WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 3,001–3,050 of 17,704 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Posts map | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute |
≤ 0.1.3 |
CVE-2026-6236 |
Wordfence | |
| 4.3 Medium | DX Unanswered Comments | Cross-Site Request Forgery Cross-Site Request Forgery via Settings Update No login needed |
≤ 1.7 |
CVE-2026-4138 |
Wordfence | |
| 5.3 Medium | CalJ | Broken Access Control Authenticated (Subscriber+) Arbitrary Settings Modification via 'save-obtained-key' Action No login needed |
≤ 1.5 |
CVE-2026-4117 |
Wordfence | |
| 4.3 Medium | Kcaptcha | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.1 |
CVE-2026-4121 |
Wordfence | |
| 4.4 Medium | Private WP suite | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Exceptions' Setting |
≤ 0.4.1 |
CVE-2026-2719 |
Wordfence | |
| 6.4 Medium | Text Snippets | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'w' Shortcode Attribute |
≤ 0.0.1 |
CVE-2026-5748 |
Wordfence | |
| 6.4 Medium | Quran Live Multilanguage | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.3 |
CVE-2026-4074 |
Wordfence | |
| 6.4 Medium | Simple Random Posts Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'container_right_width' Shortcode Attribute |
≤ 0.3 |
CVE-2026-6246 |
Wordfence | |
| 4.4 Medium | Sentence To SEO (keywords, description and tags) | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Permanent keywords' Field |
≤ 1.0 |
CVE-2026-4142 |
Wordfence | |
| 6.4 Medium | Easy Social Photos Gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper_class' Shortcode Attribute |
≤ 3.1.2 |
CVE-2026-4085 |
Wordfence | |
| 6.1 Medium | Inquiry cart | Cross-Site Request Forgery Cross-Site Request Forgery via Settings Form No login needed |
≤ 3.4.2 |
CVE-2026-4090 |
Wordfence | |
| 5.5 Medium | HTTP Headers | Denial of Service Authenticated (Administrator+) CRLF Injection via Custom Header Values |
≤ 1.19.2 |
CVE-2026-2717 |
Wordfence | |
| 4.3 Medium | mCatFilter | Cross-Site Request Forgery Cross-Site Request Forgery via compute_post() Function No login needed |
≤ 0.5.2 |
CVE-2026-4139 |
Wordfence | |
| 6.4 Medium | WPMK Block | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.1 |
CVE-2026-4125 |
Wordfence | |
| 4.3 Medium | Call To Action | Cross-Site Request Forgery Cross-Site Request Forgery via Settings Update No login needed |
≤ 3.1.3 |
CVE-2026-4118 |
Wordfence | |
| 6.4 Medium | SlideShowPro SC | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'album' Shortcode Attribute |
≤ 1.0.2 |
CVE-2026-5767 |
Wordfence | |
| 4.3 Medium | TP Restore Categories And Taxonomies | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Taxonomy Deletion via 'tpmcattt_delete_term' AJAX Action |
≤ 1.0.1 |
CVE-2026-4128 |
Wordfence | |
| 6.4 Medium | Twittee Text Tweet | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 1.0.8 |
CVE-2026-4089 |
Wordfence | |
| 4.3 Medium | Fast & Fancy Filter – 3F | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Modification via fff_save_settins AJAX Action No login needed |
≤ 1.2.2 |
CVE-2026-6396 |
Wordfence | |
| 4.4 Medium | Short Comment Filter | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Minimum Count' Setting |
≤ 2.2 |
CVE-2026-3362 |
Wordfence | |
| 6.5 Medium | Breaking News WP | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/Read |
≤ 1.3 |
CVE-2026-4280 |
Wordfence | |
| 4.3 Medium | Ni WooCommerce Order Export | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action No login needed |
≤ 3.1.6 |
CVE-2026-4140 |
Wordfence | |
| 4.3 Medium | TextP2P Texting Widget | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.7 |
CVE-2026-4133 |
Wordfence | |
| 4.3 Medium | Table Manager | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via 'table' Shortcode Attribute |
≤ 1.0.0 |
CVE-2026-4126 |
Wordfence | |
| 6.4 Medium | Slider Bootstrap Carousel | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.7 |
CVE-2026-4076 |
Wordfence | |
| 4.4 Medium | Institute Management | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Enquiry Form Title' Setting |
≤ 5.5 |
CVE-2026-2714 |
Wordfence | |
| 4.4 Medium | Buzz Comments | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Buzz Avatar' Setting |
≤ 0.9.4 |
CVE-2026-6041 |
Wordfence | |
| 6.4 Medium | Switch CTA Box | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.1 |
CVE-2026-4088 |
Wordfence | |
| 5.5 Medium | Real Estate Pro | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Settings |
≤ 1.0.9 |
CVE-2026-1845 |
Wordfence | |
| 6.1 Medium | WP Responsive Popup + Optin | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'wpo_image_url' Parameter No login needed |
≤ 1.4 |
CVE-2026-4131 |
Wordfence | |
| 6.4 Medium | ER Swiffy Insert | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.0 |
CVE-2026-4082 |
Wordfence | |
| 6.4 Medium | Bread & Butter: Content Gating for Verified Leads | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 8.2.0.25 |
CVE-2026-4279 |
Wordfence | |
| 4.4 Medium | HTTP Headers | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Headers' Plugin Setting |
≤ 1.19.2 |
CVE-2026-1379 |
Wordfence | |
| 6.4 Medium | Zypento Blocks | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Table of Contents Block |
≤ 1.06 |
CVE-2026-5820 |
Wordfence | |
| 4.4 Medium | Website LLMs.txt | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 8.2.6 |
CVE-2026-6712 |
Wordfence | |
| 6.1 Medium | Website LLMs.txt | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 8.2.6 |
CVE-2026-6711 |
Wordfence | |
| 4.3 Medium | Responsive Blocks | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via AJAX Actions |
2.0.9 – 2.2.1 |
CVE-2026-6703 |
Wordfence | |
| 6.5 Medium | Plugin: CMS für Motorrad Werkstätten | SQL Injection Authenticated (Subscriber+) SQL Injection via 'arttype' Parameter |
≤ 1.0.0 |
CVE-2026-6674 |
Wordfence | |
| 5.3 Medium | Responsive Blocks | Other Unauthenticated Open Email Relay via REST API 'email_to' Parameter No login needed |
≤ 2.2.0 |
CVE-2026-6675 |
Wordfence | |
| 4.7 Medium | wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts | Cross-Site Scripting WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import No login needed |
≤ 6.5.0.4 |
CVE-2026-5721 |
Wordfence | |
| 6.4 Medium | Image Source Control Lite – Show Image Credits and Captions | Cross-Site Scripting Show Image Credits and Captions <= 3.9.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'Image Source' Field |
≤ 3.9.1 |
CVE-2026-4852 |
Wordfence | |
| 6.4 Medium | EMC Scheduling Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via calendly Shortcode |
≤ 4.4 |
CVE-2026-0868 |
Wordfence | |
| 6.4 Medium | Contextual Related Posts | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'other_attributes' |
≤ 4.2.1 |
CVE-2026-2986 |
Wordfence | |
| 5.4 Medium | Categories Images | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'z_taxonomy_image' Shortcode |
≤ 3.3.1 |
CVE-2026-2505 |
Wordfence | |
| 6.4 Medium | Content Blocks (Custom Post Widget) | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via content_block Shortcode |
≤ 3.3.9 |
CVE-2026-0894 |
Wordfence | |
| 6.4 Medium | Flipbox Addon for Elementor | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Attributes |
≤ 2.0.8 |
CVE-2026-6048 |
Wordfence | |
| 6.4 Medium | Page Builder Gutenberg Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via External iCal Feed Data |
≤ 3.1.16 |
CVE-2026-4801 |
Wordfence | |
| 6.4 Medium | Youzify | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_place_id' Parameter |
≤ 1.3.6 |
CVE-2026-1559 |
Wordfence | |
| 6.1 Medium | Hostel | Cross-Site Scripting Reflected Cross-Site Scripting via 'shortcode_id' Parameter No login needed |
≤ 1.1.6 |
CVE-2026-1838 |
Wordfence | |
| 6.4 Medium | Pz-LinkCard | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 2.5.8.1 |
CVE-2026-2434 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.