WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,801–3,850 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 77 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium wpForo Forum Plugin wpforo Cross-Site Scripting wpForo Forum 2.4.14 Stored XSS via SVG Avatar File Upload 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28558 VulnCheck
6.5 Medium wpForo Forum Plugin wpforo Privilege Escalation wpForo Forum < 2.4.16 Privilege Escalation via Role Synchronization Handler 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28557 VulnCheck
5.4 Medium wpForo Forum Plugin wpforo Broken Access Control wpForo Forum 2.4.14 Missing Authorization via Topic Management Form Handlers 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28556 VulnCheck
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control wpForo Forum 2.4.14 Missing Authorization via Topic Close AJAX Handler 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28555 VulnCheck
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control wpForo Forum 2.4.14 Missing Authorization via Post Approval AJAX Handler 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28554 VulnCheck
6.5 Medium Super Stage WP Plugin super-stage-wp PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.0.1 CVE-2026-1542 WPScan
5.3 Medium Featured Image from Content Plugin featured-image-from-content Server-Side Request Forgery Featured Image from Content < 1.7 Authenticated SSRF via save_post < 1.7 Fixed in 1.7 CVE-2026-27759 VulnCheck
4.9 Medium MailArchiver Plugin mailarchiver SQL Injection Authenticated (Admininistrator+) SQL Injection via 'logid' Parameter ≤ 4.5.0 CVE-2026-2831 Wordfence
5.3 Medium Japanized for WooCommerce Plugin woocommerce-for-japan Broken Access Control Missing Authorization to Unauthenticated Paidy Order Manipulation No login needed ≤ 2.8.4 CVE-2026-1305 Wordfence
6.4 Medium Electric Enquiries Plugin electric-enquiries Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button' Shortcode Attribute ≤ 1.1 CVE-2025-14142 Wordfence
6.5 Medium OVRI Payment Plugin moneytigo Other Malicious .htaccess directive No login needed 1.7.0 CVE-2024-10938 Wordfence
6.4 Medium Simple Download Monitor Plugin simple-download-monitor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field ≤ 4.0.5 CVE-2026-2383 Wordfence
6.4 Medium WP Accessibility Plugin wp-accessibility Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via 'alt' Attribute ≤ 2.3.1 CVE-2026-2362 Wordfence
6.4 Medium Xpro Addons — 140+ Widgets for Elementor Plugin xpro-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Scroller Widget box link ≤ 1.4.24 CVE-2025-14149 Wordfence
6.4 Medium Automotive Car Dealership Business Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Call to Action Fields ≤ 13.4 CVE-2025-14040 Wordfence
5.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter No login needed ≤ 10.3.2 CVE-2026-1558 Wordfence
5.3 Medium WooCommerce Photo Reviews Plugin woocommerce-photo-reviews Content Injection No login needed ≤ 1.4.4 CVE-2026-28132 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Sensitive Data Exposure ≤ 1.14.4 Fixed in 1.14.5 CVE-2026-28131 Patchstack
6.5 Medium Flatsome Plugin flatsome Cross-Site Scripting ≤ 3.20.5 Fixed in 3.20.6 CVE-2026-28083 Patchstack
5.3 Medium User Registration & Membership Plugin user-registration Broken Access Control Insecure Direct Object Reference to Unauthenticated Limited User Deletion No login needed ≤ 5.1.2 CVE-2026-2356 Wordfence
4.4 Medium Custom Logo Plugin custom-logo Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Logo Path Setting ≤ 2.2 CVE-2026-2499 Wordfence
6.4 Medium Livemesh Addons for Beaver Builder Plugin addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes ≤ 3.9.2 CVE-2026-2029 Wordfence
4.4 Medium WP Social Meta Plugin wp-social-meta Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings ≤ 1.0.1 CVE-2026-2498 Wordfence
4.4 Medium TP2WP Importer Plugin tp2wp-importer Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Watched domains' Textarea ≤ 1.1 CVE-2026-2489 Wordfence
6.1 Medium EM Cost Calculator Plugin cost-calculator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'customer_name' No login needed ≤ 2.3.1 CVE-2026-2506 Wordfence
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API ≤ 6.15.16 CVE-2026-2694 Wordfence
6.4 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute ≤ 5.0.1 CVE-2026-2367 Wordfence
4.3 Medium Post Duplicator Plugin post-duplicator Broken Access Control Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter ≤ 3.0.8 CVE-2026-2301 Wordfence
4.3 Medium Disable Admin Notices – Hide Dashboard Notifications Plugin disable-admin-notices Cross-Site Request Forgery Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.4.2 CVE-2026-2410 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 10.2.3 CVE-2025-14742 Wordfence
5.0 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload ≤ 2.7.1 CVE-2026-2479 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes ≤ 3.7 CVE-2026-1614 Wordfence
5.3 Medium Simple Ajax Chat Plugin simple-ajax-chat Information Disclosure Sensitive Data Exposure No login needed ≤ 20251121 Fixed in 20260217 CVE-2026-3075 Patchstack
5.1 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Cross-Site Request Forgery Aruba HiSpeed Cache < 3.0.5 CSRF in Multiple Administrative AJAX Actions No login needed < 3.0.5 Fixed in 3.0.5 CVE-2026-23694 VulnCheck
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
4.3 Medium Conditional CAPTCHA Plugin Open Redirect No login needed ≤ 4.0.0 CVE-2026-1369 WPScan
4.8 Medium LearnPress Export Import Plugin learnpress-import-export Broken Access Control Missing Authentication to Unauthenticated Migrated Course Deletion No login needed ≤ 4.1.0 CVE-2026-1787 Wordfence
6.5 Medium weMail Plugin wemail Broken Access Control Missing Authorization to Unauthenticated Form Deletion No login needed ≤ 2.0.7 CVE-2025-14339 Wordfence
6.5 Medium Simple File List Plugin simple-file-list Path Traversal Arbitrary File Download ≤ 6.1.15 Fixed in 6.1.16 CVE-2026-24953 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.9.0 CVE-2026-24946 Patchstack
6.5 Medium Subscribe2 Plugin subscribe2 Broken Access Control No login needed ≤ 10.44 Fixed in 10.45 CVE-2026-24944 Patchstack
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 6.3.1 Fixed in 6.5.0 CVE-2026-22350 Patchstack
6.7 Medium Booked Plugin booked Privilege Escalation Account Takeover ≤ 3.0.0 CVE-2026-22341 Patchstack
6.5 Medium Cliengo – Chatbot Plugin cliengo Broken Access Control Chatbot plugin <= 3.0.4 - Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-69388 Patchstack
6.5 Medium Cartify - WooCommerce Gutenberg Theme cartify Broken Access Control WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion ≤ 1.3 CVE-2025-69385 Patchstack
5.3 Medium Primer MyData for Woocommerce Plugin primer-mydata Path Traversal No login needed ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-69325 Patchstack
6.5 Medium Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting ≤ 2.29 CVE-2025-69011 Patchstack
6.5 Medium AhaChat Messenger Marketing Plugin ahachat-messenger-marketing Authentication Bypass Broken Authentication No login needed ≤ 1.1 CVE-2025-68895 Patchstack
5.9 Medium JobBoard Job listing Plugin job-board-light Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.8 CVE-2025-68855 Patchstack
6.5 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control ≤ 3.3.5 Fixed in 3.3.6 CVE-2025-68837 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only