WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,051–3,100 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 62 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium VideoZen Plugin videozen Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'VideoZen available subtitles languages' Field ≤ 1.0.1 CVE-2026-6439 Wordfence
4.3 Medium CMS für Motorrad Werkstätten Plugin cms-fuer-motorrad-werkstaetten Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2026-6451 Wordfence
4.3 Medium Canto Plugin canto Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification ≤ 3.1.1 CVE-2026-6441 Wordfence
5.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Content Injection Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields No login needed ≤ 10.1.0 CVE-2026-5797 Wordfence
5.3 Medium Tutor LMS Plugin tutor Broken Access Control Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order No login needed ≤ 3.9.8 CVE-2026-5502 Wordfence
6.5 Medium Tutor LMS Plugin tutor SQL Injection Authenticated (Admin+) SQL Injection via 'date' Parameter ≤ 3.9.8 CVE-2026-6080 Wordfence
5.3 Medium Kubio AI Page Builder Plugin kubio Broken Access Control Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes No login needed ≤ 2.7.2 CVE-2026-5427 Wordfence
5.3 Medium LatePoint Plugin latepoint Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID No login needed ≤ 5.3.2 CVE-2026-5234 Wordfence
4.9 Medium JetBackup Plugin backup Arbitrary File Deletion Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal in 'fileName' Parameter ≤ 3.1.19.8 CVE-2026-4853 Wordfence
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter ≤ 1.15.40 CVE-2026-3330 Wordfence
6.5 Medium wpForo Forum Plugin wpforo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter ≤ 2.4.16 CVE-2026-4666 Wordfence
6.5 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters ≤ 3.7.25 CVE-2026-4817 Wordfence
6.5 Medium WP Statistics Plugin wp-statistics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure and Privacy Audit Manipulation No login needed ≤ 14.16.4 CVE-2026-3488 Wordfence
6.4 Medium Royal Addons for Elementor Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget ≤ 1.7.1056 CVE-2026-5162 Wordfence
6.4 Medium Email Encoder – Protect Email Addresses and Phone Numbers Plugin email-encoder-bundle Cross-Site Scripting Protect Email Addresses and Phone Numbers <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via eeb_mailto Shortcode ≤ 2.4.4 CVE-2026-2840 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
5.4 Medium Better Find and Replace – AI-Powered Suggestions Plugin real-time-auto-find-and-replace Cross-Site Scripting AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title ≤ 1.7.9 CVE-2026-3369 Wordfence
5.3 Medium Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX Plugin Broken Access Control PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification No login needed ≤ 5.0.5 CVE-2026-0718 Wordfence
6.1 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'crsearch' No login needed ≤ 5.101.0 CVE-2026-3355 Wordfence
6.4 Medium WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters Plugin Cross-Site Scripting Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode ≤ 4.8.7 CVE-2025-13364 Wordfence
4.4 Medium OPEN-BRAIN Plugin open-brain Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'API Key' Setting ≤ 0.5.0 CVE-2026-3995 Wordfence
6.4 Medium BetterDocs Plugin betterdocs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.3.8 CVE-2026-3875 Wordfence
6.4 Medium Livemesh Addons by Elementor Plugin addons-for-elementor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings ≤ 9.0 CVE-2026-1572 Wordfence
5.3 Medium Basic Google Maps Placemarks Plugin basic-google-maps-placemarks Broken Access Control Missing Authorization to Unauthenticated Default Map Coordinate Update No login needed ≤ 1.10.7 CVE-2026-3581 Wordfence
6.5 Medium Accessibility Suite by Ability, Inc Plugin online-accessibility SQL Injection Authenticated (Subscriber+) SQL Injection via 'scan_id' Parameter ≤ 4.20 CVE-2026-3773 Wordfence
4.4 Medium Custom New User Notification Plugin custom-new-user-notification Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'User Mail Subject' Setting ≤ 1.2.0 CVE-2026-3551 Wordfence
5.3 Medium Riaxe Product Customizer Plugin riaxe-product-customizer Broken Access Control Unauthenticated Arbitrary User Deletion via 'user_id' Parameter No login needed ≤ 2.1.2 CVE-2026-3595 Wordfence
6.4 Medium Vantage Theme vantage Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Block Text Content ≤ 1.20.32 CVE-2026-5070 Wordfence
6.4 Medium WP Docs Plugin wp-docs Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wpdocs_options[icon_size]' ≤ 2.2.9 CVE-2026-3878 Wordfence
6.1 Medium CodeColorer Plugin codecolorer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'class' attribute in 'cc' Comment Shortcode No login needed ≤ 0.10.1 CVE-2026-4032 Wordfence
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode ≤ 7.4.9 CVE-2026-3885 Wordfence
6.4 Medium WP YouTube Lyte Plugin wp-youtube-lyte Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via lyte Shortcode ≤ 1.7.29 CVE-2026-3299 Wordfence
4.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription ≤ 4.16.12 CVE-2026-4949 Wordfence
5.9 Medium Mini Ajax Cart for WooCommerce Plugin mini-ajax-woo-cart Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-6370 Patchstack
6.5 Medium YouTube Showcase Plugin youtube-showcase Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-15636 Patchstack
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Request Forgery No login needed ≤ 1.6.0 CVE-2025-15635 Patchstack
4.3 Medium Userpro Plugin userpro Cross-Site Request Forgery No login needed ≤ 5.1.11 Fixed in 5.1.11 CVE-2025-53444 Patchstack
6.1 Medium Product Pricing Table by WooBeWoo Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored XSS and Pricing Table Deletion No login needed ≤ 1.1.0 CVE-2026-1852 Wordfence
4.3 Medium MyRewards Plugin woorewards Broken Access Control ≤ 5.7.3 Fixed in 5.7.4 CVE-2026-40786 Patchstack
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2026-40778 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control No login needed ≤ 1.7.1056 Fixed in 1.7.1057 CVE-2026-40763 Patchstack
5.3 Medium Nelio AB Testing Plugin nelio-ab-testing Information Disclosure Sensitive Data Exposure No login needed ≤ 8.2.8 Fixed in 8.3.0 CVE-2026-40742 Patchstack
5.4 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-40740 Patchstack
5.3 Medium COMPE Plugin compe-woo-compare-products Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2026-40737 Patchstack
6.5 Medium Categories Images Plugin categories-images Cross-Site Scripting ≤ 3.3.1 Fixed in 3.3.2 CVE-2026-40734 Patchstack
5.3 Medium ThemeGrill Demo Importer Plugin themegrill-demo-importer Broken Access Control No login needed ≤ 2.0.0.6 Fixed in 2.0.0.7 CVE-2026-40730 Patchstack
4.3 Medium 3D viewer – Embed 3D Models Plugin 3d-viewer Broken Access Control Embed 3D Models plugin <= 1.8.5 - Broken Access Control ≤ 1.8.5 Fixed in 1.8.6 CVE-2026-40729 Patchstack
4.3 Medium Magazine Blocks Plugin magazine-blocks Broken Access Control ≤ 1.8.3 Fixed in 1.8.4 CVE-2026-40728 Patchstack
6.4 Medium Power Charts Plugin wpgo-power-charts-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 0.1.0 CVE-2026-4011 Wordfence
6.4 Medium WM JqMath Plugin wm-jqmath Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute ≤ 1.3 CVE-2026-3998 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only