WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 3,051–3,100 of 17,704 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.4 Medium | VideoZen | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'VideoZen available subtitles languages' Field |
≤ 1.0.1 |
CVE-2026-6439 |
Wordfence | |
| 4.3 Medium | CMS für Motorrad Werkstätten | Cross-Site Request Forgery No login needed |
≤ 1.0.0 |
CVE-2026-6451 |
Wordfence | |
| 4.3 Medium | Canto | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Setting Modification |
≤ 3.1.1 |
CVE-2026-6441 |
Wordfence | |
| 5.3 Medium | Quiz and Survey Master (QSM) | Content Injection Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields No login needed |
≤ 10.1.0 |
CVE-2026-5797 |
Wordfence | |
| 5.3 Medium | Tutor LMS | Broken Access Control Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order No login needed |
≤ 3.9.8 |
CVE-2026-5502 |
Wordfence | |
| 6.5 Medium | Tutor LMS | SQL Injection Authenticated (Admin+) SQL Injection via 'date' Parameter |
≤ 3.9.8 |
CVE-2026-6080 |
Wordfence | |
| 5.3 Medium | Kubio AI Page Builder | Broken Access Control Missing Authorization to Authenticated (Contributor+) Limited File Upload via Kubio Block Attributes No login needed |
≤ 2.7.2 |
CVE-2026-5427 |
Wordfence | |
| 5.3 Medium | LatePoint | Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Financial Data Exposure via Sequential Invoice ID No login needed |
≤ 5.3.2 |
CVE-2026-5234 |
Wordfence | |
| 4.9 Medium | JetBackup | Arbitrary File Deletion Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal in 'fileName' Parameter |
≤ 3.1.19.8 |
CVE-2026-4853 |
Wordfence | |
| 4.9 Medium | Form Maker by 10Web | SQL Injection Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter |
≤ 1.15.40 |
CVE-2026-3330 |
Wordfence | |
| 6.5 Medium | wpForo Forum | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Forum Post Modification via 'guestposting' Parameter |
≤ 2.4.16 |
CVE-2026-4666 |
Wordfence | |
| 6.5 Medium | MasterStudy LMS | SQL Injection Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters |
≤ 3.7.25 |
CVE-2026-4817 |
Wordfence | |
| 6.5 Medium | WP Statistics | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure and Privacy Audit Manipulation No login needed |
≤ 14.16.4 |
CVE-2026-3488 |
Wordfence | |
| 6.4 Medium | Royal Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Instagram Feed Widget |
≤ 1.7.1056 |
CVE-2026-5162 |
Wordfence | |
| 6.4 Medium | Email Encoder – Protect Email Addresses and Phone Numbers | Cross-Site Scripting Protect Email Addresses and Phone Numbers <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via eeb_mailto Shortcode |
≤ 2.4.4 |
CVE-2026-2840 |
Wordfence | |
| 5.3 Medium | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed |
6.1.21 |
CVE-2026-4160 |
Wordfence | |
| 5.4 Medium | Better Find and Replace – AI-Powered Suggestions | Cross-Site Scripting AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title |
≤ 1.7.9 |
CVE-2026-3369 |
Wordfence | |
| 5.3 Medium | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | Broken Access Control PostX <= 5.0.5 - Missing Authorization to Limited Post Meta Modification No login needed |
≤ 5.0.5 |
CVE-2026-0718 |
Wordfence | |
| 6.1 Medium | Customer Reviews for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via 'crsearch' No login needed |
≤ 5.101.0 |
CVE-2026-3355 |
Wordfence | |
| 6.4 Medium | WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters | Cross-Site Scripting Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters <= 4.8.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'put_wpgm' Shortcode |
≤ 4.8.7 |
CVE-2025-13364 |
Wordfence | |
| 4.4 Medium | OPEN-BRAIN | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'API Key' Setting |
≤ 0.5.0 |
CVE-2026-3995 |
Wordfence | |
| 6.4 Medium | BetterDocs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 4.3.8 |
CVE-2026-3875 |
Wordfence | |
| 6.4 Medium | Livemesh Addons by Elementor | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via Plugin Settings |
≤ 9.0 |
CVE-2026-1572 |
Wordfence | |
| 5.3 Medium | Basic Google Maps Placemarks | Broken Access Control Missing Authorization to Unauthenticated Default Map Coordinate Update No login needed |
≤ 1.10.7 |
CVE-2026-3581 |
Wordfence | |
| 6.5 Medium | Accessibility Suite by Ability, Inc | SQL Injection Authenticated (Subscriber+) SQL Injection via 'scan_id' Parameter |
≤ 4.20 |
CVE-2026-3773 |
Wordfence | |
| 4.4 Medium | Custom New User Notification | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'User Mail Subject' Setting |
≤ 1.2.0 |
CVE-2026-3551 |
Wordfence | |
| 5.3 Medium | Riaxe Product Customizer | Broken Access Control Unauthenticated Arbitrary User Deletion via 'user_id' Parameter No login needed |
≤ 2.1.2 |
CVE-2026-3595 |
Wordfence | |
| 6.4 Medium | Vantage | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Block Text Content |
≤ 1.20.32 |
CVE-2026-5070 |
Wordfence | |
| 6.4 Medium | WP Docs | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wpdocs_options[icon_size]' |
≤ 2.2.9 |
CVE-2026-3878 |
Wordfence | |
| 6.1 Medium | CodeColorer | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'class' attribute in 'cc' Comment Shortcode No login needed |
≤ 0.10.1 |
CVE-2026-4032 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via su_box Shortcode |
≤ 7.4.9 |
CVE-2026-3885 |
Wordfence | |
| 6.4 Medium | WP YouTube Lyte | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via lyte Shortcode |
≤ 1.7.29 |
CVE-2026-3299 |
Wordfence | |
| 4.3 Medium | ProfilePress | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription |
≤ 4.16.12 |
CVE-2026-4949 |
Wordfence | |
| 5.9 Medium | Mini Ajax Cart for WooCommerce | Cross-Site Scripting |
≤ 1.3.4 Fixed in 1.3.5 |
CVE-2026-6370 |
Patchstack | |
| 6.5 Medium | YouTube Showcase | Cross-Site Scripting |
≤ 3.5.1 Fixed in 3.5.2 |
CVE-2025-15636 |
Patchstack | |
| 4.3 Medium | Smart Online Order for Clover | Cross-Site Request Forgery No login needed |
≤ 1.6.0 |
CVE-2025-15635 |
Patchstack | |
| 4.3 Medium | Userpro | Cross-Site Request Forgery No login needed |
≤ 5.1.11 Fixed in 5.1.11 |
CVE-2025-53444 |
Patchstack | |
| 6.1 Medium | Product Pricing Table by WooBeWoo | Cross-Site Request Forgery Cross-Site Request Forgery to Stored XSS and Pricing Table Deletion No login needed |
≤ 1.1.0 |
CVE-2026-1852 |
Wordfence | |
| 4.3 Medium | MyRewards | Broken Access Control |
≤ 5.7.3 Fixed in 5.7.4 |
CVE-2026-40786 |
Patchstack | |
| 5.3 Medium | Majestic Support | Broken Access Control No login needed |
≤ 1.1.2 Fixed in 1.1.3 |
CVE-2026-40778 |
Patchstack | |
| 5.3 Medium | Royal Elementor Addons | Broken Access Control No login needed |
≤ 1.7.1056 Fixed in 1.7.1057 |
CVE-2026-40763 |
Patchstack | |
| 5.3 Medium | Nelio AB Testing | Information Disclosure Sensitive Data Exposure No login needed |
≤ 8.2.8 Fixed in 8.3.0 |
CVE-2026-40742 |
Patchstack | |
| 5.4 Medium | Tutor LMS | Broken Access Control |
≤ 3.9.7 Fixed in 3.9.8 |
CVE-2026-40740 |
Patchstack | |
| 5.3 Medium | COMPE | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 1.1.4 Fixed in 1.1.5 |
CVE-2026-40737 |
Patchstack | |
| 6.5 Medium | Categories Images | Cross-Site Scripting |
≤ 3.3.1 Fixed in 3.3.2 |
CVE-2026-40734 |
Patchstack | |
| 5.3 Medium | ThemeGrill Demo Importer | Broken Access Control No login needed |
≤ 2.0.0.6 Fixed in 2.0.0.7 |
CVE-2026-40730 |
Patchstack | |
| 4.3 Medium | 3D viewer – Embed 3D Models | Broken Access Control Embed 3D Models plugin <= 1.8.5 - Broken Access Control |
≤ 1.8.5 Fixed in 1.8.6 |
CVE-2026-40729 |
Patchstack | |
| 4.3 Medium | Magazine Blocks | Broken Access Control |
≤ 1.8.3 Fixed in 1.8.4 |
CVE-2026-40728 |
Patchstack | |
| 6.4 Medium | Power Charts | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 0.1.0 |
CVE-2026-4011 |
Wordfence | |
| 6.4 Medium | WM JqMath | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute |
≤ 1.3 |
CVE-2026-3998 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.