WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,301–3,350 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 67 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WP Fast Total Search Plugin fulltext-search SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.80.280 CVE-2026-12741 Wordfence
6.4 Medium GamiPress Plugin gamipress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute ≤ 7.9.9.1 CVE-2026-15730 Wordfence
4.4 Medium SMS Alert Plugin sms-alert SQL Injection Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings ≤ 3.9.7 CVE-2026-15673 Wordfence
4.9 Medium SMS Alert Plugin sms-alert SQL Injection Authenticated (Administrator+) SQL Injection via 'id' Parameter ≤ 3.9.7 CVE-2026-15671 Wordfence
4.9 Medium SMS Alert Plugin sms-alert SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 3.9.7 CVE-2026-15670 Wordfence
9.8 Critical SMS Alert Plugin sms-alert Authentication Bypass Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter No login needed ≤ 3.9.7 CVE-2026-15014 Wordfence
4.2 Medium FluentCart Plugin Broken Access Control Subscriber+ Subscription Payment-Method Tampering via IDOR < 1.4.0 Fixed in 1.4.0 CVE-2026-14926 WPScan
7.5 High Tablesome Plugin Broken Access Control Unauthenticated Post Creation and Modification No login needed < 1.1.31 Fixed in 1.1.31 CVE-2026-14924 WPScan
7.1 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Cross-Site Scripting Reflected XSS via form_id No login needed < 1.5.3 Fixed in 1.5.3 CVE-2026-14870 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Template Deletion < 11.1.5 Fixed in 11.1.5 CVE-2026-14821 WPScan
3.5 Low Event Tickets Plugin Cross-Site Scripting Editor+ Stored XSS via Ticket Move < 5.28.4 Fixed in 5.28.4 CVE-2026-14819 WPScan
9.8 Critical TrueBooker Appointment Booking Plugin Privilege Escalation Unauthenticated Account Takeover via Password Reset No login needed < 1.2.4 Fixed in 1.2.4 CVE-2026-14545 WPScan
4.9 Medium ShopLentor Plugin woolentor-addons SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 3.4.5 CVE-2026-16811 Wordfence
4.3 Medium Advanced Form Integration Plugin advanced-form-integration Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function ≤ 2.6.0 CVE-2026-16587 Wordfence
7.2 High Better Messages Plugin bp-better-messages Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal via 'file' Parameter ≤ 2.15.19 CVE-2026-16585 Wordfence
4.3 Medium ShopLentor Plugin woolentor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter ≤ 3.4.5 CVE-2026-16797 Wordfence
4.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed ≤ 4.3.7 CVE-2026-15136 Wordfence
5.3 Medium Demi Plugin demi-backup-migration Information Disclosure Unauthenticated Information Exposure to Arbitrary Directory Copy No login needed ≤ 0.0.8 CVE-2026-15012 Wordfence
7.5 High Demi Plugin demi-backup-migration Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action No login needed ≤ 0.0.7 CVE-2026-14490 Wordfence
5.3 Medium PDFDraft Plugin pdfdraft Broken Access Control Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter No login needed ≤ 1.1.0 CVE-2026-12124 Wordfence
6.5 Medium Chaty Pro Plugin chaty-pro SQL Injection Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter ≤ 3.5.5 CVE-2026-6251 Wordfence
6.5 Medium Anti Spam and list cleaner – AcyChecker Plugin acychecker Cross-Site Scripting AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) ≤ 1.8.1 Fixed in 2.0.0 CVE-2026-65448 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 30.0.6 Fixed in 30.0.7 CVE-2026-65447 Patchstack
7.1 High Kali Forms Plugin kali-forms Cross-Site Scripting No login needed ≤ 2.4.18 Fixed in 2.4.19 CVE-2026-65446 Patchstack
6.5 Medium Ad Invalid Click Protector (AICP) Plugin ad-invalid-click-protector Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-65445 Patchstack
7.1 High BackWPup Plugin backwpup Cross-Site Scripting No login needed ≤ 5.7.4 Fixed in 5.7.5 CVE-2026-65443 Patchstack
7.2 High FormCraft Plugin formcraft Server-Side Request Forgery No login needed ≤ 3.9.15 Fixed in 3.9.16 CVE-2026-65442 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting No login needed ≤ 4.16.3 Fixed in 4.16.4 CVE-2026-65441 Patchstack
7.1 High GetGenie Plugin getgenie Cross-Site Scripting No login needed ≤ 4.4.3 Fixed in 4.5.0 CVE-2026-65440 Patchstack
7.1 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting No login needed ≤ 3.5.45 Fixed in 3.5.46 CVE-2026-65439 Patchstack
7.1 High Message Filter for Contact Form 7 Plugin cf7-message-filter Cross-Site Scripting No login needed ≤ 1.6.3.9 Fixed in 1.6.4.0 CVE-2026-65438 Patchstack
7.1 High Spam protection, AntiSpam, FireWall by CleanTalk Plugin cleantalk-spam-protect Cross-Site Scripting No login needed ≤ 6.82 Fixed in 6.83 CVE-2026-65437 Patchstack
7.1 High miniorange otp verification Plugin miniorange-otp-verification Cross-Site Scripting No login needed ≤ 5.5.1 Fixed in 5.5.2 CVE-2026-61957 Patchstack
7.2 High Simple Link Directory Pro Plugin simple-link-directory-pro Server-Side Request Forgery No login needed ≤ 15.0.6 Fixed in 15.0.7 CVE-2026-61953 Patchstack
7.5 High Xendit Payment Plugin woo-xendit-virtual-accounts Broken Access Control No login needed ≤ 7.1.0 CVE-2026-66473 Patchstack
5.3 Medium Gillion Theme gillion Broken Access Control No login needed ≤ 4.13 Fixed in 4.14 CVE-2026-66477 Patchstack
4.9 Medium Easy Digital Downloads Plugin easy-digital-downloads Arbitrary File Deletion ≤ 3.6.9 CVE-2026-66476 Patchstack
5.9 Medium Checkout Field Editor for WooCommerce – Checkout Manager Plugin checkout-field-editor-and-manager-for-woocommerce Cross-Site Scripting Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) ≤ 3.0.5 CVE-2026-66475 Patchstack
4.3 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Request Forgery HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2026-66474 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-66448 Patchstack
6.5 Medium Open User Map Plugin open-user-map Cross-Site Scripting ≤ 1.4.46 Fixed in 1.4.47 CVE-2026-66445 Patchstack
5.4 Medium YayPricing Plugin yaypricing Broken Access Control ≤ 3.5.6 Fixed in 3.5.7 CVE-2026-66442 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-66438 Patchstack
4.9 Medium Feedzy Plugin feedzy-rss-feeds Server-Side Request Forgery ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-66437 Patchstack
6.5 Medium Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting ≤ 3.33 Fixed in 3.34 CVE-2026-66434 Patchstack
6.5 Medium Location Weather Plugin location-weather Cross-Site Scripting ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-66433 Patchstack
4.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery No login needed ≤ 18.4 Fixed in 18.5 CVE-2026-66428 Patchstack
7.6 High WP Google Review Slider Plugin wp-google-places-review-slider SQL Injection ≤ 18.4 Fixed in 18.5 CVE-2026-66427 Patchstack
5.0 Medium Visual Composer Website Builder Plugin visualcomposer Broken Access Control ≤ 45.15.0 Fixed in 45.16.0 CVE-2026-65568 Patchstack
5.3 Medium Event Tickets Plugin event-tickets Broken Access Control No login needed ≤ 5.29.0.1 Fixed in 5.29.1 CVE-2026-65567 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only