WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 3,051–3,100 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Events Made Easy | Broken Access Control Unauthenticated Person Data Modification via IDOR No login needed |
< 3.1.4 Fixed in 3.1.4 |
CVE-2026-14843 |
WPScan | |
| 6.5 Medium | Mailgun | Broken Access Control Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX No login needed |
< 2.2.1 Fixed in 2.2.1 |
CVE-2026-14834 |
WPScan | |
| 6.8 Medium | Lightbox with PhotoSwipe | Cross-Site Scripting Author+ Stored XSS via data-lbwps-caption Attribute |
< 5.9.0 Fixed in 5.9.0 |
CVE-2026-14833 |
WPScan | |
| 7.5 High | FlxWoo | Price Manipulation Unauthenticated Payment Bypass No login needed |
< 3.1.1 Fixed in 3.1.1 |
CVE-2026-14830 |
WPScan | |
| 6.5 Medium | Check & Log Email | SQL Injection Admin+ SQL Injection via d and s Parameters |
< 2.0.15 Fixed in 2.0.15 |
CVE-2026-14554 |
WPScan | |
| 7.5 High | Demi - One Click Demo Import, Backup & Site Migration | Information Disclosure One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory No login needed |
< 0.0.7 Fixed in 0.0.7 |
CVE-2026-14333 |
WPScan | |
| 7.5 High | GiveWP | Information Disclosure Unauthenticated Recurring Donor Information Disclosure No login needed |
< 4.16.3 Fixed in 4.16.3 |
CVE-2026-14319 |
WPScan | |
| 5.3 Medium | GiveWP | Broken Access Control Unauthenticated Payment Gateway Restriction Bypass No login needed |
< 4.16.3 Fixed in 4.16.3 |
CVE-2026-14317 |
WPScan | |
| 8.8 High | Realtyna Organic IDX plugin + WPL Real Estate | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 5.3.0 |
CVE-2026-16236 |
Wordfence | |
| 9.8 Critical | Realtyna Organic IDX plugin + WPL Real Estate | Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command No login needed |
≤ 5.2.0 |
CVE-2026-14483 |
Wordfence | |
| 4.3 Medium | FuseWP | Cross-Site Request Forgery Cross-Site Request Forgery to Sync Rule Status Toggle No login needed |
≤ 1.1.24.2 |
CVE-2026-5582 |
Wordfence | |
| 7.2 High | Subscriptions for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action |
≤ 2.0.0 |
CVE-2026-15397 |
Wordfence | |
| 5.4 Medium | Tutor LMS | Information Disclosure Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection |
< 4.0.0 Fixed in 4.0.0 |
CVE-2026-14310 |
WPScan | |
| 5.3 Medium | WP Delicious | Authentication Bypass Unauthenticated Arbitrary Post Meta Update via recipe_likes No login needed |
< 1.10.2 Fixed in 1.10.2 |
CVE-2026-14305 |
WPScan | |
| 7.1 High | Tourmaster | Cross-Site Scripting Stored XSS via CSRF No login needed |
< 5.4.8 Fixed in 5.4.8 |
CVE-2026-14239 |
WPScan | |
| 8.6 High | Bookly | SQL Injection Unauthenticated SQL Injection via staff_id No login needed |
< 27.8 Fixed in 27.8 |
CVE-2026-13395 |
WPScan | |
| 5.3 Medium | Essential Addons for Elementor - Lite | Information Disclosure Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table No login needed |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13345 |
WPScan | |
| 4.8 Medium | Essential Addons for Elementor - Lite | Cross-Site Scripting Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag |
< 6.6.10 Fixed in 6.6.10 |
CVE-2026-13344 |
WPScan | |
| 6.1 Medium | Animation Addons for Elementor | Cross-Site Scripting Author+ Stored XSS via SVG Upload No login needed |
< 2.7.0 Fixed in 2.7.0 |
CVE-2026-13330 |
WPScan | |
| 7.5 High | Eventin | Price Manipulation Unauthenticated Payment Bypass via Order Status Manipulation No login needed |
< 4.1.16 Fixed in 4.1.16 |
CVE-2026-13178 |
WPScan | |
| 4.3 Medium | WP Travel | Information Disclosure Subscriber+ Booking PII Disclosure via IDOR |
< 11.8.1 Fixed in 11.8.1 |
CVE-2026-13145 |
WPScan | |
| 5.3 Medium | WP Travel | Price Manipulation Unauthenticated Payment Bypass via Forged PayPal IPN No login needed |
< 11.8.1 Fixed in 11.8.1 |
CVE-2026-13143 |
WPScan | |
| 7.5 High | WP Travel Engine | Broken Access Control Unauthenticated Trip Difficulty Level Option Update No login needed |
< 6.8.2 Fixed in 6.8.2 |
CVE-2026-12500 |
WPScan | |
| 6.1 Medium | Fluent Forms | Cross-Site Scripting Contributor+ Stored XSS via Date/Time Field No login needed |
< 6.2.6 Fixed in 6.2.6 |
CVE-2026-11881 |
WPScan | |
| 5.4 Medium | Hide My WP Ghost | Authentication Bypass IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass |
< 7.0.05 Fixed in 7.0.05 |
CVE-2026-11870 |
WPScan | |
| 6.5 Medium | Frontend Admin by DynamiApps | Broken Access Control Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization |
< 3.29.7 Fixed in 3.29.7 |
CVE-2026-11867 |
WPScan | |
| 6.5 Medium | Ultimate Addons for WPBakery Page Builder | Path Traversal Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts No login needed |
< 3.21.4 Fixed in 3.21.4 |
CVE-2026-15382 |
WPScan | |
| 5.3 Medium | RegistrationMagic | Broken Access Control Unauthenticated Form Submission and User Profile Modification No login needed |
< 6.0.9.4 Fixed in 6.0.9.4 |
CVE-2026-15257 |
WPScan | |
| 5.3 Medium | RegistrationMagic | Information Disclosure Unauthenticated Form Submission Disclosure via IDOR No login needed |
< 6.0.9.4 Fixed in 6.0.9.4 |
CVE-2026-15255 |
WPScan | |
| 5.4 Medium | Search Atlas SEO | Broken Access Control Subscriber+ Google Indexing API Access |
< 2.6.12 Fixed in 2.6.12 |
CVE-2026-15252 |
WPScan | |
| 5.9 Medium | Points and Rewards for WooCommerce | Broken Access Control Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR No login needed |
< 2.10.1 Fixed in 2.10.1 |
CVE-2026-11782 |
WPScan | |
| 5.3 Medium | LatePoint | Broken Access Control Unauthenticated Booking Object Mass Assignment via Public Booking Funnel No login needed |
< 5.6.8 Fixed in 5.6.8 |
CVE-2026-15250 |
WPScan | |
| 7.5 High | Customer Switching for WooCommerce | Privilege Escalation Customer+ Privilege Escalation to Administrator via Insecure Operator Resolution |
< 2.1.3 Fixed in 2.1.3 |
CVE-2026-15240 |
WPScan | |
| 6.8 Medium | GiveWP | Cross-Site Scripting GiveWP Worker+ Stored XSS via Donation Form Template Settings |
< 4.16.3 Fixed in 4.16.3 |
CVE-2026-14318 |
WPScan | |
| 4.3 Medium | LifterLMS | Information Disclosure Subscriber+ Sensitive Information Disclosure via select2_query_posts |
< 10.0.10 Fixed in 10.0.10 |
CVE-2026-14231 |
WPScan | |
| 6.1 Medium | LifterLMS | Cross-Site Scripting Instructor+ Stored XSS via Featured Pricing Information No login needed |
9.2.3 – < 10.0.10 Fixed in 10.0.10 |
CVE-2026-14207 |
WPScan | |
| 4.3 Medium | Hotel Booking Lite | Information Disclosure Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action |
< 6.0.4 Fixed in 6.0.4 |
CVE-2026-15235 |
WPScan | |
| 6.8 Medium | WP Hotel Booking | SQL Injection Hotel Manager+ SQL Injection via Booking List Search |
< 2.3.2 Fixed in 2.3.2 |
CVE-2026-15153 |
WPScan | |
| 3.7 Low | Bit Form | Broken Access Control Unauthenticated Inactive Form Submission No login needed |
< 3.1.2 Fixed in 3.1.2 |
CVE-2026-15054 |
WPScan | |
| 7.5 High | ProfileGrid | Privilege Escalation Unauthenticated Privilege Escalation via Unrestricted Group ID No login needed |
< 5.9.9.8 Fixed in 5.9.9.8 |
CVE-2026-12687 |
WPScan | |
| 6.5 Medium | Sync Post With Other Site | Broken Access Control Contributor+ Arbitrary Page Creation/Modification |
< 1.9.3 Fixed in 1.9.3 |
CVE-2026-14923 |
WPScan | |
| 9.0 Critical | Remote API | PHP Object Injection Unauthenticated PHP Object Injection via remote-api Query Parameter No login needed |
≤ 0.2 |
CVE-2026-14602 |
WPScan | |
| 6.1 Medium | WP Real IP-based Access Control | Cross-Site Scripting Unauthenticated Stored XSS via acl_ctrl_addr No login needed |
≤ 1.3.1 |
CVE-2026-14592 |
WPScan | |
| 4.3 Medium | Easy Appointments | Information Disclosure Subscriber+ Sensitive Information Disclosure via REST Appointments Listing |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14226 |
WPScan | |
| 4.3 Medium | Easy Appointments | Information Disclosure Subscriber+ Customer PII Disclosure via IDOR |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14223 |
WPScan | |
| 3.8 Low | Easy Appointments | Broken Access Control Contributor+ Connection Deletion via Missing Authorization |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14222 |
WPScan | |
| 3.8 Low | Easy Appointments | Information Disclosure Contributor+ Appointment Data Disclosure & Modification via Missing Authorization |
≤ 4.0 |
CVE-2026-14221 |
WPScan | |
| 2.7 Low | Easy Appointments | Information Disclosure Contributor+ Customer Data Disclosure |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14188 |
WPScan | |
| 7.5 High | BuddyPress | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data |
≤ 14.5.0 |
CVE-2026-1360 |
Wordfence | |
| 9.8 Critical | Admin and Site Enhancements (ASE) Pro | Remote Code Execution Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key No login needed |
≤ 8.9.0 |
CVE-2026-16610 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.