WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,751–3,800 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 76 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery Cross-Site Request Forgery to Group Membership Request Approval/Denial No login needed ≤ 5.9.8.2 CVE-2026-2494 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion ≤ 5.9.8.1 CVE-2026-2488 Wordfence
6.4 Medium Hammas Calendar Plugin hammas-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'apix' Shortcode Attribute ≤ 1.5.11 CVE-2026-1902 Wordfence
4.3 Medium Winston AI Plugin winston-ai-wp Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion ≤ 0.0.3 CVE-2026-1981 Wordfence
4.3 Medium WP Frontend Profile Plugin wp-front-end-profile Cross-Site Request Forgery Cross-Site Request Forgery to Unauthorized User Account Approval or Rejection No login needed ≤ 1.3.8 CVE-2026-1644 Wordfence
5.3 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control Missing Authorization to Unauthenticated Private Reusable Block Disclosure via 'gspb_el_reusable_load' No login needed ≤ 12.8.3 CVE-2026-2371 Wordfence
4.3 Medium Rank Math SEO PRO Plugin seo-by-rank-math-pro Broken Access Control ≤ 3.0.95 CVE-2026-28080 Patchstack
4.7 Medium B2BKing Premium Plugin b2bking Open Redirect No login needed < 5.4.20 Fixed in 5.4.20 CVE-2026-28106 Patchstack
5.9 Medium Preferred Languages Plugin preferred-languages Cross-Site Scripting ≤ 2.2.2 Fixed in 2.3.0 CVE-2024-35644 Patchstack
6.1 Medium WP All Import Plugin wp-all-import Cross-Site Scripting Reflected Cross-Site Scripting via 'filepath' No login needed ≤ 4.0.0 CVE-2026-2830 Wordfence
4.3 Medium WP eCommerce Plugin Cross-Site Request Forgery Coupon Deletion via CSRF No login needed ≤ 3.15.1 CVE-2026-1128 WPScan
5.3 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Information Disclosure animation and page builder blocks <= 12.8.3 - Unauthenticated Sensitive Information Exposure via Settings Backup No login needed ≤ 12.8.3 CVE-2026-2589 Wordfence
6.4 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting animation and page builder blocks <= 12.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 12.8.5 CVE-2026-2593 Wordfence
6.5 Medium Page and Post Clone Plugin page-or-post-clone SQL Injection Authenticated (Contributor+) SQL Injection via 'meta_key' Parameter ≤ 6.3 CVE-2026-2893 Wordfence
6.5 Medium Site Suggest Plugin site-suggest Broken Access Control No login needed ≤ 1.3.9 CVE-2026-28104 Patchstack
4.9 Medium uListing Plugin ulisting Path Traversal Arbitrary File Download ≤ 2.2.0 CVE-2026-28078 Patchstack
6.3 Medium pixfort Core Plugin pixfort-core Broken Access Control ≤ 3.2.22 Fixed in 3.2.26 CVE-2026-28071 Patchstack
6.5 Medium Ultimate Addons for WPBakery Page Builder Plugin ultimate_vc_addons Broken Access Control ≤ 3.21.1 Fixed in 3.21.2 CVE-2026-28038 Patchstack
6.4 Medium Ratatouille Plugin ratatouille Server-Side Request Forgery ≤ 1.2.6 CVE-2026-28036 Patchstack
5.4 Medium SiteGuard WP Plugin siteguard Authentication Bypass Captcha Bypass No login needed ≤ 1.7.9 Fixed in 1.7.10 CVE-2026-27411 Patchstack
6.5 Medium WP Bakery Autoresponder Addon Plugin vc-autoresponder-addon Broken Access Control No login needed ≤ 1.0.6 CVE-2026-27362 Patchstack
6.5 Medium WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Cross-Site Scripting ≤ 5.0 CVE-2026-27354 Patchstack
5.9 Medium inseri core Plugin inseri-core Broken Access Control No login needed ≤ 1.0.5 CVE-2026-27344 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2026-23799 Patchstack
6.5 Medium Classified Listing Plugin classified-listing Information Disclosure Sensitive Data Exposure ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-23546 Patchstack
6.5 Medium WordPress CTA Plugin easy-sticky-sidebar Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-22459 Patchstack
6.5 Medium Theater Plugin theatre Cross-Site Scripting ≤ 0.19 Fixed in 0.19.1 CVE-2025-69343 Patchstack
5.8 Medium WP Booking System Plugin wp-booking-system Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.19.12 Fixed in 2.0.19.13 CVE-2025-68515 Patchstack
4.3 Medium Media Library Assistant Plugin media-library-assistant Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Taxonomy Modification ≤ 3.33 CVE-2026-3072 Wordfence
4.9 Medium Apocalypse Meow Plugin apocalypse-meow SQL Injection Authenticated (Administrator+) SQL Injection via 'type' Parameter ≤ 22.1.0 CVE-2026-3523 Wordfence
6.4 Medium OoohBoi Steroids for Elementor Plugin ooohboi-steroids-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls ≤ 2.1.24 CVE-2026-3034 Wordfence
6.5 Medium Fluent Forms Pro Add On Pack Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 6.1.17 CVE-2026-2899 Wordfence
4.3 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Information Disclosure Authenticated (Subscriber+) Exposure of Sensitive Information to an Unauthorized Actor ≤ 2.28.14 CVE-2026-3058 Wordfence
4.3 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Clearing ≤ 2.28.14 CVE-2026-3056 Wordfence
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() ≤ 1.6.0 CVE-2026-1674 Wordfence
6.4 Medium My Calendar – Accessible Event Manager Plugin my-calendar Cross-Site Scripting Accessible Event Manager <= 3.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.7.3 CVE-2026-2355 Wordfence
6.1 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Cross-Site Scripting Reflected Cross-Site Scripting via 'vi' Parameter No login needed ≤ 4.7.1 CVE-2026-1706 Wordfence
6.4 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'justified_gallery_theme' Parameter via REST API ≤ 1.12.3 CVE-2026-1236 Wordfence
5.4 Medium Enable Media Replace Plugin enable-media-replace Broken Access Control Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace ≤ 4.1.7 CVE-2026-2732 Wordfence
6.5 Medium WP-Members Membership Plugin wp-members SQL Injection Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute ≤ 3.5.5.1 CVE-2026-2363 Wordfence
6.5 Medium Email Subscribers & Newsletters Plugin email-subscribers SQL Injection Authenticated (Administrator+) SQL Injection via 'workflow_ids' Parameter ≤ 5.9.16 CVE-2026-1651 Wordfence
4.4 Medium Morkva UA Shipping Plugin morkva-ua-shipping Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Weight, kg' Field ≤ 1.7.9 CVE-2026-2292 Wordfence
4.4 Medium Taskbuilder Plugin taskbuilder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Block Emails' Field ≤ 5.0.3 CVE-2026-2289 Wordfence
5.3 Medium WPBookit Plugin wpbookit Broken Access Control Missing Authorization to Unauthenticated Sensitive Customer Data Exposure No login needed ≤ 1.0.8 CVE-2026-1980 Wordfence
6.5 Medium LatePoint Plugin SQL Injection Authenticated (Administrator+) SQL Injection via JSON Import ≤ 5.2.7 CVE-2026-1487 Wordfence
5.3 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Broken Access Control Missing Authorization to Unauthenticated API Key Modification No login needed ≤ 2.7.5 CVE-2026-1336 Wordfence
6.4 Medium Blocksy Theme blocksy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `blocksy_meta` Fields ≤ 2.1.30 CVE-2026-2583 Wordfence
5.5 Medium wpForo Forum Plugin wpforo Cross-Site Scripting wpForo Forum 2.4.14 Stored XSS via Unescaped Forum Description in Templates 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28561 VulnCheck
5.5 Medium wpForo Forum Plugin wpforo Cross-Site Scripting wpForo Forum 2.4.14 Stored XSS via Unsafe JSON Encoding in Inline Script 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28560 VulnCheck
5.3 Medium wpForo Forum Plugin wpforo Information Disclosure wpForo Forum 2.4.14 Information Disclosure via Global RSS Feed No login needed 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28559 VulnCheck

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only