WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 301–350 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.6 High VikRentItems Flexible Rental Management System Plugin vikrentitems SQL Injection Unauthenticated SQLi No login needed < 1.2.4 Fixed in 1.2.4 CVE-2026-88926 WPScan
8.8 High Master Blocks Plugin ultimate-blocks-for-gutenberg Cross-Site Scripting Unauthenticated Stored XSS via White Label Settings No login needed 1.4.1 – < 1.5.0 Fixed in 1.5.0 CVE-2026-88824 WPScan
8.1 High UsersWP - Social Login Plugin Privilege Escalation Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email No login needed < 1.5.10 Fixed in 1.5.10 CVE-2026-86814 WPScan
8.8 High Ultimate Member Plugin ultimate-member Cross-Site Scripting Unauthenticated Stored XSS via Profile Page Title No login needed < 2.13.1 Fixed in 2.13.1 CVE-2026-85680 WPScan
8.0 High Unbounce Landing Pages Plugin unbounce Broken Access Control Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains 1.1.1 – < 1.1.5 Fixed in 1.1.5 CVE-2026-85574 WPScan
7.1 High Estatik Plugin Cross-Site Scripting Reflected XSS via get_listings hash Parameter No login needed 4.0.1 – < 4.3.5 Fixed in 4.3.5 CVE-2026-76790 WPScan
7.2 High WP Import Export Lite Plugin wp-import-export-lite Privilege Escalation Authenticated Privilege Escalation via User Import < 3.9.35 Fixed in 3.9.35 CVE-2026-76554 WPScan
8.8 High Save as PDF Plugin by PDFCrowd Plugin save-as-pdf-by-pdfcrowd Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute ≤ 4.6.1 CVE-2026-92807 Wordfence
7.5 High WP Photo Album Plus Plugin wp-photo-album-plus Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection ≤ 9.2.09.002 CVE-2026-87909 Wordfence
7.2 High Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 1.4.0.5 CVE-2026-13354 Wordfence
8.8 High WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import 2.0 – 3.8.3 CVE-2026-93031 Wordfence
7.2 High Popup Maker Plugin popup-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter No login needed ≤ 1.24.0 CVE-2026-87915 Wordfence
7.2 High Jeg Kit for Elementor Plugin jeg-elementor-kit Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.2.16 CVE-2026-18405 Wordfence
8.1 High Master Addons for Elementor Plugin master-addons Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter ≤ 3.2.2 CVE-2026-85410 Wordfence
7.2 High Complianz GDPR/CCPA Cookie Consent Banner Plugin complianz-gdpr Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed ≤ 7.5.4 CVE-2026-83561 Wordfence
7.5 High Location Manager Plugin SQL Injection Unauthenticated SQL Injection via 'latitude' and 'longitude' REST API Parameters No login needed ≤ 2.3.38 CVE-2026-85705 Wordfence
7.5 High WP Multi Store Locator Pro Plugin SQL Injection Unauthenticated SQL Injection via 'store_locator_search_radius' Parameter No login needed ≤ 4.5.1 CVE-2026-15275 Wordfence
8.8 High Mapster WP Maps Plugin mapster-wp-maps Privilege Escalation Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter ≤ 1.23.0 CVE-2026-12954 Wordfence
7.5 High Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Path Traversal Unauthenticated Arbitrary File Read via 'folder' and 'mockups' Parameters No login needed ≤ 2.8.5 CVE-2026-14323 Wordfence
7.5 High WCFM Marketplace Plugin wc-multivendor-marketplace SQL Injection Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter No login needed ≤ 3.8.2 CVE-2026-18442 Wordfence
7.2 High Booking Calendar Plugin booking Privilege Escalation Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter ≤ 11.8.2 CVE-2026-92619 Wordfence
8.1 High Filter Gallery Plugin filter-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter ≤ 1.1.4 CVE-2026-89413 Wordfence
7.1 High Filter Gallery Plugin filter-gallery Broken Access Control Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check 1.1.2 – < 1.1.5 Fixed in 1.1.5 CVE-2026-90978 WPScan
8.8 High iGMS Direct Booking Plugin igms-direct-booking Cross-Site Scripting Unauthenticated Stored XSS via Widget Settings No login needed < 2.0 Fixed in 2.0 CVE-2026-88825 WPScan
8.6 High Tz Weekly Radio Schedule Plugin SQL Injection Unauthenticated SQLi via tzwrs_update_cell No login needed ≤ 1.8.1 CVE-2026-87775 WPScan
8.6 High Tz Weekly Radio Schedule Plugin SQL Injection Unauthenticated SQL Injection via week No login needed ≤ 1.8.1 CVE-2026-87774 WPScan
8.6 High Product Question and Answer Plugin SQL Injection Unauthenticated SQL Injection via p_id and read No login needed ≤ 1.1.0 CVE-2026-87771 WPScan
8.6 High Price Drop Alert for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection via product No login needed ≤ 1.1 CVE-2026-87770 WPScan
8.6 High WP Shortcut Link Plugin SQL Injection Unauthenticated SQL Injection via url No login needed ≤ 1.2.0 CVE-2026-87767 WPScan
8.8 High VikBooking Plugin Cross-Site Scripting Unauthenticated Stored XSS via SVG Chat Attachment No login needed 1.8.8 – < 1.8.15 Fixed in 1.8.15 CVE-2026-85127 WPScan
8.8 High Easy Form Builder Plugin easy-form-builder Cross-Site Scripting Unauthenticated Stored XSS via Form Type Confusion No login needed 4.0.0 – < 4.2.0 Fixed in 4.2.0 CVE-2026-85122 WPScan
7.2 High All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Privilege Escalation Authenticated Privilege Escalation to Admin via Import Secret Key Disclosure < 7.111 Fixed in 7.111 CVE-2026-81810 WPScan
7.1 High WordPress Core Cross-Site Scripting Unauth. Cross Site Scripting (XSS) No login needed 7.1 – < 7.1.1, 7.0 – 7.0.4, 6.9 – 6.9.7, … Fixed in 7.1.1 CVE-2026-93485 Patchstack
8.8 High ShortPixel Image Optimizer Plugin shortpixel-image-optimiser PHP Object Injection Authenticated (Author+) PHP Object Injection via Nested JSON Post Content ≤ 6.5.5 CVE-2026-17086 Wordfence
8.8 High faustjs Plugin Authentication Bypass FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope < 1.8.11 CVE-2026-54239 GitHub_M
7.1 High WP Inventory Manager Plugin wp-inventory-manager Cross-Site Scripting No login needed ≤ 2.5.4 CVE-2026-90887 Patchstack
8.8 High Xagio SEO Plugin xagio-seo Cross-Site Request Forgery No login needed ≤ 7.1.0.43 Fixed in 7.1.0.44 CVE-2026-78295 Patchstack
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.9.21 Fixed in 2.0.0 CVE-2026-66631 Patchstack
7.6 High PublishPress Series Plugin organize-series SQL Injection ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-66630 Patchstack
7.6 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay SQL Injection ≤ 3.8.11 Fixed in 3.8.12 CVE-2026-66628 Patchstack
7.6 High SKT Addons for Elementor Plugin skt-addons-for-elementor SQL Injection ≤ 4.0 Fixed in 4.1 CVE-2026-66626 Patchstack
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.7.2.1 Fixed in 2.7.2.2 CVE-2026-66625 Patchstack
7.6 High WPMasterToolKit Plugin wpmastertoolkit SQL Injection ≤ 2.22.0 Fixed in 2.23.1 CVE-2026-66624 Patchstack
7.6 High Newsletters Plugin newsletters-lite SQL Injection ≤ 4.18 Fixed in 4.18.1 CVE-2026-66619 Patchstack
7.6 High WP Maps Plugin wp-google-map-plugin SQL Injection ≤ 4.9.9 Fixed in 5.0.0 CVE-2026-66618 Patchstack
8.5 High Product Feed Manager Plugin best-woocommerce-feed SQL Injection ≤ 7.12.0 Fixed in 7.12.1 CVE-2026-66580 Patchstack
7.1 High Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Cross-Site Request Forgery No login needed ≤ 1.4.0.5 Fixed in 1.4.0.6 CVE-2026-66571 Patchstack
7.1 High Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro Cross-Site Scripting No login needed ≤ 11.21 Fixed in 11.22 CVE-2026-90986 Patchstack
8.6 High Yo Plugin SQL Injection Unauthenticated SQL Injection via username Parameter No login needed 1.1 – 1.3.1 CVE-2026-87963 WPScan
8.8 High To Do List Member Plugin Cross-Site Scripting Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler No login needed 1.4 – 1.6 CVE-2026-86801 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only