WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,401–3,450 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 69 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical Masteriyo LMS Plugin learning-management-system Denial of Service Unauthenticated Arbitrary User Session Termination (Denial of Service) No login needed < 2.3.1 Fixed in 2.3.1 CVE-2026-13332 WPScan
8.1 High Custom Fields Account Registration For WooCommerce Plugin custom-fields-account-registration-for-woocommerce Privilege Escalation Unauthenticated Privilege Escalation No login needed < 1.4 Fixed in 1.4 CVE-2026-13152 WPScan
6.1 Medium Document Gallery Plugin document-gallery Cross-Site Scripting Reflected XSS via dg_generate_gallery No login needed < 5.1.1 Fixed in 5.1.1 CVE-2026-12982 WPScan
7.5 High Clover Payment Gateway by Zaytech for WooCommerce Plugin woo-clover-gateway-by-zaytech Price Manipulation Unauthenticated Payment Bypass via check_order No login needed < 1.3.6 Fixed in 1.3.6 CVE-2026-12493 WPScan
9.8 Critical MemberGlut Plugin memberglut Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed < 1.1.5 Fixed in 1.1.5 CVE-2026-12394 WPScan
8.1 High MainWP Child Plugin mainwp-child Authentication Bypass Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration No login needed < 6.1.2 Fixed in 6.1.2 CVE-2026-12255 WPScan
6.1 Medium Advanced Ads – Ad Manager & AdSense Plugin advanced-ads Cross-Site Scripting Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter No login needed < 2.0.23 Fixed in 2.0.23 CVE-2026-10082 WPScan
8.6 High Printcart Web to Print Product Designer for WooCommerce Plugin Path Traversal Unauthenticated Arbitrary File Read and Server-Side Request Forgery No login needed < 2.5.3 Fixed in 2.5.3 CVE-2025-15662 WPScan
8.8 High Fluent Forms Pro Add On Pack Plugin PHP Object Injection Authenticated (Subscriber+) PHP Object Injection to Arbitrary User Password Change via User Meta Field ≤ 6.2.6 CVE-2026-15962 Wordfence
8.1 High WPForms Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering No login needed ≤ 1.10.1.1 CVE-2026-10818 Wordfence
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name) ≤ 28.0 CVE-2026-15425 Wordfence
6.5 Medium Checkout Field Editor for WooCommerce (Pro) Plugin Path Traversal Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' Parameter ≤ 3.7.7 CVE-2026-14955 Wordfence
8.1 High Easy Appointments Plugin easy-appointments Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion ≤ 3.12.27 CVE-2026-8789 Wordfence
4.9 Medium Ninja Forms Plugin ninja-forms SQL Injection Authenticated (Administrator+) SQL Injection via Import File 'settings' Key ≤ 3.14.9 CVE-2026-15663 Wordfence
7.3 High EventON Action User Plugin eventon-action-user Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action No login needed ≤ 2.5.14 CVE-2026-10033 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter No login needed ≤ 1.8.13 CVE-2026-15401 Wordfence
6.1 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Reflected Cross-Site Scripting via 'category_id' Parameter No login needed ≤ 1.8.13 CVE-2026-15346 Wordfence
6.4 Medium Rich Showcase for Google Reviews Plugin widget-google-reviews Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute ≤ 6.9.9 CVE-2026-15739 Wordfence
6.4 Medium SureDash Plugin suredash Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.10.0 CVE-2026-15821 Wordfence
6.4 Medium Visualizer Plugin visualizer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter ≤ 4.0.5 CVE-2026-15653 Wordfence
6.4 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute ≤ 2.3.2 CVE-2026-15464 Wordfence
6.4 Medium Brands for WooCommerce Plugin brands-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute ≤ 3.8.8 CVE-2026-15648 Wordfence
5.3 Medium Payment Plugins for Stripe WooCommerce Plugin woo-stripe-payment Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret No login needed ≤ 4.0.7 CVE-2026-12654 Wordfence
6.4 Medium Open User Map Plugin open-user-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.4.45 CVE-2026-15755 Wordfence
6.4 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block Attribute ≤ 2.2.11 CVE-2026-15334 Wordfence
6.4 Medium Fluent Support Plugin fluent-support Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute ≤ 2.3.0 CVE-2026-15665 Wordfence
6.4 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute ≤ 2.2.11 CVE-2026-15333 Wordfence
7.5 High WowOptin Plugin Broken Access Control Unauthenticated Opt-in Deactivation and Template Row Injection No login needed < 1.4.38 Fixed in 1.4.38 CVE-2026-14603 WPScan
7.5 High CAFEHAUS API Plugin Privilege Escalation Unauthenticated Arbitrary User Password Reset No login needed ≤ 1.0.0 CVE-2026-12981 WPScan
9.1 Critical Software Issue Manager Plugin SQL Injection Unauthenticated SQL Injection via Search Parameter No login needed < 5.1.0 Fixed in 5.1.0 CVE-2026-12877 WPScan
3.8 Low ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Premium License Tampering via Missing Authorization < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12690 WPScan
5.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12689 WPScan
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Price Manipulation Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery No login needed < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12688 WPScan
7.5 High ProfilePress Plugin Privilege Escalation Unauthenticated Privilege Escalation via Registration Role Selection No login needed < 4.16.18 Fixed in 4.16.18 CVE-2026-12497 WPScan
8.0 High WPify Woo Plugin wpify-woo Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint ≤ 5.4.16 CVE-2026-12736 Wordfence
5.3 Medium Participants Database Plugin participants-database Broken Access Control Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter No login needed ≤ 2.7.8.3 CVE-2026-11354 Wordfence
4.3 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Path Traversal Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter ≤ 5.0.0 CVE-2026-15420 Wordfence
5.3 Medium Kirki Plugin kirki Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter No login needed ≤ 6.0.14 CVE-2026-13464 Wordfence
6.4 Medium MapSVG Lite Plugin mapsvg-lite-interactive-vector-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.14.0 CVE-2025-9205 Wordfence
6.4 Medium Post Grid Gutenberg Blocks Plugin ultimate-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute ≤ 5.0.32 CVE-2026-15100 Wordfence
6.4 Medium Firelight Lightbox Plugin easy-fancybox Cross-Site Scripting Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute ≤ 2.3.20 CVE-2026-6454 Wordfence
9.8 Critical SAML Single Sign On Plugin miniorange-saml-20-single-sign-on Authentication Bypass Unauthenticated Authentication Bypass via SAMLResponse Parameter No login needed ≤ 5.4.4 CVE-2026-15981 Wordfence
8.8 High WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) Plugin wpo365-login Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update No login needed ≤ 43.2 CVE-2026-15212 Wordfence
6.5 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting 2.14.25 – 2.14.30 Fixed in 2.14.31 CVE-2026-65475 Patchstack
6.5 Medium WooCommerce Product Stock Alert Plugin woocommerce-product-stock-alert Information Disclosure Sensitive Data Exposure ≤ 3.0.6 Fixed in 3.1.0 CVE-2026-61945 Patchstack
7.1 High MailPoet Plugin mailpoet Cross-Site Request Forgery No login needed 5.30.0 – 5.33.0 Fixed in 5.33.1 CVE-2026-57626 Patchstack
5.9 Medium Tabs Plugin tabs-responsive Cross-Site Scripting ≤ 2.5 CVE-2026-65550 Patchstack
7.1 High Popup for CF7 with Sweet Alert Plugin cf7-sweet-alert-popup Cross-Site Request Forgery No login needed ≤ 1.6.5 CVE-2026-65540 Patchstack
7.1 High Kwayy HTML Sitemap Plugin kwayy-html-sitemap Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0 CVE-2026-65539 Patchstack
5.9 Medium Machete Plugin machete Cross-Site Scripting ≤ 5.2 CVE-2026-65538 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only