WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 301–350 of 1,407 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 29
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control No login needed ≤ <= 6.0.7.6 Fixed in 6.0.7.7 CVE-2026-32498 Patchstack
6.5 Medium Vertex Addons for Elementor Plugin addons-for-elementor-builder Broken Access Control ≤ 1.6.4 Fixed in 1.7.0 CVE-2026-25398 Patchstack
7.1 High FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-25346 Patchstack
8.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Account Takeover No login needed ≤ 6.0.7.1 Fixed in 6.0.7.2 CVE-2026-24373 Patchstack
7.5 High WP Cost Estimation & Payment Forms Builder Plugin wp_estimation_form Broken Access Control No login needed ≤ 10.3.0 Fixed in 10.3.0 CVE-2026-24363 Patchstack
7.5 High JetFormBuilder Plugin jetformbuilder Path Traversal Unauthenticated Arbitrary File Read via Media Field No login needed ≤ 3.5.6.2 CVE-2026-4373 Wordfence
5.3 Medium Punnel Plugin punnel-landing-page-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update via 'punnel_save_config' AJAX Action No login needed ≤ 1.3.1 CVE-2026-3645 Wordfence
5.3 Medium e-shot Plugin e-shot-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX Action No login needed ≤ 1.0.2 CVE-2026-3546 Wordfence
5.6 Medium Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder Arbitrary Shortcode Execution ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution No login needed ≤ 1.7.2 CVE-2024-13785 Wordfence
5.3 Medium Build App Online Plugin build-app-online Broken Access Control Missing Authorization to Arbitrary Post Author Modification via 'build-app-online-update-vendor-product' AJAX Action No login needed ≤ 1.0.23 CVE-2026-3651 Wordfence
6.4 Medium Ecover Builder For Dummies Plugin ecover-builder-for-dummies Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.0 CVE-2026-4077 Wordfence
6.5 Medium App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter No login needed ≤ 5.5.10 CVE-2026-2375 Wordfence
7.2 High SurveyJS: Drag & Drop Form Builder Plugin surveyjs Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.5.3 CVE-2026-2440 Wordfence
9.8 Critical BuilderPress Plugin builderpress Local File Inclusion No login needed ≤ 2.0.1 CVE-2026-27065 Patchstack
7.1 High tagDiv Opt-In Builder Plugin td-subscription Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-53222 Patchstack
5.3 Medium Instant Popup Builder Plugin instant-popup-builder Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter No login needed ≤ 1.1.7 CVE-2026-3475 Wordfence
9.3 Critical Profile Builder Pro Plugin profile-builder-pro SQL Injection No login needed < 3.14.0 Fixed in 3.14.0 CVE-2026-27413 Patchstack
7.5 High WowStore – Store Builder & Product Blocks for WooCommerce Plugin product-blocks SQL Injection Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter No login needed ≤ 4.4.3 CVE-2026-2579 Wordfence
7.5 High NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id No login needed ≤ 9.1.9 CVE-2026-1947 Wordfence
4.3 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license ≤ 9.1.9 CVE-2026-1948 Wordfence
5.3 Medium Fusion Builder Plugin fusion-builder Broken Access Control No login needed ≤ 3.15.0 Fixed in 3.15.0 CVE-2026-32452 Patchstack
6.5 Medium Fusion Builder Plugin fusion-builder Broken Access Control ≤ 3.15.0 Fixed in 3.15.0 CVE-2026-32451 Patchstack
2.7 Low Elementor Website Builder Plugin elementor Broken Access Control ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32445 Patchstack
5.3 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Broken Access Control Lite plugin <= 1.5.6 - Broken Access Control No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2026-32395 Patchstack
5.4 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control ≤ 6.0.7.6 Fixed in 6.0.7.7 CVE-2026-32385 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32352 Patchstack
7.2 High Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2026-1454 Wordfence
6.1 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting via 'themebuilder' Parameter No login needed ≤ 1.6.8 CVE-2025-12473 Wordfence
5.3 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' No login needed ≤ 12.8.3 CVE-2026-2371 Wordfence
5.3 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Information Disclosure animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup No login needed ≤ 12.8.3 CVE-2026-2589 Wordfence
6.4 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 12.8.5 CVE-2026-2593 Wordfence
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin ultimate_vc_addons Broken Access Control ≤ 3.21.1 Fixed in 3.21.2 CVE-2026-28038 Patchstack
9.9 Critical Builderall Builder Plugin builderall-cheetah-for-wp Remote Code Execution ≤ 3.0.1 CVE-2026-22390 Patchstack
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() ≤ 1.6.0 CVE-2026-1674 Wordfence
4.4 Medium Taskbuilder Plugin taskbuilder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field ≤ 5.0.3 CVE-2026-2289 Wordfence
8.8 High Page Builder by SiteOrigin Plugin siteorigin-panels Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 2.33.5 CVE-2026-2448 Wordfence
7.2 High Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 7.0.0.3 - Authenticated (Administrator+) Server-Side Request Forgery to Arbitrary File Upload ≤ 7.0.0.3 CVE-2026-2269 Wordfence
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Sensitive Data Exposure ≤ 1.14.4 Fixed in 1.14.5 CVE-2026-28131 Patchstack
6.4 Medium Livemesh Addons for Beaver Builder Plugin addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes ≤ 3.9.2 CVE-2026-2029 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes ≤ 3.7 CVE-2026-1614 Wordfence
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 6.3.1 Fixed in 6.5.0 CVE-2026-22350 Patchstack
7.1 High Business Template Blocks for WPBakery (Visual Composer) Page Builder Plugin templates-and-addons-for-wpbakery-page-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-69390 Patchstack
8.1 High Portfolio Builder Plugin swp-portfolio Local File Inclusion No login needed ≤ 1.2.5 CVE-2025-69375 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69326 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.1.7 Fixed in 9.1.8 CVE-2025-69324 Patchstack
7.5 High TopperPack – Complete Elementor Addons, Theme & CPT Builder Plugin topper-pack Local File Inclusion Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-68841 Patchstack
8.1 High Extensive VC Addons for WPBakery page builder Plugin extensive-vc-addon Local File Inclusion No login needed ≤ 1.9.1 CVE-2025-60087 Patchstack
7.6 High AIO WP Builder Plugin all-in-one-wp-builder Broken Access Control ≤ 2.0.2 CVE-2025-53217 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only