WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 3,251–3,300 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Broken Access Control for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion |
≤ 3.7.23 |
CVE-2026-5060 |
Wordfence | |
| 9.8 Critical | Cost Calculator Builder PRO | Remote Code Execution Unauthenticated Remote Code Execution via 'orderDetails' Parameter No login needed |
≤ 4.0.3 |
CVE-2026-14900 |
Wordfence | |
| 5.3 Medium | Klubraum Membership Request | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update No login needed |
≤ 1.1.0 |
CVE-2026-4604 |
Wordfence | |
| 7.2 High | GTM4WP | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields No login needed |
≤ 1.22.3 |
CVE-2026-16597 |
Wordfence | |
| 9.8 Critical | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | Broken Access Control Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation No login needed |
≤ 2.4.37 |
CVE-2025-10656 |
Wordfence | |
| 4.9 Medium | WP-Lister Lite for eBay | SQL Injection Authenticated (Shop Manager+) SQL Injection via 'orderby' Parameter |
≤ 3.8.8 |
CVE-2026-11973 |
Wordfence | |
| 4.3 Medium | Facturación Electrónica Costa Rica | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 2.0.2 |
CVE-2026-9720 |
Wordfence | |
| 7.2 High | Database for CF7 | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Array Form Field Values No login needed |
≤ 1.2.6 |
CVE-2026-13425 |
Wordfence | |
| 6.4 Medium | Link Library | Cross-Site Scripting Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Libra… No login needed |
< 7.9.4 Fixed in 7.9.4 |
CVE-2026-18197 |
tenable | |
| 8.1 High | miniOrange Social Login and Register | Privilege Escalation Unauthenticated Account Takeover No login needed |
< 7.8.0 Fixed in 7.8.0 |
CVE-2026-14300 |
WPScan | |
| 7.1 High | WOLF - WordPress Posts Bulk Editor and Manager | Cross-Site Scripting WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF No login needed |
< 1.1.0 Fixed in 1.1.0 |
CVE-2026-14234 |
WPScan | |
| 5.4 Medium | Easy Appointments | Broken Access Control Subscriber+ Cross-User Appointment Data Modification via IDOR |
< 3.12.28 Fixed in 3.12.28 |
CVE-2026-14224 |
WPScan | |
| 5.3 Medium | PayU CommercePro | Broken Access Control Unauthenticated Order Tampering No login needed |
< 3.9.0 Fixed in 3.9.0 |
CVE-2026-13692 |
WPScan | |
| 7.4 High | UsersWP | Authentication Bypass Two-Factor Authentication Bypass No login needed |
< 1.2.67 Fixed in 1.2.67 |
CVE-2026-13690 |
WPScan | |
| 6.8 Medium | Photo Swipe | Cross-Site Scripting Author+ Stored XSS via title Attribute |
≤ 4.1.1.1 |
CVE-2026-13605 |
WPScan | |
| 9.8 Critical | Streamit | Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary Function Call No login needed |
≤ 4.5.0 |
CVE-2026-13423 |
WPScan | |
| 8.6 High | Media folder Addon | Path Traversal Unauthenticated Arbitrary File Download No login needed |
< 4.1.7 Fixed in 4.1.7 |
CVE-2026-11974 |
WPScan | |
| 5.3 Medium | ShinyStat Analytics | Information Disclosure Unauthenticated Non-Published Product Information Disclosure No login needed |
1.0.12 – < 1.0.17 Fixed in 1.0.17 |
CVE-2026-11351 |
WPScan | |
| 9.8 Critical | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … | Authentication Bypass Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter No login needed |
10.8.7 |
CVE-2026-18072 |
Wordfence | |
| 4.9 Medium | WP Photo Album Plus | SQL Injection Authenticated (Administrator+) SQL Injection via 'table' Parameter |
≤ 9.2.04.002 |
CVE-2026-15344 |
Wordfence | |
| 4.3 Medium | Survey Form Block | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export |
≤ 1.0.1 |
CVE-2026-5626 |
Wordfence | |
| 7.2 High | Easy Digital Downloads | Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter |
≤ 3.6.9 |
CVE-2026-12476 |
Wordfence | |
| 6.4 Medium | WowStore | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attribute |
≤ 4.4.24 |
CVE-2026-17162 |
Wordfence | |
| 6.4 Medium | WowStore | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attribute |
≤ 4.4.24 |
CVE-2026-17161 |
Wordfence | |
| 4.3 Medium | Event Booking Manager for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action |
≤ 5.3.7 |
CVE-2026-17166 |
Wordfence | |
| 6.4 Medium | Newsletters | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute |
≤ 4.15 |
CVE-2026-12939 |
Wordfence | |
| 8.8 High | Wholesale for WooCommerce | Privilege Escalation Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter |
≤ 2.0.5 |
CVE-2026-12144 |
Wordfence | |
| 6.4 Medium | Contact Form to Any API | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta |
≤ 3.0.6 |
CVE-2026-15735 |
Wordfence | |
| 6.4 Medium | Newsletters | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute |
≤ 4.15 |
CVE-2026-12938 |
Wordfence | |
| 4.9 Medium | SpeedyCache | Path Traversal Authenticated (Administrator+) Arbitrary File Read |
≤ 1.3.8 |
CVE-2026-5114 |
Wordfence | |
| 4.1 Medium | Media Cleaner: Clean your WordPress! | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 7.0.3 |
CVE-2026-4912 |
Wordfence | |
| 8.8 High | WP Password Policy | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation |
≤ 3.7.1 |
CVE-2026-15992 |
Wordfence | |
| 6.5 Medium | Plugin Organizer | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 10.2.4 |
CVE-2026-15304 |
Wordfence | |
| 6.4 Medium | Cozy Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute |
≤ 2.2.11 |
CVE-2026-15393 |
Wordfence | |
| 6.4 Medium | Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions | Cross-Site Scripting Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.8.1 |
CVE-2026-15016 |
Wordfence | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-13110 |
Wordfence | |
| 4.9 Medium | Tutor LMS | SQL Injection Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter |
≤ 4.0.1 |
CVE-2026-15444 |
Wordfence | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-15411 |
Wordfence | |
| 5.3 Medium | WPBot | Information Disclosure Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action No login needed |
≤ 8.5.9 |
CVE-2026-16773 |
Wordfence | |
| 7.2 High | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter No login needed |
≤ 2.1.0 |
CVE-2026-13440 |
Wordfence | |
| 5.3 Medium | WPBot | Broken Access Control Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action No login needed |
≤ 8.5.9 |
CVE-2026-16774 |
Wordfence | |
| 7.5 High | Uncanny Automator | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints No login needed |
≤ 7.3.2 |
CVE-2026-15025 |
Wordfence | |
| 7.5 High | Web Directory Free | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.7.13 |
CVE-2026-14785 |
Wordfence | |
| 5.0 Medium | Shortcodify | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute |
≤ 1.4.3 |
CVE-2026-11598 |
Wordfence | |
| 8.8 High | Eazy Plugin Manager | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint |
≤ 4.4.1 |
CVE-2026-14328 |
Wordfence | |
| 7.5 High | PickPlugins Question Answer | SQL Injection Unauthenticated SQL Injection via 'id' Parameter No login needed |
≤ 1.2.73 |
CVE-2026-10207 |
Wordfence | |
| 6.5 Medium | Taskbuilder | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 5.0.9 |
CVE-2026-15267 |
Wordfence | |
| 7.5 High | TrueBooker | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.2.2 |
CVE-2026-13161 |
Wordfence | |
| 7.5 High | Premium Packages | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.2.0 |
CVE-2026-12800 |
Wordfence | |
| 7.5 High | Online Scheduling and Appointment Booking System | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 27.5 |
CVE-2026-14516 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.