WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 3,851–3,900 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 78 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Livemesh Addons for Beaver Builder Plugin addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' and 'value' Shortcode Attributes ≤ 3.9.2 CVE-2026-2029 Wordfence
4.4 Medium WP Social Meta Plugin wp-social-meta Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings ≤ 1.0.1 CVE-2026-2498 Wordfence
4.4 Medium TP2WP Importer Plugin tp2wp-importer Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Watched domains' Textarea ≤ 1.1 CVE-2026-2489 Wordfence
6.1 Medium EM Cost Calculator Plugin cost-calculator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'customer_name' No login needed ≤ 2.3.1 CVE-2026-2506 Wordfence
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Improper Authorization to Authenticated (Contributor+) Event/Organizer/Venue Update/Trash via REST API ≤ 6.15.16 CVE-2026-2694 Wordfence
6.4 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute ≤ 5.0.1 CVE-2026-2367 Wordfence
4.3 Medium Post Duplicator Plugin post-duplicator Broken Access Control Missing Authorization to Authenticated (Contributor+) Protected Post Meta Insertion via 'customMetaData' Parameter ≤ 3.0.8 CVE-2026-2301 Wordfence
4.3 Medium Disable Admin Notices – Hide Dashboard Notifications Plugin disable-admin-notices Cross-Site Request Forgery Hide Dashboard Notifications <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.4.2 CVE-2026-2410 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 10.2.3 CVE-2025-14742 Wordfence
5.0 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via Remote Library Image Upload ≤ 2.7.1 CVE-2026-2479 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Identity Block Attributes ≤ 3.7 CVE-2026-1614 Wordfence
5.3 Medium Simple Ajax Chat Plugin simple-ajax-chat Information Disclosure Sensitive Data Exposure No login needed ≤ 20251121 Fixed in 20260217 CVE-2026-3075 Patchstack
5.1 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Cross-Site Request Forgery Aruba HiSpeed Cache < 3.0.5 CSRF in Multiple Administrative AJAX Actions No login needed < 3.0.5 Fixed in 3.0.5 CVE-2026-23694 VulnCheck
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
4.3 Medium Conditional CAPTCHA Plugin Open Redirect No login needed ≤ 4.0.0 CVE-2026-1369 WPScan
4.8 Medium LearnPress Export Import Plugin learnpress-import-export Broken Access Control Missing Authentication to Unauthenticated Migrated Course Deletion No login needed ≤ 4.1.0 CVE-2026-1787 Wordfence
6.5 Medium weMail Plugin wemail Broken Access Control Missing Authorization to Unauthenticated Form Deletion No login needed ≤ 2.0.7 CVE-2025-14339 Wordfence
6.5 Medium Simple File List Plugin simple-file-list Path Traversal Arbitrary File Download ≤ 6.1.15 Fixed in 6.1.16 CVE-2026-24953 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.9.0 CVE-2026-24946 Patchstack
6.5 Medium Subscribe2 Plugin subscribe2 Broken Access Control No login needed ≤ 10.44 Fixed in 10.45 CVE-2026-24944 Patchstack
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Broken Access Control ≤ 6.3.1 Fixed in 6.5.0 CVE-2026-22350 Patchstack
6.7 Medium Booked Plugin booked Privilege Escalation Account Takeover ≤ 3.0.0 CVE-2026-22341 Patchstack
6.5 Medium Cliengo – Chatbot Plugin cliengo Broken Access Control Chatbot plugin <= 3.0.4 - Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-69388 Patchstack
6.5 Medium Cartify - WooCommerce Gutenberg Theme cartify Broken Access Control WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion ≤ 1.3 CVE-2025-69385 Patchstack
5.3 Medium Primer MyData for Woocommerce Plugin primer-mydata Path Traversal No login needed ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-69325 Patchstack
6.5 Medium Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting ≤ 2.29 CVE-2025-69011 Patchstack
6.5 Medium AhaChat Messenger Marketing Plugin ahachat-messenger-marketing Authentication Bypass Broken Authentication No login needed ≤ 1.1 CVE-2025-68895 Patchstack
5.9 Medium JobBoard Job listing Plugin job-board-light Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.8 CVE-2025-68855 Patchstack
6.5 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control ≤ 3.3.5 Fixed in 3.3.6 CVE-2025-68837 Patchstack
6.5 Medium Sendy Plugin sendy Broken Access Control No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2025-68564 Patchstack
6.5 Medium Checkout Gateway for IRIS Plugin checkout-gateway-iris Broken Access Control No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-68542 Patchstack
6.5 Medium PDF for WPForms Plugin pdf-for-wpforms Broken Access Control ≤ 6.3.0 Fixed in 6.3.1 CVE-2025-68534 Patchstack
6.5 Medium Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.16.8 Fixed in 2.16.9 CVE-2025-68514 Patchstack
6.5 Medium Leadpages Plugin leadpages Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-68050 Patchstack
6.5 Medium Travelpayouts Plugin travelpayouts Broken Access Control ≤ 1.2.2 CVE-2025-68042 Patchstack
6.5 Medium Advanced WC Analytics Plugin advance-wc-analytics Broken Access Control Settings Change No login needed ≤ 3.19.0 Fixed in 4.0.0 CVE-2025-68032 Patchstack
6.5 Medium GA4WP: Google Analytics Plugin ga-for-wp Broken Access Control No login needed ≤ 2.10.0 CVE-2025-68028 Patchstack
6.5 Medium LC Wizard Plugin ghl-wizard Broken Access Control Settings Change No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-68026 Patchstack
6.5 Medium Addonify Floating Cart For WooCommerce Plugin addonify-floating-cart Broken Access Control No login needed ≤ 1.2.17 CVE-2025-68025 Patchstack
6.5 Medium Addonify – WooCommerce Wishlist Plugin addonify-wishlist Broken Access Control WooCommerce Wishlist plugin <= 2.0.15 - Settings Change No login needed ≤ 2.0.15 Fixed in 2.0.16 CVE-2025-68024 Patchstack
6.5 Medium Addonify – Compare Products For WooCommerce Plugin addonify-compare-products Broken Access Control Compare Products For WooCommerce plugin <= 1.1.17 - Settings Change No login needed ≤ 1.1.17 Fixed in 1.1.18 CVE-2025-68023 Patchstack
6.5 Medium ConveyThis Plugin conveythis-translate Broken Access Control No login needed ≤ 269.9 CVE-2025-68021 Patchstack
6.5 Medium Easy Hotel Booking Plugin easy-hotel Broken Access Control ≤ 1.9.2 CVE-2025-68005 Patchstack
6.5 Medium Open User Map Plugin open-user-map Path Traversal Arbitrary File Download ≤ 1.4.16 Fixed in 1.4.17 CVE-2025-68002 Patchstack
6.5 Medium Testimonial Slider Plugin testimonial Broken Access Control ≤ 2.0.15 CVE-2025-68000 Patchstack
6.5 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-67993 Patchstack
6.5 Medium aDirectory Plugin adirectory Broken Access Control ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67975 Patchstack
6.5 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.5.6.2 Fixed in 3.5.7.1 CVE-2025-67973 Patchstack
4.3 Medium Zoho ZeptoMail Plugin transmail Broken Access Control ≤ 3.2.9 Fixed in 3.3.0 CVE-2025-67972 Patchstack
5.9 Medium Schedula Plugin schedula-smart-appointment-booking Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-67970 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only