSV Export No login needed |
3.15.3 – < 3.15.4 Fixed in 3.15.4 |
CVE-2026-91827 |
WPScan | |
| 8.8 High | Ninja Forms | Cross-Site Scripting Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin No login needed |
3.15.3 – < 3.15.4 Fixed in 3.15.4 |
CVE-2026-92438 |
WPScan | |
| 7.2 High | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed |
≤ 3.15.3 |
CVE-2026-94504 |
Wordfence | |
| 7.2 High | TranslatePress | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel No login needed |
≤ 3.3.5 |
CVE-2026-89412 |
Wordfence | |
| 7.2 High | CMP | Privilege Escalation Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action |
≤ 4.1.17 |
CVE-2026-12470 |
Wordfence | |
| 7.2 High | Import and export users and customers | Privilege Escalation Custom Role Privilege Escalation to Administrator via Frontend Importer |
< 2.5.2 Fixed in 2.5.2 |
CVE-2026-92541 |
WPScan | |
| 7.2 High | Import and export users and customers | Privilege Escalation Custom Role Privilege Escalation to Administrator via caller_can_promote_users |
2.4.16 – < 2.5.2 Fixed in 2.5.2 |
CVE-2026-92540 |
WPScan | |
| 7.5 High | Tripzzy | Broken Access Control Unauthenticated Arbitrary Comment Deletion No login needed |
1.1.8 – < 1.5.1 Fixed in 1.5.1 |
CVE-2026-87839 |
WPScan | |
| 8.5 High | Forminator Forms | Remote Code Execution Authenticated RCE via XML-RPC PHP Object Injection |
1.57.0.7 – < 1.57.2.1 Fixed in 1.57.2.1 |
CVE-2026-87067 |
WPScan | |
| 7.5 High | Unlimited Elements For Elementor | PHP Object Injection Subscriber+ PHP Object Injection |
< 2.0.20 Fixed in 2.0.20 |
CVE-2026-85017 |
WPScan | |
| 8.1 High | SAML Single Sign On | Privilege Escalation Unauthenticated Privilege Escalation via Account Matching No login needed |
4.8.43 – < 6.0.0 Fixed in 6.0.0 |
CVE-2026-82842 |
WPScan | |
| 7.2 High | NextGEN Gallery | Arbitrary File Upload Authenticated Arbitrary File Upload via ZIP Import |
< 4.5.0 Fixed in 4.5.0 |
CVE-2026-81650 |
WPScan | |
| 7.5 High | YS LeadGen – Popups, Opt-ins & Lead Capture | Information Disclosure Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action No login needed |
≤ 2.1.4 |
CVE-2026-1255 |
Wordfence | |
| 8.1 High | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) |
≤ 4.17.2 |
CVE-2026-85658 |
Wordfence | |
| 8.8 High | The Welcomizer | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter |
≤ 2.8.1 |
CVE-2026-4327 |
Wordfence | |
| 7.2 High | Quill Forms | Conversational Multi Step Forms, Surveys & quizzes | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value No login needed |
≤ 5.7.1 |
CVE-2026-15664 |
Wordfence | |
| 7.5 High | MgoSync | Information Disclosure Unauthenticated WooCommerce API Credential Disclosure No login needed |
2.1.5 – < 2.1.7 Fixed in 2.1.7 |
CVE-2026-92404 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.