WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 301–350 of 8,917 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.6 High | VikRentItems Flexible Rental Management System | SQL Injection Unauthenticated SQLi No login needed |
< 1.2.4 Fixed in 1.2.4 |
CVE-2026-88926 |
WPScan | |
| 8.8 High | Master Blocks | Cross-Site Scripting Unauthenticated Stored XSS via White Label Settings No login needed |
1.4.1 – < 1.5.0 Fixed in 1.5.0 |
CVE-2026-88824 |
WPScan | |
| 8.1 High | UsersWP - Social Login | Privilege Escalation Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email No login needed |
< 1.5.10 Fixed in 1.5.10 |
CVE-2026-86814 |
WPScan | |
| 8.8 High | Ultimate Member | Cross-Site Scripting Unauthenticated Stored XSS via Profile Page Title No login needed |
< 2.13.1 Fixed in 2.13.1 |
CVE-2026-85680 |
WPScan | |
| 8.0 High | Unbounce Landing Pages | Broken Access Control Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains |
1.1.1 – < 1.1.5 Fixed in 1.1.5 |
CVE-2026-85574 |
WPScan | |
| 7.1 High | Estatik | Cross-Site Scripting Reflected XSS via get_listings hash Parameter No login needed |
4.0.1 – < 4.3.5 Fixed in 4.3.5 |
CVE-2026-76790 |
WPScan | |
| 7.2 High | WP Import Export Lite | Privilege Escalation Authenticated Privilege Escalation via User Import |
< 3.9.35 Fixed in 3.9.35 |
CVE-2026-76554 |
WPScan | |
| 8.8 High | Save as PDF Plugin by PDFCrowd | Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute |
≤ 4.6.1 |
CVE-2026-92807 |
Wordfence | |
| 7.5 High | WP Photo Album Plus | Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection |
≤ 9.2.09.002 |
CVE-2026-87909 |
Wordfence | |
| 7.2 High | Asset CleanUp: Page Speed Booster | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed |
≤ 1.4.0.5 |
CVE-2026-13354 |
Wordfence | |
| 8.8 High | WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import |
2.0 – 3.8.3 |
CVE-2026-93031 |
Wordfence | |
| 7.2 High | Popup Maker | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via values[Name] Parameter No login needed |
≤ 1.24.0 |
CVE-2026-87915 |
Wordfence | |
| 7.2 High | Jeg Kit for Elementor | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed |
≤ 3.2.16 |
CVE-2026-18405 |
Wordfence | |
| 8.1 High | Master Addons for Elementor | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Modification/Deletion via 'popup_id' Parameter |
≤ 3.2.2 |
CVE-2026-85410 |
Wordfence | |
| 7.2 High | Complianz GDPR/CCPA Cookie Consent Banner | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed |
≤ 7.5.4 |
CVE-2026-83561 |
Wordfence | |
| 7.5 High | Location Manager | SQL Injection Unauthenticated SQL Injection via 'latitude' and 'longitude' REST API Parameters No login needed |
≤ 2.3.38 |
CVE-2026-85705 |
Wordfence | |
| 7.5 High | WP Multi Store Locator Pro | SQL Injection Unauthenticated SQL Injection via 'store_locator_search_radius' Parameter No login needed |
≤ 4.5.1 |
CVE-2026-15275 |
Wordfence | |
| 8.8 High | Mapster WP Maps | Privilege Escalation Authenticated (Subscriber+) Arbitrary User Meta Write via 'acf-photo-gallery-groups' Parameter |
≤ 1.23.0 |
CVE-2026-12954 |
Wordfence | |
| 7.5 High | Printcart Web to Print Product Designer for WooCommerce | Path Traversal Unauthenticated Arbitrary File Read via 'folder' and 'mockups' Parameters No login needed |
≤ 2.8.5 |
CVE-2026-14323 |
Wordfence | |
| 7.5 High | WCFM Marketplace | SQL Injection Unauthenticated SQL Injection via 'wcfmmp_user_location_lat' / 'wcfmmp_user_location_lng' Parameter No login needed |
≤ 3.8.2 |
CVE-2026-18442 |
Wordfence | |
| 7.2 High | Booking Calendar | Privilege Escalation Authenticated (Editor+) Privilege Escalation to 'data_name' Parameter |
≤ 11.8.2 |
CVE-2026-92619 |
Wordfence | |
| 8.1 High | Filter Gallery | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Gallery Deletion via 'ufg_gallery_id' Parameter |
≤ 1.1.4 |
CVE-2026-89413 |
Wordfence | |
| 7.1 High | Filter Gallery | Broken Access Control Subscriber+ Arbitrary Post Overwrite and Plugin Option Deletion via Fail-Open Nonce Check |
1.1.2 – < 1.1.5 Fixed in 1.1.5 |
CVE-2026-90978 |
WPScan | |
| 8.8 High | iGMS Direct Booking | Cross-Site Scripting Unauthenticated Stored XSS via Widget Settings No login needed |
< 2.0 Fixed in 2.0 |
CVE-2026-88825 |
WPScan | |
| 8.6 High | Tz Weekly Radio Schedule | SQL Injection Unauthenticated SQLi via tzwrs_update_cell No login needed |
≤ 1.8.1 |
CVE-2026-87775 |
WPScan | |
| 8.6 High | Tz Weekly Radio Schedule | SQL Injection Unauthenticated SQL Injection via week No login needed |
≤ 1.8.1 |
CVE-2026-87774 |
WPScan | |
| 8.6 High | Product Question and Answer | SQL Injection Unauthenticated SQL Injection via p_id and read No login needed |
≤ 1.1.0 |
CVE-2026-87771 |
WPScan | |
| 8.6 High | Price Drop Alert for WooCommerce | SQL Injection Unauthenticated SQL Injection via product No login needed |
≤ 1.1 |
CVE-2026-87770 |
WPScan | |
| 8.6 High | WP Shortcut Link | SQL Injection Unauthenticated SQL Injection via url No login needed |
≤ 1.2.0 |
CVE-2026-87767 |
WPScan | |
| 8.8 High | VikBooking | Cross-Site Scripting Unauthenticated Stored XSS via SVG Chat Attachment No login needed |
1.8.8 – < 1.8.15 Fixed in 1.8.15 |
CVE-2026-85127 |
WPScan | |
| 8.8 High | Easy Form Builder | Cross-Site Scripting Unauthenticated Stored XSS via Form Type Confusion No login needed |
4.0.0 – < 4.2.0 Fixed in 4.2.0 |
CVE-2026-85122 |
WPScan | |
| 7.2 High | All-in-One WP Migration and Backup | Privilege Escalation Authenticated Privilege Escalation to Admin via Import Secret Key Disclosure |
< 7.111 Fixed in 7.111 |
CVE-2026-81810 |
WPScan | |
| 7.1 High | WordPress | Cross-Site Scripting Unauth. Cross Site Scripting (XSS) No login needed |
7.1 – < 7.1.1, 7.0 – 7.0.4, 6.9 – 6.9.7, … Fixed in 7.1.1 |
CVE-2026-93485 |
Patchstack | |
| 8.8 High | ShortPixel Image Optimizer | PHP Object Injection Authenticated (Author+) PHP Object Injection via Nested JSON Post Content |
≤ 6.5.5 |
CVE-2026-17086 |
Wordfence | |
| 8.8 High | faustjs | Authentication Bypass FaustWP — Authentication Bypass via Initialization Vector Modification in Token Envelope |
< 1.8.11 |
CVE-2026-54239 |
GitHub_M | |
| 7.1 High | WP Inventory Manager | Cross-Site Scripting No login needed |
≤ 2.5.4 |
CVE-2026-90887 |
Patchstack | |
| 8.8 High | Xagio SEO | Cross-Site Request Forgery No login needed |
≤ 7.1.0.43 Fixed in 7.1.0.44 |
CVE-2026-78295 |
Patchstack | |
| 7.6 High | MC Woocommerce Wishlist | SQL Injection |
≤ 1.9.21 Fixed in 2.0.0 |
CVE-2026-66631 |
Patchstack | |
| 7.6 High | PublishPress Series | SQL Injection |
≤ 3.1.3 Fixed in 3.1.4 |
CVE-2026-66630 |
Patchstack | |
| 7.6 High | WP-Lister Lite for eBay | SQL Injection |
≤ 3.8.11 Fixed in 3.8.12 |
CVE-2026-66628 |
Patchstack | |
| 7.6 High | SKT Addons for Elementor | SQL Injection |
≤ 4.0 Fixed in 4.1 |
CVE-2026-66626 |
Patchstack | |
| 7.6 High | WC Vendors Marketplace | SQL Injection |
≤ 2.7.2.1 Fixed in 2.7.2.2 |
CVE-2026-66625 |
Patchstack | |
| 7.6 High | WPMasterToolKit | SQL Injection |
≤ 2.22.0 Fixed in 2.23.1 |
CVE-2026-66624 |
Patchstack | |
| 7.6 High | Newsletters | SQL Injection |
≤ 4.18 Fixed in 4.18.1 |
CVE-2026-66619 |
Patchstack | |
| 7.6 High | WP Maps | SQL Injection |
≤ 4.9.9 Fixed in 5.0.0 |
CVE-2026-66618 |
Patchstack | |
| 8.5 High | Product Feed Manager | SQL Injection |
≤ 7.12.0 Fixed in 7.12.1 |
CVE-2026-66580 |
Patchstack | |
| 7.1 High | Asset CleanUp: Page Speed Booster | Cross-Site Request Forgery No login needed |
≤ 1.4.0.5 Fixed in 1.4.0.6 |
CVE-2026-66571 |
Patchstack | |
| 7.1 High | Visitor Traffic Real Time Statistics Pro | Cross-Site Scripting No login needed |
≤ 11.21 Fixed in 11.22 |
CVE-2026-90986 |
Patchstack | |
| 8.6 High | Yo | SQL Injection Unauthenticated SQL Injection via username Parameter No login needed |
1.1 – 1.3.1 |
CVE-2026-87963 |
WPScan | |
| 8.8 High | To Do List Member | Cross-Site Scripting Unauthenticated Stored XSS, File Listing and Deletion via Unprotected Upload Handler No login needed |
1.4 – 1.6 |
CVE-2026-86801 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.