WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,951–3,000 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 60 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium My Social Feeds Plugin my-social-feeds Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via 'ttp_get_accounts' AJAX Action ≤ 1.0.4 CVE-2026-6446 Wordfence
6.5 Medium Widgets for Social Photo Feed Plugin social-photo-feed-widget Broken Access Control Missing Authentication to Unauthenticated Plugin Settings Access/Update via trustindex_feed_hook_instagram REST API endpoints No login needed ≤ 1.8 CVE-2025-14726 Wordfence
6.4 Medium Gutenberg Essential Blocks Plugin essential-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes ≤ 6.0.4 CVE-2026-4658 Wordfence
6.4 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 8.9.2 CVE-2026-7209 Wordfence
5.3 Medium App Builder Plugin app-builder Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter No login needed ≤ 5.6.0 CVE-2026-7638 Wordfence
6.4 Medium Maxi Blocks Plugin maxi-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Style Card REST API ≤ 2.1.9 CVE-2026-6378 Wordfence
5.3 Medium Total Upkeep Plugin boldgrid-backup Broken Access Control Missing Authorization to Unauthenticated Rollback Cancellation No login needed ≤ 1.17.1 CVE-2026-3143 Wordfence
4.3 Medium Ultimate Dashboard Plugin ultimate-dashboard Cross-Site Request Forgery Cross-Site Request Forgery to Module Activation/Deactivation No login needed ≤ 3.8.14 CVE-2026-3140 Wordfence
6.1 Medium Freemius Theme tablepress Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via url Parameter No login needed ≤ 1.8.4.8.1, ≤ 1.0.4, ≤ 1.0.40, … CVE-2024-13362 Wordfence
6.4 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via REST API ≤ 4.0.4 CVE-2026-6127 Wordfence
5.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Price Manipulation Unauthenticated Payment Bypass via PHP Type Juggling in 'payment_id' Parameter No login needed ≤ 2.7.16 CVE-2026-6498 Wordfence
6.1 Medium WP Meteor Website Speed Optimization Addon Plugin wp-meteor Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 3.4.16 CVE-2026-2902 Wordfence
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control ≤ 2.19.22 Fixed in 2.19.23 CVE-2026-42648 Patchstack
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.11.0 Fixed in 1.12.0 CVE-2026-42645 Patchstack
5.3 Medium BetterDocs Plugin betterdocs Information Disclosure Sensitive Data Exposure No login needed ≤ 4.3.10 Fixed in 4.3.11 CVE-2026-42644 Patchstack
5.9 Medium Image Widget Plugin image-widget Cross-Site Scripting ≤ 4.4.11 Fixed in 4.4.12 CVE-2026-42643 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed ≤ 4.14.5 Fixed in 4.14.6 CVE-2026-42642 Patchstack
5.4 Medium Share This Image Plugin share-this-image Server-Side Request Forgery No login needed ≤ 2.14 Fixed in 2.15 CVE-2026-42641 Patchstack
5.3 Medium Complianz – GDPR/CCPA Cookie Consent Plugin complianz-gdpr Broken Access Control GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint No login needed ≤ 7.4.5 CVE-2026-4019 Wordfence
6.5 Medium WP User Frontend Plugin wp-user-frontend Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-42412 Patchstack
5.3 Medium Booking Package Plugin booking-package Price Manipulation Unauthenticated Price Manipulation via 'amount' Parameter No login needed ≤ 1.7.06 CVE-2026-4911 Wordfence
6.4 Medium Woostify Plugin woostify Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Lity.js Library via data-lity Attribute in Custom HTML Block ≤ 2.5.0 CVE-2026-4805 Wordfence
5.4 Medium Check & Log Email Plugin check-email Cross-Site Scripting Unauthenticated Stored XSS < 2.0.13 Fixed in 2.0.13 CVE-2026-5306 WPScan
6.4 Medium Social Post Embed Plugin social-post-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Threads Embed ≤ 2.0.1 CVE-2026-6809 Wordfence
6.4 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute ≤ 4.2.8 CVE-2026-6725 Wordfence
6.4 Medium Timeline Blocks for Gutenberg Plugin timeline-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute ≤ 1.1.10 CVE-2026-6551 Wordfence
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting < 5.12.1.1 Fixed in 5.12.1.1 CVE-2026-42410 Patchstack
6.4 Medium ITERAS Plugin iteras Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.8.2 CVE-2026-4078 Wordfence
5.3 Medium Liaison Site Prober Plugin liaison-site-prober Broken Access Control Missing Authorization to Unauthenticated Information Exposure in '/logs' REST API Endpoint No login needed ≤ 1.2.1 CVE-2026-3569 Wordfence
4.3 Medium Taqnix Plugin taqnix Cross-Site Request Forgery Cross-Site Request Forgery to Account Deletion via 'taqnix_delete_my_account' AJAX Action No login needed ≤ 1.0.3 CVE-2026-3565 Wordfence
4.3 Medium HubSpot All-In-One Marketing - Forms, Popups, Live Chat Plugin leadin Broken Access Control Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure ≤ 11.3.32 CVE-2025-11762 Wordfence
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Calendar Takeover No login needed ≤ 1.2.63 CVE-2026-6810 Wordfence
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Caption Field ≤ 1.7.1056 CVE-2026-5428 Wordfence
5.3 Medium WP Books Gallery Plugin wp-books-gallery Broken Access Control Missing Authorization to Unauthenticated Settings Update via 'permalink_structure' Parameter No login needed ≤ 4.8.0 CVE-2026-5347 Wordfence
5.3 Medium ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token' No login needed ≤ 9.1.2 CVE-2026-5488 Wordfence
5.3 Medium Maxi Blocks Plugin maxi-blocks Broken Access Control Missing Authorization to Authenticated (Author+) Media File Deletion via 'old_media_src' Parameter No login needed ≤ 2.1.8 CVE-2026-2028 Wordfence
4.3 Medium BetterDocs Plugin betterdocs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Unauthorized AI API Usage ≤ 4.3.11 CVE-2026-6393 Wordfence
6.5 Medium Rescue Shortcodes Plugin rescue-shortcodes Cross-Site Scripting ≤ 3.3 Fixed in 3.4 CVE-2025-62110 Patchstack
4.3 Medium ACF Galerie 4 Plugin acf-galerie-4 Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-62104 Patchstack
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
5.3 Medium HT Mega Plugin Information Disclosure Unauthenticated PII Disclosure No login needed < 3.0.7 Fixed in 3.0.7 CVE-2026-4106 WPScan
6.4 Medium WP Store Locator Plugin wp-store-locator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsl_address' Post Meta ≤ 2.2.261 CVE-2026-3361 Wordfence
5.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutentor Block HTML ≤ 3.5.5 CVE-2026-2951 Wordfence
6.4 Medium Social Rocket – Social Sharing Plugin social-rocket Cross-Site Scripting Social Sharing Plugin <= 1.3.4.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via id ≤ 1.3.4.2 CVE-2026-1923 Wordfence
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed < 7.13.2 Fixed in 7.13.2 CVE-2025-58922 Patchstack
6.4 Medium Gallagher Website Design Plugin gallagher-website-design Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'prefix' Shortcode Attribute ≤ 2.6.4 CVE-2026-1913 Wordfence
6.4 Medium Gutentools Plugin gutentools Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Slider Block Attributes ≤ 1.1.3 CVE-2026-1395 Wordfence
4.3 Medium Emailchef Plugin emailchef Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion ≤ 3.5.1 CVE-2026-1930 Wordfence
6.4 Medium CI HUB Connector Plugin ci-hub-connector Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.2.106 CVE-2026-4353 Wordfence
4.3 Medium Google PageRank Display Plugin google-pagerank-display Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update via Settings Page No login needed ≤ 1.4 CVE-2026-6294 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only