WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,651–3,700 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 74 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium WPForms Plugin wpforms-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content ≤ 2.0.0.1 CVE-2026-15782 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings ≤ 6.6.11 CVE-2026-15156 Wordfence
6.4 Medium Spectra Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block ≤ 2.19.28 CVE-2026-12900 Wordfence
5.4 Medium ThumbPress Plugin image-sizes Broken Access Control Subscriber+ Plugin Deactivation < 6.2.2 Fixed in 6.2.2 CVE-2026-13432 WPScan
7.1 High Tag Groups Plugin Cross-Site Scripting Reflected XSS via 'tag_groups_task' Parameter No login needed < 2.2.0 Fixed in 2.2.0 CVE-2026-9833 WPScan
4.9 Medium Elementor Plugin Information Disclosure Contributor+ Sensitive Information Disclosure via REST API < 4.1.4 Fixed in 4.1.4 CVE-2026-8825 WPScan
5.4 Medium MailerSend - Official SMTP Integration Plugin Cross-Site Request Forgery Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF No login needed < 1.0.8 Fixed in 1.0.8 CVE-2026-13156 WPScan
9.1 Critical Kirki Plugin kirki Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via kirki_get_apis No login needed < 6.0.12 Fixed in 6.0.12 CVE-2026-13147 WPScan
8.1 High Passwordless Login by VentraConnect Plugin Privilege Escalation Unauthenticated Account Takeover via Email OTP Brute Force No login needed < 1.4.1 Fixed in 1.4.1 CVE-2026-13142 WPScan
6.5 Medium PayPlus Payment Gateway Plugin payplus-payment-gateway Information Disclosure Unauthenticated Order Key Disclosure and Order Status Modification No login needed < 8.2.2 Fixed in 8.2.2 CVE-2026-12973 WPScan
5.3 Medium PayPlus Payment Gateway Plugin payplus-payment-gateway Broken Access Control Unauthenticated Order Payment Metadata Tampering No login needed < 8.2.2 Fixed in 8.2.2 CVE-2026-12972 WPScan
7.1 High LearnPress Plugin learnpress Cross-Site Scripting Reflected XSS via c_search No login needed < 4.4.1 Fixed in 4.4.1 CVE-2026-12970 WPScan
6.5 Medium All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Path Traversal Unauthenticated Arbitrary-Location Log File Write via Path Traversal No login needed 7.87 – < 7.106 Fixed in 7.106 CVE-2026-12898 WPScan
4.3 Medium Kirki Plugin kirki Content Injection Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password No login needed < 6.0.12 Fixed in 6.0.12 CVE-2026-12724 WPScan
5.3 Medium Kirki Plugin kirki Broken Access Control Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library No login needed < 6.0.12 Fixed in 6.0.12 CVE-2026-12723 WPScan
7.5 High SlimStat Analytics Plugin wp-slimstat Cross-Site Scripting Unauthenticated Stored XSS via CF-IPCountry Header No login needed < 5.5.0 Fixed in 5.5.0 CVE-2026-12592 WPScan
5.3 Medium WP Travel Plugin wp-travel Broken Access Control Unauthenticated Arbitrary Booking Cancellation No login needed < 11.7.1 Fixed in 11.7.1 CVE-2026-11868 WPScan
8.6 High Modern Events Calendar (Lite & Pro) Plugin SQL Injection Unauthenticated SQL Injection via mec_list_load_more No login needed < 7.34.0 Fixed in 7.34.0 CVE-2026-11349 WPScan
2.7 Low All in One SEO Plugin all-in-one-seo-pack Broken Access Control Contributor+ Incorrect Authorization via AI Integration < 4.9.9 Fixed in 4.9.9 CVE-2026-10755 WPScan
4.8 Medium Reviews Feed Plugin reviews-feed Arbitrary Shortcode Execution Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews No login needed < 2.6.5 Fixed in 2.6.5 CVE-2026-10724 WPScan
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Unauthenticated Stored XSS via Google Reviews Widget No login needed < 2.0.11 Fixed in 2.0.11 CVE-2026-10081 WPScan
4.3 Medium Flow Payment Plugin Cross-Site Scripting Flow Payment Plugin for WordPress Reflected Cross-Site Scripting via error_message Parameter No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2026-57857 VulnCheck
4.3 Medium W3SC Elementor to Zoho CRM Plugin w3sc-elementor-to-zoho Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.2.0 CVE-2026-9734 Wordfence
9.8 Critical WordPress Core SQL Injection REST API batch-route confusion and SQL injection issue leading to Remote Code Execution No login needed 6.9.0 – < 6.9.5, 7.0.0 – < 7.0.2 Fixed in 6.9.5 CVE-2026-63030 WPScan
5.9 Medium WordPress Core SQL Injection Facilitated SQL Injection via author__not_in in WP_Query No login needed 6.8.0 – < 6.8.6, 6.9.0 – < 6.9.5, 7.0.0 – < 7.0.2 Fixed in 6.8.6 CVE-2026-60137 WPScan
4.3 Medium HubSpot All-In-One Marketing Plugin leadin Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script ≤ 11.3.62 CVE-2026-9656 Wordfence
5.3 Medium Royal Elementor Addons Plugin Information Disclosure Unauthenticated Private Mega Menu Template Disclosure No login needed < 1.7.1063 Fixed in 1.7.1063 CVE-2026-13402 WPScan
5.4 Medium WPS Bookings for WooCommerce Plugin mwb-bookings-for-woocommerce Broken Access Control Subscriber+ Arbitrary Booking Order Cancellation via IDOR < 3.11.7 Fixed in 3.11.7 CVE-2026-12393 WPScan
5.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Unauthenticated Limited User Deletion via Stripe Subscription Handler No login needed 4.2.3 – < 5.2.3 Fixed in 5.2.3 CVE-2026-11966 WPScan
8.1 High User Registration & Membership Plugin user-registration Privilege Escalation Unauthenticated Privilege Escalation via Unbound members_data Membership ID No login needed < 5.2.3 Fixed in 5.2.3 CVE-2026-11961 WPScan
9.8 Critical AI Chatbot & Workflow Automation by AIWU Plugin Privilege Escalation Unauthenticated Privilege Escalation via MCP OAuth No login needed < 1.5.4 Fixed in 1.5.4 CVE-2026-9810 WPScan
7.5 High PhonePe Payment Solutions Plugin phonepe-payment-solutions Price Manipulation Unauthenticated Payment Bypass via Forged Callback No login needed < 3.1.0 Fixed in 3.1.0 CVE-2026-11575 WPScan
6.1 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored XSS via Form Submission No login needed < 9.2.3 Fixed in 9.2.3 CVE-2026-10525 WPScan
6.1 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Scripting Reflected Cross-Site Scripting via 'check_in_date' Parameter No login needed ≤ 2.3.2 CVE-2026-15094 Wordfence
9.8 Critical Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit Plugin Privilege Escalation All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function' No login needed ≤ 2.8.4 CVE-2026-15982 Wordfence
6.4 Medium ChatHelp Plugin chat-help Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes ≤ 3.5.1 CVE-2026-15759 Wordfence
6.4 Medium Ninja Forms - Excel Export Plugin ninja-forms-excel-export Cross-Site Scripting Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter ≤ 3.3.6 CVE-2026-15161 Wordfence
7.5 High LearnPress Plugin learnpress Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints No login needed ≤ 4.4.1 CVE-2026-13765 Wordfence
4.3 Medium ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce Plugin erp Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler ≤ 1.17.6 CVE-2026-15349 Wordfence
6.5 Medium pCloud WP Backup Plugin pcloud-wp-backup Broken Access Control Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read ≤ 2.0.3 CVE-2026-14503 Wordfence
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary File Upload Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion ≤ 4.16.18 CVE-2026-13352 Wordfence
4.9 Medium Kirki Plugin kirki Path Traversal Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter ≤ 6.0.13 CVE-2026-15457 Wordfence
7.2 High Kali Forms Plugin kali-forms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value No login needed ≤ 2.4.18 CVE-2026-15395 Wordfence
4.3 Medium Ninja Forms - Excel Export Plugin ninja-forms-excel-export Broken Access Control Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal ≤ 3.3.6 CVE-2026-15160 Wordfence
4.3 Medium Ninja Forms - Excel Export Plugin ninja-forms-excel-export Broken Access Control Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter ≤ 3.3.6 CVE-2026-15159 Wordfence
6.1 Medium WooCommerce Placetopay Gateway Plugin Cross-Site Scripting Reflected Cross-Site Scripting via 'redirect-url' No login needed ≤ 3.2.2 CVE-2026-11324 Wordfence
5.3 Medium Fense Proxy & VPN Blocker Plugin fense-block-vpn-proxy Broken Access Control Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action No login needed ≤ 3.0.1 CVE-2026-8616 Wordfence
9.8 Critical Bricksforge Plugin Privilege Escalation Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter No login needed ≤ 3.1.8.6 CVE-2026-14956 Wordfence
6.4 Medium Smart Custom Fields Plugin smart-custom-fields Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title ≤ 5.0.7 CVE-2026-2594 Wordfence
4.9 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking SQL Injection Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import ≤ 2.4.3 CVE-2026-14782 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only