WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Loops & Logic Plugin tangible-loops-and-logic Broken Access Control No login needed ≤ 4.2.4 Fixed in 4.3.0 CVE-2026-95604 Patchstack
7.2 High Reycob Product Import Export Plugin reycob-product-import-export PHP Object Injection ≤ 2.3.0 Fixed in 2.4.0 CVE-2026-95603 Patchstack
7.6 High Ultimeter Plugin ultimeter SQL Injection ≤ 3.0.8 Fixed in 3.1.0 CVE-2026-95593 Patchstack
7.1 High Tainacan Plugin tainacan SQL Injection ≤ 1.2.0 Fixed in 1.3.0 CVE-2026-95590 Patchstack
7.1 High Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting No login needed ≤ 5.5.1.1 Fixed in 5.5.1.2 CVE-2026-95529 Patchstack
7.1 High Core Web Vitals & PageSpeed Booster Plugin core-web-vitals-pagespeed-booster Cross-Site Scripting No login needed ≤ 1.0.31 Fixed in 1.0.32 CVE-2026-95528 Patchstack
7.6 High Easy Digital Downloads Plugin easy-digital-downloads SQL Injection ≤ 3.7.0 Fixed in 3.7.1 CVE-2026-95522 Patchstack
7.1 High Ninja Forms Plugin ninja-forms Cross-Site Scripting No login needed ≤ 3.15.3 Fixed in 3.15.4 CVE-2026-95515 Patchstack
7.5 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control No login needed ≤ 4.6.0 Fixed in 4.6.3 CVE-2026-95513 Patchstack
8.1 High PublishPress Capabilities Plugin capability-manager-enhanced Cross-Site Request Forgery No login needed ≤ 2.50.1 Fixed in 2.51.0 CVE-2026-94487 Patchstack
7.1 High Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2026-94179 Patchstack
7.1 High Mang Board WP Plugin mangboard Cross-Site Scripting No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2026-94176 Patchstack
7.6 High Email Log Plugin email-log SQL Injection ≤ 2.63 Fixed in 2.64 CVE-2026-94174 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.9.4 Fixed in 6.0.0 CVE-2026-94124 Patchstack
7.1 High WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting No login needed ≤ 9.3.02.002 Fixed in 9.3.02.003 CVE-2026-93774 Patchstack
8.5 High Mollie Forms Plugin mollie-forms SQL Injection ≤ 2.11.0 Fixed in 2.11.1 CVE-2026-93773 Patchstack
7.1 High WPS Limit Login Plugin wps-limit-login Cross-Site Scripting No login needed ≤ 1.5.9.3 Fixed in 1.5.9.4 CVE-2026-93622 Patchstack
8.5 High Live Copy Paste for Elementor Plugin live-copy-paste SQL Injection ≤ 1.5.10 Fixed in 1.5.11 CVE-2026-93527 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting No login needed ≤ 5.29.4 Fixed in 5.29.5 CVE-2026-93526 Patchstack
7.5 High Rename wp-login.php to anything you want Plugin rename-wp-loginphp-to-anything-you-want SQL Injection Unauthenticated SQL Injection via 'log' (Username) Parameter No login needed ≤ 2.0.1 CVE-2026-93368 Wordfence
8.1 High WC Fields Factory Plugin wc-fields-factory Broken Access Control Subscriber+ Arbitrary Post Meta Manipulation via AJAX < 4.1.11 Fixed in 4.1.11 CVE-2026-93508 WPScan
8.2 High WP Recipe Maker Plugin wp-recipe-maker Denial of Service Unauthenticated DoS via Unbounded User Meta Insertion No login needed 9.8.0 – < 10.8.2 Fixed in 10.8.2 CVE-2026-86608 WPScan
8.2 High Divi Dash Plugin Denial of Service Unauthenticated Denial of Service via IP Address Spoofing No login needed < 1.0.7 Fixed in 1.0.7 CVE-2026-14321 WPScan
8.6 High JetFormBuilder Stripe Gateway Plugin SQL Injection Unauthenticated Blind SQLi via Payment Token No login needed < 1.1.0 Fixed in 1.1.0 CVE-2022-4997 WPScan
7.6 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar SQL Injection WordPress Notification Bar plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 Fixed in 2.0.4 CVE-2026-94117 Patchstack
7.3 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed < 2.0.8 Fixed in 2.0.8 CVE-2026-93928 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'template' Shortcode Attribute ≤ 6.8.0 CVE-2026-9231 Wordfence
7.2 High WPC Product Bundles for WooCommerce Plugin woo-product-bundle Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter No login needed ≤ 8.6.6 CVE-2026-93836 Wordfence
7.2 High WP Yelp Review Slider Plugin wp-yelp-review-slider Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Yelp Review Text (imported via wpyelp_download_source) No login needed ≤ 9.2 CVE-2026-93778 Wordfence
8.1 High WP Ultimate Review Plugin wp-ultimate-review Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter ≤ 2.4.2 CVE-2026-92235 Wordfence
7.1 High WP Table Builder Plugin wp-table-builder Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion via 'ids' Parameter ≤ 2.2.1 CVE-2026-6922 Wordfence
8.8 High BM Content Builder Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion < 3.17.1 Fixed in 3.17.1 CVE-2025-1281 Wordfence
8.1 High HUSKY Plugin woocommerce-products-filter Local File Inclusion Unauthenticated Local File Inclusion via 'custom_tpl' Shortcode Attribute via 'woof_draw_products' AJAX No login needed ≤ 1.4.4 CVE-2026-92969 Wordfence
7.5 High Ninja Forms Plugin ninja-forms PHP Object Injection Unauthenticated PHP Object Injection via CSV Export No login needed 3.15.3 – < 3.15.4 Fixed in 3.15.4 CVE-2026-91827 WPScan
8.8 High Ninja Forms Plugin ninja-forms Cross-Site Scripting Unauthenticated Stored XSS via Paragraph Text Field in Submissions Admin No login needed 3.15.3 – < 3.15.4 Fixed in 3.15.4 CVE-2026-92438 WPScan
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting No login needed ≤ 3.15.3 CVE-2026-94504 Wordfence
7.2 High TranslatePress Plugin translatepress-multilingual Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Translation Memory Suggestion Panel No login needed ≤ 3.3.5 CVE-2026-89412 Wordfence
7.2 High CMP Plugin cmp-coming-soon-maintenance Privilege Escalation Authenticated (Editor+) Privilege Escalation via Arbitrary Option Update to cmp_ajax_import_settings AJAX Action ≤ 4.1.17 CVE-2026-12470 Wordfence
7.2 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Custom Role Privilege Escalation to Administrator via Frontend Importer < 2.5.2 Fixed in 2.5.2 CVE-2026-92541 WPScan
7.2 High Import and export users and customers Plugin import-users-from-csv-with-meta Privilege Escalation Custom Role Privilege Escalation to Administrator via caller_can_promote_users 2.4.16 – < 2.5.2 Fixed in 2.5.2 CVE-2026-92540 WPScan
7.5 High Tripzzy Plugin tripzzy Broken Access Control Unauthenticated Arbitrary Comment Deletion No login needed 1.1.8 – < 1.5.1 Fixed in 1.5.1 CVE-2026-87839 WPScan
8.5 High Forminator Forms Plugin forminator Remote Code Execution Authenticated RCE via XML-RPC PHP Object Injection 1.57.0.7 – < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87067 WPScan
7.5 High Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor PHP Object Injection Subscriber+ PHP Object Injection < 2.0.20 Fixed in 2.0.20 CVE-2026-85017 WPScan
8.1 High SAML Single Sign On Plugin miniorange-saml-20-single-sign-on Privilege Escalation Unauthenticated Privilege Escalation via Account Matching No login needed 4.8.43 – < 6.0.0 Fixed in 6.0.0 CVE-2026-82842 WPScan
7.2 High NextGEN Gallery Plugin Arbitrary File Upload Authenticated Arbitrary File Upload via ZIP Import < 4.5.0 Fixed in 4.5.0 CVE-2026-81650 WPScan
7.5 High YS LeadGen – Popups, Opt-ins & Lead Capture Plugin ysleadgen Information Disclosure Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclosure in 'ysleadgen_get_captured_data' AJAX Action No login needed ≤ 2.1.4 CVE-2026-1255 Wordfence
8.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) ≤ 4.17.2 CVE-2026-85658 Wordfence
8.8 High The Welcomizer Plugin the-welcomizer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'twiz_custom_logic' Parameter ≤ 2.8.1 CVE-2026-4327 Wordfence
7.2 High Quill Forms | Conversational Multi Step Forms, Surveys & quizzes Plugin quillforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value No login needed ≤ 5.7.1 CVE-2026-15664 Wordfence
7.5 High MgoSync Plugin megamo Information Disclosure Unauthenticated WooCommerce API Credential Disclosure No login needed 2.1.5 – < 2.1.7 Fixed in 2.1.7 CVE-2026-92404 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only