WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,851–3,900 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 78 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Authentication Bypass Broken Authentication No login needed ≤ 5.9.9.6 Fixed in 5.9.9.7 CVE-2026-57697 Patchstack
7.1 High Document Gallery Plugin document-gallery Cross-Site Scripting No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2026-57695 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.13 Fixed in 3.9.14 CVE-2026-57694 Patchstack
6.5 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting ≤ 2.8.11 Fixed in 2.8.12 CVE-2026-57693 Patchstack
5.8 Medium Anti-Malware Security and Brute-Force Firewall Plugin gotmls Cross-Site Scripting No login needed ≤ 4.23.89 Fixed in 4.23.90 CVE-2026-57691 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting No login needed ≤ 9.2.2 Fixed in 9.2.3 CVE-2026-57668 Patchstack
6.5 Medium Razorpay Payment Links for WooCommerce Plugin rzp-woocommerce Broken Access Control No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57424 Patchstack
7.1 High Message Filter for Contact Form 7 Plugin cf7-message-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3.8 Fixed in 1.6.3.9 CVE-2026-57423 Patchstack
7.1 High Bopo – WooCommerce Product Bundle Builder Plugin bopo-woo-product-bundle-builder Cross-Site Scripting WooCommerce Product Bundle Builder plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-57422 Patchstack
7.1 High CRM Perks Forms Plugin crm-perks-forms Cross-Site Scripting No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2026-57421 Patchstack
6.5 Medium Author Box WP Lens Plugin author-box-for-divi Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-57420 Patchstack
6.5 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 3.1.8 Fixed in 3.1.9 CVE-2026-57419 Patchstack
6.5 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control ≤ 20.8.13 Fixed in 20.8.14 CVE-2026-57418 Patchstack
7.1 High Cart Lift Plugin cart-lift Cross-Site Scripting No login needed ≤ 3.1.57 Fixed in 3.1.58 CVE-2026-57417 Patchstack
7.1 High SiteGround Email Marketing Plugin siteground-email-marketing Cross-Site Scripting No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2026-57416 Patchstack
7.1 High Gift Vouchers Plugin gift-voucher Cross-Site Scripting No login needed ≤ 4.7.0 Fixed in 4.7.1 CVE-2026-57415 Patchstack
6.5 Medium ChatBot for eCommerce – WoowBot Plugin woowbot-woocommerce-chatbot Cross-Site Scripting WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) ≤ 4.6.1 Fixed in 4.7.0 CVE-2026-57414 Patchstack
6.4 Medium Instant Image Generator Plugin ai-image Server-Side Request Forgery ≤ 2.1.4 Fixed in 2.1.5 CVE-2026-57413 Patchstack
6.5 Medium Gift Vouchers Plugin gift-voucher Broken Access Control No login needed ≤ 4.6.9 Fixed in 4.7.0 CVE-2026-57412 Patchstack
7.1 High CF7 Views – Complete Entry Management for Contact Form 7 Plugin cf7-views Cross-Site Scripting Complete Entry Management for Contact Form 7 plugin <= 3.2.2 - Cross Site Scripting (XSS) No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2026-57411 Patchstack
8.8 High MailerPress Plugin mailerpress Privilege Escalation ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-57410 Patchstack
7.1 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57409 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2026-57408 Patchstack
7.2 High PDF Generator Plugin pdf-generator-for-wp Server-Side Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-57407 Patchstack
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-57406 Patchstack
7.1 High Open Shop Plugin open-shop Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2026-57405 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2026-57404 Patchstack
7.1 High GD Security Headers Plugin gd-security-headers Cross-Site Scripting No login needed ≤ 1.8 Fixed in 1.9 CVE-2026-57403 Patchstack
6.5 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Cross-Site Scripting ≤ 1.0.51 Fixed in 1.0.52 CVE-2026-57402 Patchstack
9.9 Critical SureDash Plugin suredash Arbitrary File Deletion ≤ 1.8.0 Fixed in 1.8.1 CVE-2026-57401 Patchstack
6.5 Medium Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-57400 Patchstack
7.1 High Proxy & VPN Blocker Plugin proxy-vpn-blocker Cross-Site Scripting No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2026-57399 Patchstack
7.1 High Real Estate Manager Pro Plugin real-estate-manager-pro Cross-Site Scripting No login needed ≤ 12.8.3 Fixed in 12.8.4 CVE-2026-57398 Patchstack
7.1 High Free Gifts for WooCommerce Plugin free-gifts-for-woocommerce Cross-Site Scripting No login needed ≤ 13.1.0 Fixed in 13.3.0 CVE-2026-57396 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57395 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting No login needed ≤ 4.14 Fixed in 4.15 CVE-2026-57394 Patchstack
6.5 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Information Disclosure Sensitive Data Exposure ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-57393 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control No login needed ≤ 2.22.5 Fixed in 2.22.6 CVE-2026-57392 Patchstack
6.5 Medium Loops & Logic Plugin tangible-loops-and-logic Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2026-57391 Patchstack
6.5 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Broken Access Control No login needed ≤ 1.2.167 Fixed in 1.2.168 CVE-2026-57390 Patchstack
8.6 High Groundhogg Plugin groundhogg Arbitrary File Deletion No login needed ≤ 4.4.1 Fixed in 4.5 CVE-2026-57389 Patchstack
7.1 High Hydra Booking Plugin hydra-booking Cross-Site Scripting No login needed ≤ 1.1.44 Fixed in 1.1.45 CVE-2026-57388 Patchstack
7.1 High picu Plugin picu Cross-Site Scripting No login needed ≤ 3.5.1 Fixed in 3.6.1 CVE-2026-57387 Patchstack
8.8 High aBlocks Plugin ablocks Privilege Escalation ≤ 2.9.1 Fixed in 2.9.1 CVE-2026-57386 Patchstack
8.5 High Vitepos Plugin vitepos-lite SQL Injection ≤ 3.4.2 Fixed in 3.4.3 CVE-2026-57385 Patchstack
7.1 High JobSearch Plugin wp-jobsearch Cross-Site Scripting No login needed ≤ 3.2.9 Fixed in 3.3.0 CVE-2026-57383 Patchstack
7.1 High Simple File List Plugin simple-file-list Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.3.8 Fixed in 6.3.9 CVE-2026-57382 Patchstack
7.1 High PropertyHive Plugin propertyhive Cross-Site Scripting No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2026-57381 Patchstack
7.1 High Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting No login needed ≤ 5.1 Fixed in 5.2 CVE-2026-57380 Patchstack
7.1 High FormyChat Plugin social-contact-form Cross-Site Scripting No login needed ≤ 2.15.3 Fixed in 2.15.4 CVE-2026-57379 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only