WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,051–3,100 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 62 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Product Addons for Woocommerce – Product Options with Custom Fields Plugin woo-custom-product-addons Remote Code Execution Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter ≤ 3.1.0 CVE-2026-2296 Wordfence
7.2 High YayMail Plugin yaymail Broken Access Control Missing Authorization to Authenticated (Shop Manager+) Arbitrary Options Update via 'yaymail_import_state' AJAX Action ≤ 4.3.2 CVE-2026-1937 Wordfence
7.2 High Cart All In One For WooCommerce Plugin woo-cart-all-in-one Remote Code Execution Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting ≤ 1.1.21 CVE-2026-2019 Wordfence
7.5 High Video Conferencing with Zoom API Plugin Authentication Bypass Unauthenticated SDK Signature Generation No login needed < 4.6.6 Fixed in 4.6.6 CVE-2026-1368 WPScan
7.5 High Business Directory Plugin business-directory-plugin SQL Injection Unauthenticated SQL Injection via payment Parameter No login needed ≤ 6.4.21 CVE-2026-2576 Wordfence
8.6 High ShopLentor Plugin woolentor-addons Content Injection Unauthenticated Email Relay Abuse via 'woolentor_suggest_price_action' AJAX Action No login needed ≤ 3.3.2 CVE-2026-1714 Wordfence
7.2 High Rent Fetch Plugin rentfetch Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'keyword' Parameter No login needed ≤ 0.32.6 CVE-2026-1931 Wordfence
7.2 High RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting Reflected Cross-Site Scripting via 'template' Parameter No login needed ≤ 5.0.10 CVE-2026-1216 Wordfence
7.7 High Zarinpal Gateway for WooCommerce Plugin zarinpal-woocommerce-payment-gateway Broken Access Control Improper Access Control to Payment Status Update No login needed ≤ 5.0.16 CVE-2026-2592 Wordfence
8.8 High WP Maps Plugin wp-google-map-plugin Local File Inclusion Authenticated (Subscriber+) Limited Local File Inclusion ≤ 4.8.6 CVE-2025-12062 Wordfence
8.8 High WowRevenue Plugin revenue Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 2.1.3 CVE-2026-2001 Wordfence
8.8 High Ecwid by Lightspeed Ecommerce Shopping Cart Plugin ecwid-shopping-cart Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via ec_store_admin_access ≤ 7.0.7 CVE-2026-1750 Wordfence
7.2 High Super Page Cache Plugin wp-cloudflare-page-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Activity Log No login needed ≤ 5.2.2 CVE-2026-1843 Wordfence
7.5 High Flexi Product Slider and Grid for WooCommerce Plugin flexi-product-slider-grid Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute ≤ 1.0.5 CVE-2026-1988 Wordfence
7.2 High Super Simple Contact Form Plugin super-simple-contact-form Cross-Site Scripting Reflected Cross-Site Scripting via 'sscf_name' Parameter No login needed ≤ 1.6.2 CVE-2026-0753 Wordfence
7.5 High PhotoStack Gallery Plugin photostack-gallery SQL Injection Unauthenticated SQL Injection via 'postid' Parameter No login needed ≤ 0.4.1 CVE-2026-2024 Wordfence
7.5 High BlueSnap Payment Gateway for WooCommerce Plugin bluesnap-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation No login needed ≤ 3.4.0 CVE-2026-0692 Wordfence
8.1 High Magic Login Mail or QR Code Plugin magic-login-mail Privilege Escalation Unauthenticated Privilege Escalation via Insecure QR Code File Storage No login needed ≤ 2.05 CVE-2026-2144 Wordfence
7.2 High PixelYourSite Plugin pixelyoursite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 11.2.0 CVE-2026-1841 Wordfence
7.2 High PixelYourSite PRO Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 12.4.0.2 CVE-2026-1844 Wordfence
8.8 High Starfish Review Generation & Marketing Plugin starfish-reviews Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update via srm_restore_options_defaults ≤ 3.1.19 CVE-2025-15157 Wordfence
8.8 High FastDup – Fastest WordPress Migration & Duplicator Plugin fastdup Broken Access Control Fastest WordPress Migration & Duplicator <= 2.7.1 - Missing Authorization to Authenticated (Contributor+) Backup Creation and Download ≤ 2.7.1 CVE-2026-1104 Wordfence
7.2 High Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via X-Forwarded-For Header No login needed ≤ 4.9.8 CVE-2026-1320 Wordfence
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via media[].href Parameter No login needed ≤ 5.97.0 CVE-2026-1316 Wordfence
8.8 High wpForo Forum Plugin wpforo PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 2.4.13 CVE-2026-0910 Wordfence
8.8 High Videospirecore Theme Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via User Email Change/Account Takeover ≤ 1.0.6 CVE-2025-15096 Wordfence
8.8 High Custom Block Builder – Lazy Blocks Plugin lazy-blocks Remote Code Execution Lazy Blocks <= 4.2.0 - Authenticated (Contributor+) Remote Code Execution ≤ 4.2.0 CVE-2026-1560 Wordfence
7.2 High iONE360 configurator Plugin ione360-configurator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Contact Form Parameters No login needed ≤ 2.0.57 CVE-2025-15440 Wordfence
7.2 High Lucky Wheel Giveaway Plugin wp-lucky-wheel Remote Code Execution Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter ≤ 1.0.22 CVE-2025-14541 Wordfence
7.2 High Name Directory Plugin name-directory Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Double HTML-Entity Encoding in Submission Form No login needed ≤ 1.32.0 CVE-2026-1866 Wordfence
7.5 High Ninja Forms Plugin ninja-forms Information Disclosure Unauthenticated Information Disclosure in nf_ajax_submit AJAX Action No login needed ≤ 3.14.0 CVE-2026-2268 Wordfence
7.2 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update ≤ 6.7.24 CVE-2026-0845 Wordfence
8.8 High JAY Login & Register Plugin jay-login-register Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via jay_panel_ajax_update_profile ≤ 2.6.03 CVE-2025-15100 Wordfence
8.8 High WP Duplicate Plugin local-sync Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via 'process_add_site' AJAX Action ≤ 1.1.8 CVE-2026-1499 Wordfence
7.2 High All In One Image Viewer Block Plugin image-viewer Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via image-proxy Endpoint No login needed ≤ 1.0.2 CVE-2026-1294 Wordfence
8.2 High Popup builder with Gamification Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via Multiple REST API Endpoints No login needed ≤ 2.2.0 CVE-2025-13192 Wordfence
8.8 High SportsPress Plugin sportspress Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.7.26 CVE-2025-15368 Wordfence
7.5 High Infility Global Plugin infility-global SQL Injection Unauthenticated SQL Injection via Predictable API Key and IP Whitelist Bypass No login needed ≤ 2.14.46 CVE-2025-15268 Wordfence
7.5 High SEO Flow by LupsOnline Plugin lupsonline-link-netwerk Broken Access Control Unauthenticated Arbitrary Post/Category Modification No login needed ≤ 2.2.1 CVE-2025-15285 Wordfence
8.8 High WP FOFT Loader Plugin wp-foft-loader Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.1.39 CVE-2026-1756 Wordfence
7.5 High Unicamp Plugin unicamp Local File Inclusion ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-25027 Patchstack
8.5 High KiviCare Plugin kivicare-clinic-management-system SQL Injection ≤ 3.6.16 Fixed in 4.0.0 CVE-2026-25022 Patchstack
8.8 High WpEvently Plugin mage-eventpress PHP Object Injection Deserialization of untrusted data ≤ 5.0.8 Fixed in 5.0.9 CVE-2026-24954 Patchstack
8.8 High OS DataHub Maps Plugin os-datahub-maps Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 1.8.3 CVE-2026-1730 Wordfence
8.1 High Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion ≤ 3.9.5 CVE-2026-1375 Wordfence
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Hidden Field No login needed ≤ 1.15.35 CVE-2026-1058 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG file No login needed ≤ 1.15.35 CVE-2026-1065 Wordfence
7.2 High LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Scripting Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2026-0617 Wordfence
7.5 High Spirit Framework Plugin spirit-framework Local File Inclusion ≤ 1.2.13 CVE-2024-54263 Patchstack
7.1 High Library Viewer Plugin library-viewer Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 3.2.0 Fixed in 3.2.0 CVE-2025-15396 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only