WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,151–3,200 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 64 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Post Blocks & Tools Plugin bnm-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'sliderStyle' Block Attribute ≤ 1.3.0 CVE-2026-5711 Wordfence
6.4 Medium Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'elevation-track' Shortcode ≤ 4.14 CVE-2026-5451 Wordfence
4.3 Medium Advanced CF7 DB Plugin advanced-cf7-db Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Submissions Excel Export ≤ 2.0.9 CVE-2026-0814 Wordfence
5.4 Medium Advanced CF7 DB Plugin advanced-cf7-db Cross-Site Request Forgery Cross-Site Request Forgery to Form Entry Deletion No login needed ≤ 2.0.9 CVE-2026-0811 Wordfence
6.4 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 2.0.8 CVE-2026-2509 Wordfence
6.4 Medium Beaver Builder Page Builder – Drag and Drop Website Builder Plugin beaver-builder-lite-version Cross-Site Scripting Drag and Drop Website Builder <= 2.10.1.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'settings[js]' ≤ 2.10.1.1 CVE-2026-2481 Wordfence
6.5 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification No login needed ≤ 1.1.5 CVE-2026-1672 Wordfence
4.3 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Taxonomy Term Deletion No login needed ≤ 1.1.5 CVE-2026-1673 Wordfence
6.5 Medium User Registration & Membership Plugin user-registration SQL Injection Authenticated (Subscriber+) SQL Injection via membership_ids[] ≤ 5.1.2 CVE-2026-1865 Wordfence
6.4 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Loading Label' Setting ≤ 5.1.3 CVE-2026-4300 Wordfence
6.4 Medium WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'height' Shortcode Attribute ≤ 8.4 CVE-2026-4303 Wordfence
6.4 Medium PrivateContent Free Plugin privatecontent-free Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Shortcode Attribute ≤ 1.2.0 CVE-2026-4025 Wordfence
6.4 Medium pdfl.io Plugin pdfl-io Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Shortcode Attribute ≤ 1.0.5 CVE-2026-4073 Wordfence
5.3 Medium Flipmart Theme flipmart Broken Access Control No login needed ≤ 2.8 CVE-2026-39716 Patchstack
5.3 Medium AnyTrack Affiliate Link Manager Plugin anytrack-affiliate-link-manager Broken Access Control No login needed ≤ 1.5.5 CVE-2026-39715 Patchstack
5.3 Medium G5Plus April Theme g5plus-april Broken Access Control No login needed ≤ 6.8 CVE-2026-39714 Patchstack
5.3 Medium Mailercloud – Integrate webforms and synchronize website contacts Plugin mailercloud-integrate-webforms-synchronize-contacts Broken Access Control Integrate webforms and synchronize website contacts plugin <= 1.0.7 - Broken Access Control No login needed ≤ 1.0.7 CVE-2026-39713 Patchstack
5.3 Medium tagDiv Composer Plugin td-composer Arbitrary Shortcode Execution No login needed ≤ 5.4.3 CVE-2026-39712 Patchstack
5.3 Medium RT-Theme 18 | Extensions Plugin rt18-extensions Information Disclosure Sensitive Data Exposure No login needed ≤ 2.5 CVE-2026-39711 Patchstack
5.4 Medium RT-Theme 18 | Extensions Plugin rt18-extensions Cross-Site Request Forgery No login needed ≤ 2.5 CVE-2026-39710 Patchstack
5.3 Medium The Tribal Plugin the-tech-tribe Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.4 CVE-2026-39709 Patchstack
6.5 Medium UiCore Elements Plugin uicore-elements Cross-Site Scripting ≤ 1.3.17 Fixed in 1.3.18 CVE-2026-39708 Patchstack
5.3 Medium Accept PayPal Payments using Contact Form 7 Plugin contact-form-7-paypal-extension Broken Access Control No login needed ≤ 4.0.4 CVE-2026-39707 Patchstack
5.3 Medium Make My Trivia Plugin trivialy Broken Access Control No login needed ≤ 1.1.0 CVE-2026-39706 Patchstack
5.3 Medium MIPL WC Multisite Sync Plugin mipl-wc-multisite-sync Broken Access Control No login needed ≤ 1.4.4 CVE-2026-39705 Patchstack
5.3 Medium Precious Metals Automated Product Pricing – Pro Plugin precious-metals-automated-product-pricing-pro Broken Access Control Pro plugin <= 4.0.5 - Broken Access Control No login needed ≤ 4.0.5 CVE-2026-39704 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.8.1 CVE-2026-39703 Patchstack
6.5 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Cross-Site Scripting ≤ 2.6.1 CVE-2026-39702 Patchstack
5.3 Medium ShopWP Plugin wpshopify Broken Access Control No login needed ≤ 5.2.4 CVE-2026-39701 Patchstack
5.3 Medium WowOptin Plugin optin Broken Access Control No login needed ≤ 1.4.32 CVE-2026-39700 Patchstack
5.3 Medium AI Workflow Automation Plugin ai-workflow-automation-lite Broken Access Control No login needed ≤ 1.4.2 CVE-2026-39699 Patchstack
5.3 Medium The Publisher Desk ads.txt Plugin the-publisher-desk-ads-txt Broken Access Control No login needed ≤ 1.5.0 CVE-2026-39698 Patchstack
5.3 Medium MAIO – The new AI GEO / SEO tool Plugin maio-the-new-ai-geo-seo-tool Broken Access Control The new AI GEO / SEO tool plugin <= 6.2.8 - Broken Access Control No login needed ≤ 6.2.8 CVE-2026-39697 Patchstack
6.5 Medium Elfsight WhatsApp Chat CC Plugin elfsight-whatsapp-chat Cross-Site Scripting ≤ 1.2.0 CVE-2026-39696 Patchstack
5.4 Medium Podigee Plugin podigee Server-Side Request Forgery No login needed ≤ 1.4.0 CVE-2026-39695 Patchstack
5.3 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Broken Access Control No login needed ≤ 1.6.10.2 CVE-2026-39694 Patchstack
5.9 Medium FSM Custom Featured Image Caption Plugin fsm-custom-featured-image-caption Cross-Site Scripting ≤ 1.25.1 CVE-2026-39693 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.3 CVE-2026-39692 Patchstack
5.3 Medium Cryptocurrency Donation Box – Bitcoin & Crypto Donations Plugin cryptocurrency-donation-box Broken Access Control Bitcoin & Crypto Donations plugin <= 2.2.13 - Broken Access Control No login needed ≤ 2.2.13 CVE-2026-39691 Patchstack
5.3 Medium Author Avatars List/Block Plugin author-avatars Broken Access Control No login needed ≤ 2.1.25 CVE-2026-39690 Patchstack
5.3 Medium eShipper Commerce Plugin eshipper-commerce Broken Access Control No login needed ≤ 2.16.12 CVE-2026-39689 Patchstack
5.3 Medium WP Frontend Profile Plugin wp-front-end-profile Broken Access Control No login needed ≤ 1.3.9 CVE-2026-39688 Patchstack
5.3 Medium Rapid Car Check Vehicle Data Plugin free-vehicle-data-uk Broken Access Control No login needed ≤ 2.0 CVE-2026-39687 Patchstack
5.3 Medium BSK PDF Manager Plugin bsk-pdf-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.7.2 CVE-2026-39686 Patchstack
5.3 Medium The Moneytizer Plugin the-moneytizer Broken Access Control No login needed ≤ 10.0.10 CVE-2026-39685 Patchstack
5.9 Medium Garden Gnome Package Plugin garden-gnome-package Cross-Site Scripting ≤ 2.4.1 CVE-2026-39683 Patchstack
5.3 Medium linkPizza-Manager Plugin linkpizza-manager Broken Access Control No login needed ≤ 5.5.5 CVE-2026-39682 Patchstack
5.3 Medium Diet Calorie Calculator Plugin diet-calorie-calculator Broken Access Control No login needed ≤ 1.1.1 CVE-2026-39680 Patchstack
5.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control No login needed ≤ 2.9.9.6.5 CVE-2026-39678 Patchstack
5.3 Medium Download Manager Plugin download-manager Broken Access Control No login needed ≤ 3.3.52 Fixed in 3.3.53 CVE-2026-39676 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only