WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 3,001–3,050 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 61 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.7 Low Builderall Plugin Broken Access Control Unauthenticated OAuth Access Token Poisoning via Public REST Routes No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-11882 WPScan
3.5 Low Spectra (Ultimate Addons for Gutenberg) Plugin Content Injection Contributor+ Stored CSS Injection via Block Attributes < 2.20.0 Fixed in 2.20.0 CVE-2026-10827 WPScan
5.4 Medium Admin Columns for ACF Fields Plugin admin-columns-for-acf-fields Cross-Site Scripting Contributor+ Stored XSS via ACF Field Value Column ≤ 0.3.2 CVE-2026-15262 WPScan
5.4 Medium Codeless Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode Attribute ≤ 1.1.4 CVE-2026-15234 WPScan
7.2 High Everest Toolkit Plugin Arbitrary File Upload Admin+ Arbitrary File Upload ≤ 1.2.3 CVE-2026-13158 WPScan
8.1 High Profile Builder Plugin Privilege Escalation Unauthenticated Account Takeover via Auto-Login After Registration No login needed < 3.16.4 Fixed in 3.16.4 CVE-2026-15368 WPScan
7.2 High HUSKY - Products Filter Professional for WooCommerce Plugin Local File Inclusion Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view < 1.4.1 Fixed in 1.4.1 CVE-2026-15244 WPScan
8.1 High Login/Signup Popup Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset Rate Limit Bypass No login needed < 3.2.5 Fixed in 3.2.5 CVE-2026-14836 WPScan
8.8 High DynamicKit for Elementor Plugin dynamickit-elementor Privilege Escalation Unauthenticated Account Takeover via Password Reset Link Host Injection No login needed < 1.0.3 Fixed in 1.0.3 CVE-2026-14596 WPScan
8.1 High Chat On Desk Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset OTP Bypass No login needed < 1.0.9 Fixed in 1.0.9 CVE-2026-14309 WPScan
3.8 Low Fluent Support Plugin fluent-support Broken Access Control Agent+ Arbitrary Ticket Customer Reassignment via IDOR < 2.3.1 Fixed in 2.3.1 CVE-2026-14197 WPScan
5.3 Medium Direct Payments for WooCommerce Plugin direct-payments-for-woocommerce Broken Access Control Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions No login needed < 2.5.3 Fixed in 2.5.3 CVE-2026-12966 WPScan
4.8 Medium Bit Form Plugin bit-form Cross-Site Scripting Admin+ Stored XSS via Conversational Form Progress Label < 3.1.4 Fixed in 3.1.4 CVE-2025-15669 WPScan
5.3 Medium Support Genix Lite Plugin Path Traversal Unauthenticated Arbitrary File Read via Path Traversal No login needed < 1.4.48 Fixed in 1.4.48 CVE-2026-15932 WPScan
9.1 Critical FormGent Plugin formgent Broken Access Control FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter No login needed ≤ 1.9.2 CVE-2026-3141 Wordfence
4.9 Medium Pinpoint Booking System Plugin booking-system SQL Injection Authenticated (Administrator+) SQL Injection via 'field' Parameter ≤ 2.9.9.6.9 CVE-2026-15403 Wordfence
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Privilege Escalation Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta ≤ 2.0.0 CVE-2026-15414 Wordfence
7.5 High Bit integrations Plugin bit-integrations Path Traversal Unauthenticated Arbitrary File Read via Optional CF7 File Field No login needed ≤ 2.9.0 CVE-2026-15006 Wordfence
6.4 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _sp_form_code Post Meta ≤ 2.2.5 CVE-2026-13362 Wordfence
6.4 Medium SureForms Plugin sureforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute ≤ 2.8.1 CVE-2026-7623 Wordfence
4.3 Medium WP Maps Plugin wp-google-map-plugin Information Disclosure Sensitive Data Exposure ≤ 4.9.6 Fixed in 4.9.7 CVE-2026-28144 Patchstack
5.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control No login needed ≤ 3.7.39 Fixed in 3.7.40 CVE-2026-28145 Patchstack
5.3 Medium Fluent Forms Plugin fluentform Information Disclosure Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter No login needed ≤ 6.2.8 CVE-2026-17567 Wordfence
5.3 Medium MailPress Plugin mailerpress Broken Access Control Missing Authorization to Unauthenticated Contact Updates No login needed ≤ 1.5.0 CVE-2026-18437 Wordfence
5.3 Medium MailerPress Plugin mailerpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint No login needed ≤ 1.5.0 CVE-2026-18436 Wordfence
9.8 Critical ShopMonitor.io Plugin shopmonitorio Privilege Escalation Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-14919 WPScan
3.7 Low Support Genix Lite Plugin Broken Access Control Unauthenticated Ticket Attachment Download via Missing Authorization No login needed < 1.4.48 Fixed in 1.4.48 CVE-2026-14862 WPScan
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Field No login needed < 3.29.9 Fixed in 3.29.9 CVE-2026-13609 WPScan
3.5 Low ElementsKit Lite Plugin Cross-Site Scripting Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13393 WPScan
5.4 Medium wpForo Forum Plugin wpforo Broken Access Control Subscriber+ Cross-User AI Chat Message Deletion via IDOR < 3.1.2 Fixed in 3.1.2 CVE-2026-12697 WPScan
8.1 High miniOrange 2FA Plugin miniorange-2-factor-authentication Authentication Bypass miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret No login needed < 6.2.6 Fixed in 6.2.6 CVE-2026-12695 WPScan
4.3 Medium Academy LMS Plugin academy Information Disclosure Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint ≤ 3.8.2 CVE-2026-12376 WPScan
7.2 High ElementsKit Lite Plugin Remote Code Execution Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13392 WPScan
8.6 High Kirki Plugin kirki SQL Injection Unauthenticated SQL Injection No login needed < 6.0.13 Fixed in 6.0.13 CVE-2026-12721 WPScan
7.5 High Kirki Plugin kirki PHP Object Injection Unauthenticated PHP Object Injection No login needed < 6.0.13 Fixed in 6.0.13 CVE-2026-12720 WPScan
8.1 High Ultimate Member Plugin ultimate-member Privilege Escalation Unauthenticated Privilege Escalation via Role Selection Field No login needed < 2.12.1 Fixed in 2.12.1 CVE-2026-12251 WPScan
5.4 Medium BuddyPress Plugin buddypress Information Disclosure Subscriber+ Private Messages Disclosure via IDOR < 14.5.0 Fixed in 14.5.0 CVE-2026-8155 WPScan
3.7 Low WP Go Maps Plugin wp-google-maps SQL Injection Unauthenticated SQL Injection via Markers REST filter No login needed < 10.1.04 Fixed in 10.1.04 CVE-2026-15381 WPScan
8.1 High Product Feed Manager for WooCommerce Plugin webappick-product-feed-for-woocommerce SQL Injection Contributor+ SQL Injection via Feed Filter < 7.6.1 Fixed in 7.6.1 CVE-2026-15258 WPScan
6.5 Medium JS Help Desk – AI-Powered Support & Ticketing System Plugin js-support-ticket Information Disclosure AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR < 3.1.5 Fixed in 3.1.5 CVE-2026-15209 WPScan
7.5 High GeekyBot Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via Chat History No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-15048 WPScan
6.5 Medium JS Help Desk Plugin js-support-ticket Information Disclosure Contributor+ User Email Disclosure < 3.1.4 Fixed in 3.1.4 CVE-2026-14931 WPScan
7.5 High JS Help Desk Plugin js-support-ticket Broken Access Control Unauthenticated Arbitrary Ticket File Attachment Upload No login needed < 3.1.4 Fixed in 3.1.4 CVE-2026-14930 WPScan
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Subscriber+ Ticket Reply Modification via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-14929 WPScan
6.5 Medium JS Help Desk Plugin js-support-ticket Information Disclosure Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject < 3.1.4 Fixed in 3.1.4 CVE-2026-14928 WPScan
3.7 Low FluentCart Plugin Information Disclosure Unauthenticated Order PII Disclosure via Print Routes No login needed < 1.5.3 Fixed in 1.5.3 CVE-2026-14927 WPScan
6.1 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via ult_buttons Shortcode No login needed < 3.21.5 Fixed in 3.21.5 CVE-2026-14921 WPScan
3.7 Low Paid Member Subscriptions Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via Residual Export Files No login needed < 3.0.7 Fixed in 3.0.7 CVE-2026-14849 WPScan
4.3 Medium Paid Member Subscriptions Plugin Information Disclosure Subscriber+ Payment Data Disclosure via IDOR < 3.0.7 Fixed in 3.0.7 CVE-2026-14847 WPScan
6.1 Medium NewStatPress Plugin Cross-Site Scripting Unauthenticated Stored XSS via Top Post Widget No login needed < 1.4.5 Fixed in 1.4.5 CVE-2026-14845 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only