WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,151–3,200 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 64 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Chat On Desk Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset OTP Bypass No login needed < 1.0.9 Fixed in 1.0.9 CVE-2026-14309 WPScan
3.8 Low Fluent Support Plugin fluent-support Broken Access Control Agent+ Arbitrary Ticket Customer Reassignment via IDOR < 2.3.1 Fixed in 2.3.1 CVE-2026-14197 WPScan
5.3 Medium Direct Payments for WooCommerce Plugin direct-payments-for-woocommerce Broken Access Control Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions No login needed < 2.5.3 Fixed in 2.5.3 CVE-2026-12966 WPScan
4.8 Medium Bit Form Plugin bit-form Cross-Site Scripting Admin+ Stored XSS via Conversational Form Progress Label < 3.1.4 Fixed in 3.1.4 CVE-2025-15669 WPScan
5.3 Medium Support Genix Lite Plugin Path Traversal Unauthenticated Arbitrary File Read via Path Traversal No login needed < 1.4.48 Fixed in 1.4.48 CVE-2026-15932 WPScan
9.1 Critical FormGent Plugin formgent Broken Access Control FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter No login needed ≤ 1.9.2 CVE-2026-3141 Wordfence
4.9 Medium Pinpoint Booking System Plugin booking-system SQL Injection Authenticated (Administrator+) SQL Injection via 'field' Parameter ≤ 2.9.9.6.9 CVE-2026-15403 Wordfence
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Privilege Escalation Authenticated (Contributor+) Privilege Escalation via '_wps_plan_user_role' Membership Plan Meta ≤ 2.0.0 CVE-2026-15414 Wordfence
7.5 High Bit integrations Plugin bit-integrations Path Traversal Unauthenticated Arbitrary File Read via Optional CF7 File Field No login needed ≤ 2.9.0 CVE-2026-15006 Wordfence
6.4 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _sp_form_code Post Meta ≤ 2.2.5 CVE-2026-13362 Wordfence
6.4 Medium SureForms Plugin sureforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'headingWrapper' Block Attribute ≤ 2.8.1 CVE-2026-7623 Wordfence
4.3 Medium WP Maps Plugin wp-google-map-plugin Information Disclosure Sensitive Data Exposure ≤ 4.9.6 Fixed in 4.9.7 CVE-2026-28144 Patchstack
5.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control No login needed ≤ 3.7.39 Fixed in 3.7.40 CVE-2026-28145 Patchstack
5.3 Medium Fluent Forms Plugin fluentform Information Disclosure Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter No login needed ≤ 6.2.8 CVE-2026-17567 Wordfence
5.3 Medium MailPress Plugin mailerpress Broken Access Control Missing Authorization to Unauthenticated Contact Updates No login needed ≤ 1.5.0 CVE-2026-18437 Wordfence
5.3 Medium MailerPress Plugin mailerpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint No login needed ≤ 1.5.0 CVE-2026-18436 Wordfence
9.8 Critical ShopMonitor.io Plugin shopmonitorio Privilege Escalation Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute No login needed < 1.2.0 Fixed in 1.2.0 CVE-2026-14919 WPScan
3.7 Low Support Genix Lite Plugin Broken Access Control Unauthenticated Ticket Attachment Download via Missing Authorization No login needed < 1.4.48 Fixed in 1.4.48 CVE-2026-14862 WPScan
8.8 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Field No login needed < 3.29.9 Fixed in 3.29.9 CVE-2026-13609 WPScan
3.5 Low ElementsKit Lite Plugin Cross-Site Scripting Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13393 WPScan
5.4 Medium wpForo Forum Plugin wpforo Broken Access Control Subscriber+ Cross-User AI Chat Message Deletion via IDOR < 3.1.2 Fixed in 3.1.2 CVE-2026-12697 WPScan
8.1 High miniOrange 2FA Plugin miniorange-2-factor-authentication Authentication Bypass miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret No login needed < 6.2.6 Fixed in 6.2.6 CVE-2026-12695 WPScan
4.3 Medium Academy LMS Plugin academy Information Disclosure Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint ≤ 3.8.2 CVE-2026-12376 WPScan
7.2 High ElementsKit Lite Plugin Remote Code Execution Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite) < 3.10.01 Fixed in 3.10.01 CVE-2026-13392 WPScan
8.6 High Kirki Plugin kirki SQL Injection Unauthenticated SQL Injection No login needed < 6.0.13 Fixed in 6.0.13 CVE-2026-12721 WPScan
7.5 High Kirki Plugin kirki PHP Object Injection Unauthenticated PHP Object Injection No login needed < 6.0.13 Fixed in 6.0.13 CVE-2026-12720 WPScan
8.1 High Ultimate Member Plugin ultimate-member Privilege Escalation Unauthenticated Privilege Escalation via Role Selection Field No login needed < 2.12.1 Fixed in 2.12.1 CVE-2026-12251 WPScan
5.4 Medium BuddyPress Plugin buddypress Information Disclosure Subscriber+ Private Messages Disclosure via IDOR < 14.5.0 Fixed in 14.5.0 CVE-2026-8155 WPScan
3.7 Low WP Go Maps Plugin wp-google-maps SQL Injection Unauthenticated SQL Injection via Markers REST filter No login needed < 10.1.04 Fixed in 10.1.04 CVE-2026-15381 WPScan
8.1 High Product Feed Manager for WooCommerce Plugin webappick-product-feed-for-woocommerce SQL Injection Contributor+ SQL Injection via Feed Filter < 7.6.1 Fixed in 7.6.1 CVE-2026-15258 WPScan
6.5 Medium JS Help Desk – AI-Powered Support & Ticketing System Plugin js-support-ticket Information Disclosure AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR < 3.1.5 Fixed in 3.1.5 CVE-2026-15209 WPScan
7.5 High GeekyBot Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via Chat History No login needed < 1.2.8 Fixed in 1.2.8 CVE-2026-15048 WPScan
6.5 Medium JS Help Desk Plugin js-support-ticket Information Disclosure Contributor+ User Email Disclosure < 3.1.4 Fixed in 3.1.4 CVE-2026-14931 WPScan
7.5 High JS Help Desk Plugin js-support-ticket Broken Access Control Unauthenticated Arbitrary Ticket File Attachment Upload No login needed < 3.1.4 Fixed in 3.1.4 CVE-2026-14930 WPScan
4.3 Medium JS Help Desk Plugin js-support-ticket Broken Access Control Subscriber+ Ticket Reply Modification via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-14929 WPScan
6.5 Medium JS Help Desk Plugin js-support-ticket Information Disclosure Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject < 3.1.4 Fixed in 3.1.4 CVE-2026-14928 WPScan
3.7 Low FluentCart Plugin Information Disclosure Unauthenticated Order PII Disclosure via Print Routes No login needed < 1.5.3 Fixed in 1.5.3 CVE-2026-14927 WPScan
6.1 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS via ult_buttons Shortcode No login needed < 3.21.5 Fixed in 3.21.5 CVE-2026-14921 WPScan
3.7 Low Paid Member Subscriptions Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via Residual Export Files No login needed < 3.0.7 Fixed in 3.0.7 CVE-2026-14849 WPScan
4.3 Medium Paid Member Subscriptions Plugin Information Disclosure Subscriber+ Payment Data Disclosure via IDOR < 3.0.7 Fixed in 3.0.7 CVE-2026-14847 WPScan
6.1 Medium NewStatPress Plugin Cross-Site Scripting Unauthenticated Stored XSS via Top Post Widget No login needed < 1.4.5 Fixed in 1.4.5 CVE-2026-14845 WPScan
5.3 Medium Events Made Easy Plugin events-made-easy Broken Access Control Unauthenticated Person Data Modification via IDOR No login needed < 3.1.4 Fixed in 3.1.4 CVE-2026-14843 WPScan
6.5 Medium Mailgun Plugin mailgun Broken Access Control Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-14834 WPScan
6.8 Medium Lightbox with PhotoSwipe Plugin lightbox-photoswipe Cross-Site Scripting Author+ Stored XSS via data-lbwps-caption Attribute < 5.9.0 Fixed in 5.9.0 CVE-2026-14833 WPScan
7.5 High FlxWoo Plugin flx-woo Price Manipulation Unauthenticated Payment Bypass No login needed < 3.1.1 Fixed in 3.1.1 CVE-2026-14830 WPScan
6.5 Medium Check & Log Email Plugin check-email SQL Injection Admin+ SQL Injection via d and s Parameters < 2.0.15 Fixed in 2.0.15 CVE-2026-14554 WPScan
7.5 High Demi - One Click Demo Import, Backup & Site Migration Plugin Information Disclosure One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory No login needed < 0.0.7 Fixed in 0.0.7 CVE-2026-14333 WPScan
7.5 High GiveWP Plugin give Information Disclosure Unauthenticated Recurring Donor Information Disclosure No login needed < 4.16.3 Fixed in 4.16.3 CVE-2026-14319 WPScan
5.3 Medium GiveWP Plugin give Broken Access Control Unauthenticated Payment Gateway Restriction Bypass No login needed < 4.16.3 Fixed in 4.16.3 CVE-2026-14317 WPScan
8.8 High Realtyna Organic IDX plugin + WPL Real Estate Plugin real-estate-listing-realtyna-wpl Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 5.3.0 CVE-2026-16236 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only