WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 301–350 of 2,150 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.1 Critical | SoftMarket | Privilege Escalation Unauthenticated Account Takeover via Email Verification Bypass No login needed |
≤ 1.0.0 |
CVE-2026-14557 |
WPScan | |
| 9.1 Critical | Super Store Finder | SQL Injection Unauthenticated SQL Injection via ssf_tracking No login needed |
< 7.11 Fixed in 7.11 |
CVE-2026-12965 |
WPScan | |
| 9.8 Critical | Webinfos | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.2 |
CVE-2026-12872 |
WPScan | |
| 9.1 Critical | Import and export users and customers | Privilege Escalation Custom Role Privilege Escalation to Administrator via CSV Import No login needed |
< 2.4.2 Fixed in 2.4.2 |
CVE-2026-16534 |
WPScan | |
| 9.1 Critical | Link Library | SQL Injection Unauthenticated SQL Injection via the Front-End Link Submission Form No login needed |
< 7.9.3 Fixed in 7.9.3 |
CVE-2026-16532 |
WPScan | |
| 9.8 Critical | Pouco Import Users | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.0.0 |
CVE-2026-16256 |
WPScan | |
| 9.8 Critical | WooCommerce - Social Login | Authentication Bypass Social Login <= 2.8.7 - Unauthenticated Authentication Bypass via Forged Apple 'id_token' JWT No login needed |
≤ 2.8.7 |
CVE-2026-8457 |
Wordfence | |
| 9.8 Critical | Single Sign On For TNG | Privilege Escalation Unauthenticated Privilege Escalation via Unverified Password Change No login needed |
≤ 2.0.0 |
CVE-2026-15964 |
Wordfence | |
| 9.1 Critical | Participants Database | SQL Injection Unauthenticated SQL Injection via List Search No login needed |
< 2.7.8.4 Fixed in 2.7.8.4 |
CVE-2026-13596 |
WPScan | |
| 9.1 Critical | FormGent | Broken Access Control FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter No login needed |
≤ 1.9.2 |
CVE-2026-3141 |
Wordfence | |
| 9.8 Critical | ShopMonitor.io | Privilege Escalation Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute No login needed |
< 1.2.0 Fixed in 1.2.0 |
CVE-2026-14919 |
WPScan | |
| 9.8 Critical | Realtyna Organic IDX plugin + WPL Real Estate | Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command No login needed |
≤ 5.2.0 |
CVE-2026-14483 |
Wordfence | |
| 9.0 Critical | Remote API | PHP Object Injection Unauthenticated PHP Object Injection via remote-api Query Parameter No login needed |
≤ 0.2 |
CVE-2026-14602 |
WPScan | |
| 9.8 Critical | Admin and Site Enhancements (ASE) Pro | Remote Code Execution Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key No login needed |
≤ 8.9.0 |
CVE-2026-16610 |
Wordfence | |
| 9.1 Critical | Meta Box AIO | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter No login needed |
≤ 3.8.0 |
CVE-2026-14488 |
Wordfence | |
| 9.8 Critical | Cost Calculator Builder PRO | Remote Code Execution Unauthenticated Remote Code Execution via 'orderDetails' Parameter No login needed |
≤ 4.0.3 |
CVE-2026-14900 |
Wordfence | |
| 9.8 Critical | Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light | Broken Access Control Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation No login needed |
≤ 2.4.37 |
CVE-2025-10656 |
Wordfence | |
| 9.8 Critical | Streamit | Remote Code Execution Unauthenticated Remote Code Execution via Arbitrary Function Call No login needed |
≤ 4.5.0 |
CVE-2026-13423 |
WPScan | |
| 9.8 Critical | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … | Authentication Bypass Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter No login needed |
10.8.7 |
CVE-2026-18072 |
Wordfence | |
| 9.8 Critical | SMS Alert | Authentication Bypass Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter No login needed |
≤ 3.9.7 |
CVE-2026-15014 |
Wordfence | |
| 9.8 Critical | TrueBooker Appointment Booking | Privilege Escalation Unauthenticated Account Takeover via Password Reset No login needed |
< 1.2.4 Fixed in 1.2.4 |
CVE-2026-14545 |
WPScan | |
| 9.3 Critical | AWP Classifieds | SQL Injection No login needed |
≤ 4.4.7 Fixed in 4.4.8 |
CVE-2026-59550 |
Patchstack | |
| 9.3 Critical | rtMedia for WordPress, BuddyPress and bbPress | SQL Injection No login needed |
≤ 4.7.10 Fixed in 4.7.11 |
CVE-2026-59549 |
Patchstack | |
| 9.3 Critical | GamiPress | SQL Injection No login needed |
≤ 7.9.7 Fixed in 7.9.8 |
CVE-2026-59538 |
Patchstack | |
| 9.3 Critical | Relevanssi Light | SQL Injection No login needed |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2026-59533 |
Patchstack | |
| 9.3 Critical | MapSVG | SQL Injection No login needed |
≤ 8.14.0 Fixed in 8.14.1 |
CVE-2026-59527 |
Patchstack | |
| 9.0 Critical | WP FacturaONE | Remote Code Execution Unauthenticated Remote Code Execution No login needed |
< 5.37 Fixed in 5.37 |
CVE-2026-14289 |
WPScan | |
| 9.8 Critical | Realtyna Organic IDX plugin + WPL Real Estate | Arbitrary File Upload Unauthenticated Arbitrary File Upload to Remote Code Execution No login needed |
< 5.3.0 Fixed in 5.3.0 |
CVE-2026-13714 |
WPScan | |
| 9.1 Critical | QRcode Login for WeChat | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 1.3 |
CVE-2026-13597 |
WPScan | |
| 9.1 Critical | Masteriyo LMS | Denial of Service Unauthenticated Arbitrary User Session Termination (Denial of Service) No login needed |
< 2.3.1 Fixed in 2.3.1 |
CVE-2026-13332 |
WPScan | |
| 9.8 Critical | MemberGlut | Privilege Escalation Unauthenticated Privilege Escalation to Administrator No login needed |
< 1.1.5 Fixed in 1.1.5 |
CVE-2026-12394 |
WPScan | |
| 9.1 Critical | Software Issue Manager | SQL Injection Unauthenticated SQL Injection via Search Parameter No login needed |
< 5.1.0 Fixed in 5.1.0 |
CVE-2026-12877 |
WPScan | |
| 9.8 Critical | SAML Single Sign On | Authentication Bypass Unauthenticated Authentication Bypass via SAMLResponse Parameter No login needed |
≤ 5.4.4 |
CVE-2026-15981 |
Wordfence | |
| 9.6 Critical | Avada Core | Cross-Site Request Forgery No login needed |
≤ 5.15.6 Fixed in 5.15.7 |
CVE-2026-65471 |
Patchstack | |
| 9.1 Critical | Really Simple CSV Importer | Arbitrary File Upload |
≤ 1.3 Fixed in 1.3.1 |
CVE-2026-65461 |
Patchstack | |
| 9.1 Critical | MapSVG | Arbitrary File Upload |
≤ 8.14.0 Fixed in 8.14.1 |
CVE-2026-65455 |
Patchstack | |
| 9.8 Critical | TrueBooker | Privilege Escalation No login needed |
≤ 1.2.3 Fixed in 1.2.4 |
CVE-2026-61951 |
Patchstack | |
| 9.3 Critical | TrueBooker | SQL Injection No login needed |
≤ 1.2.3 Fixed in 1.2.4 |
CVE-2026-61950 |
Patchstack | |
| 9.3 Critical | Bookly | SQL Injection No login needed |
≤ 27.7 Fixed in 27.8 |
CVE-2026-61949 |
Patchstack | |
| 9.3 Critical | WPDM – Premium Packages | SQL Injection Premium Packages plugin <= 6.2.0 - SQL Injection No login needed |
≤ 6.2.0 Fixed in 7.0.0 |
CVE-2026-61948 |
Patchstack | |
| 10.0 Critical | Participants Database | Arbitrary File Deletion No login needed |
≤ 2.7.8.3 Fixed in 2.7.8.4 |
CVE-2026-59555 |
Patchstack | |
| 9.8 Critical | Thrive Quiz Builder | PHP Object Injection No login needed |
≤ 10.9.3.0 Fixed in 10.9.3.1 |
CVE-2026-59544 |
Patchstack | |
| 9.9 Critical | Advanced Views | Remote Code Execution |
≤ 3.8.11 Fixed in 3.9.0 |
CVE-2026-59543 |
Patchstack | |
| 9.8 Critical | SMS Alert Order Notifications | Privilege Escalation No login needed |
≤ 3.9.6 Fixed in 3.9.7 |
CVE-2026-59540 |
Patchstack | |
| 9.3 Critical | MapSVG | SQL Injection No login needed |
≤ 8.14.0 Fixed in 8.14.1 |
CVE-2026-59526 |
Patchstack | |
| 9.3 Critical | Participants Database | SQL Injection No login needed |
≤ 2.7.8.3 Fixed in 2.7.8.4 |
CVE-2026-59525 |
Patchstack | |
| 9.3 Critical | Buddyboss Platform | SQL Injection No login needed |
≤ 3.0.5 Fixed in 3.1.0 |
CVE-2026-59514 |
Patchstack | |
| 9.6 Critical | Ninja Forms File Uploads Extension | Arbitrary File Upload Cross Site Request Forgery (CSRF) No login needed |
≤ 3.3.26 |
CVE-2026-57784 |
Patchstack | |
| 9.1 Critical | Mailster | Arbitrary File Upload |
≤ 4.1.17 Fixed in 4.1.18 |
CVE-2026-27064 |
Patchstack | |
| 9.8 Critical | MountDev AI MCP Connector | Privilege Escalation Unauthenticated Privilege Escalation via OAuth Authorization Endpoint No login needed |
≤ 1.6.1 |
CVE-2026-15015 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.