WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 301–350 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WP User Frontend Plugin wp-user-frontend Arbitrary File Deletion ≤ 4.3.11 Fixed in 4.3.12 CVE-2026-95525 Patchstack
5.3 Medium WP User Frontend Plugin wp-user-frontend Authentication Bypass Bypass Vulnerability No login needed ≤ 4.3.11 Fixed in 4.3.12 CVE-2026-95524 Patchstack
6.5 Medium WP User Frontend Plugin wp-user-frontend Authentication Bypass Bypass Vulnerability ≤ 4.3.11 Fixed in 4.3.12 CVE-2026-95523 Patchstack
7.6 High Easy Digital Downloads Plugin easy-digital-downloads SQL Injection ≤ 3.7.0 Fixed in 3.7.1 CVE-2026-95522 Patchstack
7.1 High Ninja Forms Plugin ninja-forms Cross-Site Scripting No login needed ≤ 3.15.3 Fixed in 3.15.4 CVE-2026-95515 Patchstack
5.3 Medium Netgsm Plugin netgsm Other Bypass Vulnerability No login needed ≤ 2.10.0 Fixed in 2.10.2 CVE-2026-95514 Patchstack
7.5 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control No login needed ≤ 4.6.0 Fixed in 4.6.3 CVE-2026-95513 Patchstack
6.5 Medium Podcast Importer SecondLine Plugin podcast-importer-secondline Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.8 CVE-2026-94682 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94680 Patchstack
5.4 Medium Fluent Support Plugin fluent-support Broken Access Control ≤ 2.3.2 Fixed in 2.4.0 CVE-2026-94679 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94671 Patchstack
6.5 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2026-94500 Patchstack
6.5 Medium AppMySite Plugin appmysite Broken Access Control No login needed ≤ 3.15.4 Fixed in 3.15.5 CVE-2026-94498 Patchstack
8.1 High PublishPress Capabilities Plugin capability-manager-enhanced Cross-Site Request Forgery No login needed ≤ 2.50.1 Fixed in 2.51.0 CVE-2026-94487 Patchstack
6.5 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting ≤ 3.1.69 Fixed in 3.1.70 CVE-2026-94461 Patchstack
4.8 Medium Captcha Code Plugin captcha-code-authentication Authentication Bypass Bypass Vulnerability No login needed ≤ 3.32 Fixed in 3.33 CVE-2026-94457 Patchstack
6.5 Medium Ultimate FAQ Plugin ultimate-faqs Cross-Site Scripting ≤ 2.4.14 Fixed in 2.5.0 CVE-2026-94391 Patchstack
7.1 High Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2026-94179 Patchstack
7.1 High Mang Board WP Plugin mangboard Cross-Site Scripting No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2026-94176 Patchstack
7.6 High Email Log Plugin email-log SQL Injection ≤ 2.63 Fixed in 2.64 CVE-2026-94174 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.11.105 Fixed in 4.11.106 CVE-2026-94168 Patchstack
8.5 High WP EasyCart Plugin wp-easycart SQL Injection ≤ 5.9.4 Fixed in 6.0.0 CVE-2026-94124 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) ≤ 2.3.17 Fixed in 2.3.18 CVE-2026-94118 Patchstack
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.70 Fixed in 2.1.72 CVE-2026-94080 Patchstack
5.3 Medium WP User Manager Plugin wp-user-manager Broken Access Control No login needed ≤ 2.9.19 Fixed in 2.9.20 CVE-2026-94079 Patchstack
7.1 High WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting No login needed ≤ 9.3.02.002 Fixed in 9.3.02.003 CVE-2026-93774 Patchstack
8.5 High Mollie Forms Plugin mollie-forms SQL Injection ≤ 2.11.0 Fixed in 2.11.1 CVE-2026-93773 Patchstack
6.5 Medium wpForo Forum Plugin wpforo Cross-Site Scripting ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-93772 Patchstack
5.3 Medium AI Engine Plugin ai-engine Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2026-93623 Patchstack
7.1 High WPS Limit Login Plugin wps-limit-login Cross-Site Scripting No login needed ≤ 1.5.9.3 Fixed in 1.5.9.4 CVE-2026-93622 Patchstack
6.5 Medium PayPlus Payment Gateway Plugin payplus-payment-gateway Broken Access Control No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2026-93620 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-93618 Patchstack
6.5 Medium WSP MCP – AI Agents Connector Plugin wsp-mcp-ai-agents-connector Broken Access Control AI Agents Connector plugin <= 2.7.0 - Broken Access Control ≤ 2.7.0 Fixed in 2.7.1 CVE-2026-93529 Patchstack
8.5 High Live Copy Paste for Elementor Plugin live-copy-paste SQL Injection ≤ 1.5.10 Fixed in 1.5.11 CVE-2026-93527 Patchstack
7.1 High Event Tickets Plugin event-tickets Cross-Site Scripting No login needed ≤ 5.29.4 Fixed in 5.29.5 CVE-2026-93526 Patchstack
4.3 Medium SiteSkite Plugin siteskite Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.7 Fixed in 2.1.8 CVE-2026-93513 Patchstack
7.6 High HashBar – WordPress Notification Bar Plugin hashbar-wp-notification-bar SQL Injection WordPress Notification Bar plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 Fixed in 2.0.4 CVE-2026-94117 Patchstack
7.3 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Authentication Bypass Broken Authentication No login needed < 2.0.8 Fixed in 2.0.8 CVE-2026-93928 Patchstack
6.1 Medium MC4WP: Mailchimp Plugin mailchimp-for-wp Cross-Site Scripting Reflected Cross-Site Scripting via 'data' Dynamic Content Tag No login needed ≤ 4.14.0 CVE-2026-87917 Wordfence
5.4 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird Cross-Site Scripting WordPress Media Library Folders & File Manager <= 6.5.6 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 6.5.6 CVE-2026-15004 Wordfence
7.1 High WordPress Core Cross-Site Scripting Unauth. Cross Site Scripting (XSS) No login needed 7.1 – < 7.1.1, 7.0 – 7.0.4, 6.9 – 6.9.7, … Fixed in 7.1.1 CVE-2026-93485 Patchstack
7.1 High WP Inventory Manager Plugin wp-inventory-manager Cross-Site Scripting No login needed ≤ 2.5.4 CVE-2026-90887 Patchstack
5.3 Medium BerqWP Plugin searchpro Broken Access Control No login needed ≤ 4.1.15 Fixed in 4.1.16 CVE-2026-78528 Patchstack
8.8 High Xagio SEO Plugin xagio-seo Cross-Site Request Forgery No login needed ≤ 7.1.0.43 Fixed in 7.1.0.44 CVE-2026-78295 Patchstack
6.5 Medium Geo Mashup Plugin geo-mashup Cross-Site Scripting ≤ 1.13.21 Fixed in 1.13.22 CVE-2026-78294 Patchstack
5.3 Medium User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.2.7 Fixed in 5.2.8 CVE-2026-74017 Patchstack
5.4 Medium PublishPress Series Plugin organize-series Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-74005 Patchstack
5.3 Medium Booking Calendar Plugin booking Broken Access Control No login needed ≤ 11.7 Fixed in 11.8 CVE-2026-74002 Patchstack
5.3 Medium Simple Membership Plugin simple-membership Broken Access Control No login needed ≤ 4.8.2 Fixed in 4.8.3 CVE-2026-74000 Patchstack
5.4 Medium Cooked Plugin cooked Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.16.0 Fixed in 1.16.1 CVE-2026-73999 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only