WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 3,351–3,400 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | MapPress Maps | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.97.6 Fixed in 2.97.7 |
CVE-2026-65564 |
Patchstack | |
| 5.9 Medium | Orbit Fox by ThemeIsle | Cross-Site Scripting |
≤ 3.0.7 Fixed in 3.0.8 |
CVE-2026-65563 |
Patchstack | |
| 6.5 Medium | BetterDocs | Cross-Site Scripting |
≤ 4.6.2 Fixed in 4.7.0 |
CVE-2026-65562 |
Patchstack | |
| 6.5 Medium | WordPress Social Login and Register | Cross-Site Scripting |
≤ 7.8.0 Fixed in 7.8.1 |
CVE-2026-65561 |
Patchstack | |
| 5.4 Medium | AffiliateX | Server-Side Request Forgery No login needed |
≤ 2.3.5 Fixed in 2.3.6 |
CVE-2026-65558 |
Patchstack | |
| 5.9 Medium | Abandoned Cart Lite for WooCommerce | Cross-Site Scripting |
≤ 6.8.0 Fixed in 6.8.1 |
CVE-2026-65557 |
Patchstack | |
| 6.8 Medium | Kirki | Arbitrary File Deletion |
≤ 6.0.13 Fixed in 6.0.14 |
CVE-2026-65436 |
Patchstack | |
| 6.5 Medium | Thrive Leads Version | Broken Access Control No login needed |
≤ 10.9.2 Fixed in 10.9.2.1 |
CVE-2026-65435 |
Patchstack | |
| 6.5 Medium | ЮKassa для WooCommerce | Information Disclosure Sensitive Data Exposure |
≤ 2.16.1 Fixed in 2.16.2 |
CVE-2026-65434 |
Patchstack | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-65433 |
Patchstack | |
| 6.5 Medium | FundEngine | Broken Access Control |
≤ 1.7.8 Fixed in 1.7.9 |
CVE-2026-59560 |
Patchstack | |
| 6.5 Medium | RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg | Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2026-59559 |
Patchstack | |
| 7.1 High | Booking Calendar | Cross-Site Scripting No login needed |
≤ 11.4.2 Fixed in 11.4.3 |
CVE-2026-59558 |
Patchstack | |
| 6.5 Medium | Events Made Easy | Broken Access Control No login needed |
≤ 3.1.3 Fixed in 3.1.4 |
CVE-2026-59557 |
Patchstack | |
| 7.1 High | Dynamic Pricing With Discount Rules for WooCommerce | Cross-Site Scripting No login needed |
≤ 4.5.11 Fixed in 5.0.0 |
CVE-2026-59556 |
Patchstack | |
| 7.1 High | Product Feed Manager | Cross-Site Scripting No login needed |
≤ 7.6.1 Fixed in 7.6.2 |
CVE-2026-59553 |
Patchstack | |
| 7.2 High | 3D Flipbook PDF Viewer & Embedder | Server-Side Request Forgery No login needed |
≤ 1.4.2 Fixed in 1.4.4 |
CVE-2026-59552 |
Patchstack | |
| 8.5 High | rtMedia for WordPress, BuddyPress and bbPress | SQL Injection |
≤ 4.7.10 Fixed in 4.7.11 |
CVE-2026-59551 |
Patchstack | |
| 9.3 Critical | AWP Classifieds | SQL Injection No login needed |
≤ 4.4.7 Fixed in 4.4.8 |
CVE-2026-59550 |
Patchstack | |
| 9.3 Critical | rtMedia for WordPress, BuddyPress and bbPress | SQL Injection No login needed |
≤ 4.7.10 Fixed in 4.7.11 |
CVE-2026-59549 |
Patchstack | |
| 7.5 High | Byteflows Travel & Hotel Booking | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.0.0 Fixed in 1.0.1 |
CVE-2026-59548 |
Patchstack | |
| 7.4 High | Hide My WP Ghost | Authentication Bypass WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass No login needed |
≤ 7.0.06 Fixed in 7.0.07 |
CVE-2026-59546 |
Patchstack | |
| 7.5 High | Paid Member Subscriptions | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 3.0.7 Fixed in 3.0.8 |
CVE-2026-59539 |
Patchstack | |
| 9.3 Critical | GamiPress | SQL Injection No login needed |
≤ 7.9.7 Fixed in 7.9.8 |
CVE-2026-59538 |
Patchstack | |
| 7.6 High | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | SQL Injection Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.10.22 - SQL Injection |
≤ 2.10.22 Fixed in 2.10.23 |
CVE-2026-59537 |
Patchstack | |
| 7.5 High | CoCart – Headless ecommerce | Broken Access Control Headless ecommerce plugin <= 4.8.4 - Broken Access Control No login needed |
≤ 4.8.4 Fixed in 4.9.0 |
CVE-2026-59536 |
Patchstack | |
| 7.3 High | Thrive Product Manager | Broken Access Control No login needed |
≤ 10.9.2 Fixed in 10.9.2.1 |
CVE-2026-59535 |
Patchstack | |
| 7.5 High | Post My CF7 Form | Broken Access Control No login needed |
≤ 6.2.0 Fixed in 7.0.0 |
CVE-2026-59534 |
Patchstack | |
| 9.3 Critical | Relevanssi Light | SQL Injection No login needed |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2026-59533 |
Patchstack | |
| 7.5 High | Booking and Rental Manager | Price Manipulation No login needed |
≤ 2.7.2 Fixed in 2.7.3 |
CVE-2026-59532 |
Patchstack | |
| 7.5 High | Falcon – WordPress Optimizations & Tweaks | Other WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown No login needed |
≤ 2.10.0 Fixed in 2.10.1 |
CVE-2026-59531 |
Patchstack | |
| 7.5 High | Stripe For WooCommerce | Broken Access Control No login needed |
≤ 4.0.7 Fixed in 4.0.8 |
CVE-2026-59530 |
Patchstack | |
| 7.5 High | Ebook Store | Information Disclosure Sensitive Data Exposure No login needed |
≤ 6.19 Fixed in 6.20 |
CVE-2026-59529 |
Patchstack | |
| 7.5 High | ShipTime: Discounted Shipping Rates | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.1.1 Fixed in 1.1.5 |
CVE-2026-59528 |
Patchstack | |
| 9.3 Critical | MapSVG | SQL Injection No login needed |
≤ 8.14.0 Fixed in 8.14.1 |
CVE-2026-59527 |
Patchstack | |
| 6.8 Medium | Calendar | Cross-Site Scripting Contributor+ Stored XSS via event_link Parameter |
< 1.3.18 Fixed in 1.3.18 |
CVE-2026-14827 |
WPScan | |
| 8.2 High | BookingPress Pro | Information Disclosure Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug No login needed |
< 5.7.3 Fixed in 5.7.3 |
CVE-2026-9830 |
WPScan | |
| 5.3 Medium | Quiz And Survey Master | Information Disclosure Unauthenticated User Enumeration and Password Oracle via Quiz Login No login needed |
< 11.1.3 Fixed in 11.1.3 |
CVE-2026-14820 |
WPScan | |
| 6.5 Medium | WP User Frontend | Authentication Bypass Unauthenticated Author-less Attachment Deletion No login needed |
< 4.3.8 Fixed in 4.3.8 |
CVE-2026-14568 |
WPScan | |
| 9.0 Critical | WP FacturaONE | Remote Code Execution Unauthenticated Remote Code Execution No login needed |
< 5.37 Fixed in 5.37 |
CVE-2026-14289 |
WPScan | |
| 4.7 Medium | Contact Form 7 – PayPal & Stripe Add-on | Open Redirect PayPal & Stripe Add-on < 2.5 - Open Redirect No login needed |
< 2.5 Fixed in 2.5 |
CVE-2026-14236 |
WPScan | |
| 7.5 High | WordPress Download Manager | Broken Access Control Unauthorized Protected File Download via Reusable Download Key No login needed |
< 3.3.62 Fixed in 3.3.62 |
CVE-2026-14235 |
WPScan | |
| 4.8 Medium | Smart Manager | Cross-Site Scripting Contributor+ Stored XSS via Post Title |
< 8.92.0 Fixed in 8.92.0 |
CVE-2026-14203 |
WPScan | |
| 6.1 Medium | Sina Extension for Elementor | Cross-Site Scripting Reflected XSS No login needed |
< 3.10.2 Fixed in 3.10.2 |
CVE-2026-14190 |
WPScan | |
| 3.8 Low | WPBot AI ChatBot | SQL Injection Admin+ Second-Order SQL Injection via qc_bot_str_fields |
< 8.5.2 Fixed in 8.5.2 |
CVE-2026-14189 |
WPScan | |
| 7.1 High | Multiple Page Generator Plugin – MPG | Cross-Site Scripting MPG < 4.1.8 - Reflected XSS via mpg_shortcode No login needed |
< 4.1.8 Fixed in 4.1.8 |
CVE-2026-13726 |
WPScan | |
| 9.8 Critical | Realtyna Organic IDX plugin + WPL Real Estate | Arbitrary File Upload Unauthenticated Arbitrary File Upload to Remote Code Execution No login needed |
< 5.3.0 Fixed in 5.3.0 |
CVE-2026-13714 |
WPScan | |
| 9.1 Critical | QRcode Login for WeChat | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 1.3 |
CVE-2026-13597 |
WPScan | |
| 6.1 Medium | Simply Schedule Appointments | Cross-Site Scripting Unauthenticated Stored XSS via Booking Customer Information No login needed |
< 1.6.12.4 Fixed in 1.6.12.4 |
CVE-2026-13400 |
WPScan | |
| 5.3 Medium | The Events Calendar | Broken Access Control Unauthenticated Event Aggregator Import Status Manipulation No login needed |
< 6.16.5.1 Fixed in 6.16.5.1 |
CVE-2026-13390 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.