WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 3,101–3,150 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | FleekDash V2 | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover via /users/{id} REST Endpoint |
≤ 2.6.2.2 |
CVE-2026-14356 |
Wordfence | |
| 6.5 Medium | Improved Save Button | SQL Injection Authenticated (Author+) Second-Order SQL Injection via 'meta_key' Parameter |
≤ 1.2.1 |
CVE-2026-16092 |
Wordfence | |
| 5.3 Medium | Persian Elementor (المنتور فارسی) | Price Manipulation Unauthenticated Price Manipulation via ZarinPal Widget No login needed |
≤ 2.8.1 |
CVE-2026-1982 |
Wordfence | |
| 8.8 High | Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload in eco_save_settings |
≤ 2.3.2 |
CVE-2026-14270 |
Wordfence | |
| 9.1 Critical | Meta Box AIO | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter No login needed |
≤ 3.8.0 |
CVE-2026-14488 |
Wordfence | |
| 6.4 Medium | Booking System Trafft | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
<= 1.0.17 |
CVE-2026-8791 |
Wordfence | |
| 4.9 Medium | WP CTA | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
2.1.2 |
CVE-2026-6089 |
Wordfence | |
| 7.2 High | Fluent Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member No login needed |
≤ 6.2.7 |
CVE-2026-16655 |
Wordfence | |
| 6.4 Medium | WPC Badge Management for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Attribute |
≤ 3.1.6 |
CVE-2026-7436 |
Wordfence | |
| 6.5 Medium | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Broken Access Control for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion |
≤ 3.7.23 |
CVE-2026-5060 |
Wordfence | |
| 9.8 Critical | Cost Calculator Builder PRO | Remote Code Execution Unauthenticated Remote Code Execution via 'orderDetails' Parameter No login needed |
≤ 4.0.3 |
CVE-2026-14900 |
Wordfence | |
| 5.3 Medium | Klubraum Membership Request | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update No login needed |
≤ 1.1.0 |
CVE-2026-4604 |
Wordfence | |
| 7.2 High | GTM4WP | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields No login needed |
≤ 1.22.3 |
CVE-2026-16597 |
Wordfence | |
| 9.8 Critical | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | Broken Access Control Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation No login needed |
≤ 2.4.37 |
CVE-2025-10656 |
Wordfence | |
| 4.9 Medium | WP-Lister Lite for eBay | SQL Injection Authenticated (Shop Manager+) SQL Injection via 'orderby' Parameter |
≤ 3.8.8 |
CVE-2026-11973 |
Wordfence | |
| 4.3 Medium | Facturación Electrónica Costa Rica | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 2.0.2 |
CVE-2026-9720 |
Wordfence | |
| 7.2 High | Database for CF7 | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Array Form Field Values No login needed |
≤ 1.2.6 |
CVE-2026-13425 |
Wordfence | |
| 6.4 Medium | Link Library | Cross-Site Scripting Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Libra… No login needed |
< 7.9.4 Fixed in 7.9.4 |
CVE-2026-18197 |
tenable | |
| 8.1 High | miniOrange Social Login and Register | Privilege Escalation Unauthenticated Account Takeover No login needed |
< 7.8.0 Fixed in 7.8.0 |
CVE-2026-14300 |
WPScan | |
| 7.1 High | WOLF - WordPress Posts Bulk Editor and Manager | Cross-Site Scripting WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF No login needed |
< 1.1.0 Fixed in 1.1.0 |
CVE-2026-14234 |
WPScan | |
| 5.4 Medium | Easy Appointments | Broken Access Control Subscriber+ Cross-User Appointment Data Modification via IDOR |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14224 |
WPScan | |
| 5.3 Medium | PayU CommercePro | Broken Access Control Unauthenticated Order Tampering No login needed |
< 3.9.0 Fixed in 3.9.0 |
CVE-2026-13692 |
WPScan | |
| 7.4 High | UsersWP | Authentication Bypass Two-Factor Authentication Bypass No login needed |
< 1.2.67 Fixed in 1.2.67 |
CVE-2026-13690 |
WPScan | |
| 6.8 Medium | Photo Swipe | Cross-Site Scripting Author+ Stored XSS via title Attribute |
≤ 4.1.1.1 |
CVE-2026-13605 |
WPScan | |
| 9.8 Critical | Streamit | Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary Function Call No login needed |
≤ 4.5.0 |
CVE-2026-13423 |
WPScan | |
| 8.6 High | Media folder Addon | Path Traversal Unauthenticated Arbitrary File Download No login needed |
< 4.1.7 Fixed in 4.1.7 |
CVE-2026-11974 |
WPScan | |
| 5.3 Medium | ShinyStat Analytics | Information Disclosure Unauthenticated Non-Published Product Information Disclosure No login needed |
1.0.12 – < 1.0.17 Fixed in 1.0.17 |
CVE-2026-11351 |
WPScan | |
| 9.8 Critical | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … | Authentication Bypass Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter No login needed |
10.8.7 |
CVE-2026-18072 |
Wordfence | |
| 4.9 Medium | WP Photo Album Plus | SQL Injection Authenticated (Administrator+) SQL Injection via 'table' Parameter |
≤ 9.2.04.002 |
CVE-2026-15344 |
Wordfence | |
| 4.3 Medium | Survey Form Block | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export |
≤ 1.0.1 |
CVE-2026-5626 |
Wordfence | |
| 7.2 High | Easy Digital Downloads | Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter |
≤ 3.6.9 |
CVE-2026-12476 |
Wordfence | |
| 6.4 Medium | WowStore | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attribute |
≤ 4.4.24 |
CVE-2026-17162 |
Wordfence | |
| 6.4 Medium | WowStore | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attribute |
≤ 4.4.24 |
CVE-2026-17161 |
Wordfence | |
| 4.3 Medium | Event Booking Manager for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action |
≤ 5.3.7 |
CVE-2026-17166 |
Wordfence | |
| 6.4 Medium | Newsletters | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute |
≤ 4.15 |
CVE-2026-12939 |
Wordfence | |
| 8.8 High | Wholesale for WooCommerce | Privilege Escalation Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter |
≤ 2.0.5 |
CVE-2026-12144 |
Wordfence | |
| 6.4 Medium | Contact Form to Any API | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta |
≤ 3.0.6 |
CVE-2026-15735 |
Wordfence | |
| 6.4 Medium | Newsletters | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute |
≤ 4.15 |
CVE-2026-12938 |
Wordfence | |
| 4.9 Medium | SpeedyCache | Path Traversal Authenticated (Administrator+) Arbitrary File Read |
≤ 1.3.8 |
CVE-2026-5114 |
Wordfence | |
| 4.1 Medium | Media Cleaner: Clean your WordPress! | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 7.0.3 |
CVE-2026-4912 |
Wordfence | |
| 8.8 High | WP Password Policy | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation |
≤ 3.7.1 |
CVE-2026-15992 |
Wordfence | |
| 6.5 Medium | Plugin Organizer | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 10.2.4 |
CVE-2026-15304 |
Wordfence | |
| 6.4 Medium | Cozy Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute |
≤ 2.2.11 |
CVE-2026-15393 |
Wordfence | |
| 6.4 Medium | Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions | Cross-Site Scripting Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.8.1 |
CVE-2026-15016 |
Wordfence | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-13110 |
Wordfence | |
| 4.9 Medium | Tutor LMS | SQL Injection Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter |
≤ 4.0.1 |
CVE-2026-15444 |
Wordfence | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-15411 |
Wordfence | |
| 5.3 Medium | WPBot | Information Disclosure Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action No login needed |
≤ 8.5.9 |
CVE-2026-16773 |
Wordfence | |
| 7.2 High | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter No login needed |
≤ 2.1.0 |
CVE-2026-13440 |
Wordfence | |
| 5.3 Medium | WPBot | Broken Access Control Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action No login needed |
≤ 8.5.9 |
CVE-2026-16774 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.