WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,351–3,400 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 68 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium MapPress Maps Plugin mappress-google-maps-for-wordpress Information Disclosure Sensitive Data Exposure No login needed ≤ 2.97.6 Fixed in 2.97.7 CVE-2026-65564 Patchstack
5.9 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-65563 Patchstack
6.5 Medium BetterDocs Plugin betterdocs Cross-Site Scripting ≤ 4.6.2 Fixed in 4.7.0 CVE-2026-65562 Patchstack
6.5 Medium WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting ≤ 7.8.0 Fixed in 7.8.1 CVE-2026-65561 Patchstack
5.4 Medium AffiliateX Plugin affiliatex Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2026-65558 Patchstack
5.9 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Scripting ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-65557 Patchstack
6.8 Medium Kirki Plugin kirki Arbitrary File Deletion ≤ 6.0.13 Fixed in 6.0.14 CVE-2026-65436 Patchstack
6.5 Medium Thrive Leads Version Plugin thrive-leads Broken Access Control No login needed ≤ 10.9.2 Fixed in 10.9.2.1 CVE-2026-65435 Patchstack
6.5 Medium ЮKassa для WooCommerce Plugin yookassa Information Disclosure Sensitive Data Exposure ≤ 2.16.1 Fixed in 2.16.2 CVE-2026-65434 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-65433 Patchstack
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control ≤ 1.7.8 Fixed in 1.7.9 CVE-2026-59560 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-59559 Patchstack
7.1 High Booking Calendar Plugin booking Cross-Site Scripting No login needed ≤ 11.4.2 Fixed in 11.4.3 CVE-2026-59558 Patchstack
6.5 Medium Events Made Easy Plugin events-made-easy Broken Access Control No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-59557 Patchstack
7.1 High Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing Cross-Site Scripting No login needed ≤ 4.5.11 Fixed in 5.0.0 CVE-2026-59556 Patchstack
7.1 High Product Feed Manager Plugin best-woocommerce-feed Cross-Site Scripting No login needed ≤ 7.6.1 Fixed in 7.6.2 CVE-2026-59553 Patchstack
7.2 High 3D Flipbook PDF Viewer & Embedder Plugin pdf-embed-viewer Server-Side Request Forgery No login needed ≤ 1.4.2 Fixed in 1.4.4 CVE-2026-59552 Patchstack
8.5 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection ≤ 4.7.10 Fixed in 4.7.11 CVE-2026-59551 Patchstack
9.3 Critical AWP Classifieds Plugin another-wordpress-classifieds-plugin SQL Injection No login needed ≤ 4.4.7 Fixed in 4.4.8 CVE-2026-59550 Patchstack
9.3 Critical rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection No login needed ≤ 4.7.10 Fixed in 4.7.11 CVE-2026-59549 Patchstack
7.5 High Byteflows Travel & Hotel Booking Plugin byteflows-travel-hotel-booking Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.0 Fixed in 1.0.1 CVE-2026-59548 Patchstack
7.4 High Hide My WP Ghost Plugin hide-my-wp Authentication Bypass WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass No login needed ≤ 7.0.06 Fixed in 7.0.07 CVE-2026-59546 Patchstack
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-59539 Patchstack
9.3 Critical GamiPress Plugin gamipress SQL Injection No login needed ≤ 7.9.7 Fixed in 7.9.8 CVE-2026-59538 Patchstack
7.6 High Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails SQL Injection Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.10.22 - SQL Injection ≤ 2.10.22 Fixed in 2.10.23 CVE-2026-59537 Patchstack
7.5 High CoCart – Headless ecommerce Plugin cart-rest-api-for-woocommerce Broken Access Control Headless ecommerce plugin <= 4.8.4 - Broken Access Control No login needed ≤ 4.8.4 Fixed in 4.9.0 CVE-2026-59536 Patchstack
7.3 High Thrive Product Manager Plugin thrive-product-manager Broken Access Control No login needed ≤ 10.9.2 Fixed in 10.9.2.1 CVE-2026-59535 Patchstack
7.5 High Post My CF7 Form Plugin post-my-contact-form-7 Broken Access Control No login needed ≤ 6.2.0 Fixed in 7.0.0 CVE-2026-59534 Patchstack
9.3 Critical Relevanssi Light Plugin relevanssi-light SQL Injection No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2026-59533 Patchstack
7.5 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Price Manipulation No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2026-59532 Patchstack
7.5 High Falcon – WordPress Optimizations & Tweaks Plugin falcon Other WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown No login needed ≤ 2.10.0 Fixed in 2.10.1 CVE-2026-59531 Patchstack
7.5 High Stripe For WooCommerce Plugin woo-stripe-payment Broken Access Control No login needed ≤ 4.0.7 Fixed in 4.0.8 CVE-2026-59530 Patchstack
7.5 High Ebook Store Plugin ebook-store Information Disclosure Sensitive Data Exposure No login needed ≤ 6.19 Fixed in 6.20 CVE-2026-59529 Patchstack
7.5 High ShipTime: Discounted Shipping Rates Plugin shiptime-discount-shipping Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.1 Fixed in 1.1.5 CVE-2026-59528 Patchstack
9.3 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps SQL Injection No login needed ≤ 8.14.0 Fixed in 8.14.1 CVE-2026-59527 Patchstack
6.8 Medium Calendar Plugin Cross-Site Scripting Contributor+ Stored XSS via event_link Parameter < 1.3.18 Fixed in 1.3.18 CVE-2026-14827 WPScan
8.2 High BookingPress Pro Plugin Information Disclosure Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug No login needed < 5.7.3 Fixed in 5.7.3 CVE-2026-9830 WPScan
5.3 Medium Quiz And Survey Master Plugin Information Disclosure Unauthenticated User Enumeration and Password Oracle via Quiz Login No login needed < 11.1.3 Fixed in 11.1.3 CVE-2026-14820 WPScan
6.5 Medium WP User Frontend Plugin Authentication Bypass Unauthenticated Author-less Attachment Deletion No login needed < 4.3.8 Fixed in 4.3.8 CVE-2026-14568 WPScan
9.0 Critical WP FacturaONE Plugin Remote Code Execution Unauthenticated Remote Code Execution No login needed < 5.37 Fixed in 5.37 CVE-2026-14289 WPScan
4.7 Medium Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Open Redirect PayPal & Stripe Add-on < 2.5 - Open Redirect No login needed < 2.5 Fixed in 2.5 CVE-2026-14236 WPScan
7.5 High WordPress Download Manager Plugin Broken Access Control Unauthorized Protected File Download via Reusable Download Key No login needed < 3.3.62 Fixed in 3.3.62 CVE-2026-14235 WPScan
4.8 Medium Smart Manager Plugin smart-manager-for-wp-e-commerce Cross-Site Scripting Contributor+ Stored XSS via Post Title < 8.92.0 Fixed in 8.92.0 CVE-2026-14203 WPScan
6.1 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Reflected XSS No login needed < 3.10.2 Fixed in 3.10.2 CVE-2026-14190 WPScan
3.8 Low WPBot AI ChatBot Plugin SQL Injection Admin+ Second-Order SQL Injection via qc_bot_str_fields < 8.5.2 Fixed in 8.5.2 CVE-2026-14189 WPScan
7.1 High Multiple Page Generator Plugin – MPG Plugin Cross-Site Scripting MPG < 4.1.8 - Reflected XSS via mpg_shortcode No login needed < 4.1.8 Fixed in 4.1.8 CVE-2026-13726 WPScan
9.8 Critical Realtyna Organic IDX plugin + WPL Real Estate Plugin real-estate-listing-realtyna-wpl Arbitrary File Upload Unauthenticated Arbitrary File Upload to Remote Code Execution No login needed < 5.3.0 Fixed in 5.3.0 CVE-2026-13714 WPScan
9.1 Critical QRcode Login for WeChat Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.3 CVE-2026-13597 WPScan
6.1 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Unauthenticated Stored XSS via Booking Customer Information No login needed < 1.6.12.4 Fixed in 1.6.12.4 CVE-2026-13400 WPScan
5.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Unauthenticated Event Aggregator Import Status Manipulation No login needed < 6.16.5.1 Fixed in 6.16.5.1 CVE-2026-13390 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only