WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 3,901–3,950 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 79 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Advanced Forms Plugin advanced-forms Broken Access Control No login needed ≤ 1.9.3.7 Fixed in 1.9.3.8 CVE-2026-57378 Patchstack
6.5 Medium WowAddons Plugin product-addons Broken Access Control No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2026-57377 Patchstack
7.1 High ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2026-57376 Patchstack
6.5 Medium MStore API Plugin mstore-api Broken Access Control No login needed ≤ 4.18.4 Fixed in 4.19.0 CVE-2026-57375 Patchstack
7.2 High WPJAM Basic Plugin wpjam-basic Server-Side Request Forgery No login needed ≤ 7.0 Fixed in 7.0.1 CVE-2026-57372 Patchstack
8.8 High WPJAM Basic Plugin wpjam-basic PHP Object Injection ≤ 7.0 Fixed in 7.0.1 CVE-2026-57371 Patchstack
7.1 High Themify Builder Plugin themify-builder Cross-Site Scripting No login needed ≤ 7.7.4 Fixed in 7.7.5 CVE-2026-57369 Patchstack
7.1 High Jobmonster Theme noo-jobmonster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.8.5 Fixed in 4.8.5.1 CVE-2026-57368 Patchstack
6.5 Medium reCAPTCHA (v2 & v3) for Asgaros Forum Plugin recaptcha-for-asgaros-forum Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57365 Patchstack
6.5 Medium Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More Plugin better-payment Other Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-57364 Patchstack
7.1 High ChatBot Plugin chatbot Cross-Site Scripting No login needed ≤ 8.3.7 Fixed in 8.3.8 CVE-2026-57363 Patchstack
8.6 High Library Management System Plugin library-management-system SQL Injection Unauthenticated SQL Injection via book_id No login needed 3.5 – < 3.5.8 Fixed in 3.5.8 CVE-2026-12582 WPScan
4.3 Medium WP Job Portal Plugin wp-job-portal Information Disclosure Subscriber+ Employer Email Disclosure via IDOR < 2.5.5 Fixed in 2.5.5 CVE-2026-12397 WPScan
5.4 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Subscriber+ Arbitrary Job Approval, Featuring and Rejection < 2.5.5 Fixed in 2.5.5 CVE-2026-12396 WPScan
7.1 High Tutor LMS Plugin tutor Broken Access Control Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration < 3.9.13 Fixed in 3.9.13 CVE-2026-12275 WPScan
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Instructor+ Arbitrary Post Overwrite via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12274 WPScan
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Subscriber+ Arbitrary Auto-Approved Comment Creation < 3.9.13 Fixed in 3.9.13 CVE-2026-12273 WPScan
5.4 Medium Tutor LMS Plugin tutor Broken Access Control Subscriber+ Arbitrary Quiz Attempt Modification via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12271 WPScan
5.0 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries PHP Object Injection Unauthenticated PHP Object Injection via Entry File Field No login needed < 1.5.2 Fixed in 1.5.2 CVE-2026-12081 WPScan
9.1 Critical User Registration & Membership Plugin user-registration Authentication Bypass Unauthenticated PayPal Webhook Signature Verification Bypass Leading to Membership Activation No login needed < 5.2.2 Fixed in 5.2.2 CVE-2026-11964 WPScan
8.1 High User Registration & Membership Plugin user-registration Broken Access Control Subscriber+ Cross-User Role and Membership Tier Modification via IDOR < 5.2.2 Fixed in 5.2.2 CVE-2026-11963 WPScan
6.1 Medium Breeze Cache Plugin breeze Cross-Site Scripting Unauthenticated Stored XSS via Minify Library No login needed < 2.5.6 Fixed in 2.5.6 CVE-2026-10551 WPScan
8.8 High Genolve – AI image AI video generation Plugin Broken Access Control AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt ≤ 5.0.5 CVE-2026-1359 Wordfence
6.4 Medium bbp style pack Plugin bbp-style-pack Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields ≤ 6.4.5 CVE-2026-15010 Wordfence
7.5 High W3 Total Cache Plugin w3-total-cache Path Traversal Unauthenticated Arbitrary File Read via 'f_array[]' Parameter No login needed ≤ 2.9.4 CVE-2026-9282 Wordfence
5.3 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action No login needed ≤ 9.2.2 CVE-2026-9017 Wordfence
4.3 Medium WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers ≤ 6.7.27 CVE-2026-10041 Wordfence
7.2 High CorvusPay WooCommerce Payment Gateway Plugin corvuspay-woocommerce-integration Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter No login needed ≤ 2.7.4 CVE-2026-6939 Wordfence
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Authenticated (Contributor+) Account Takeover via Email Header Injection ≤ 6.6.10 CVE-2026-15155 Wordfence
4.3 Medium Wallet for WooCommerce Plugin woo-wallet Broken Access Control Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action ≤ 1.6.4 CVE-2026-12103 Wordfence
5.3 Medium WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller No login needed ≤ 6.7.27 CVE-2026-12994 Wordfence
6.4 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title' ≤ 3.7.3 CVE-2026-12126 Wordfence
7.5 High WP CTA Plugin easy-sticky-sidebar SQL Injection Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter No login needed ≤ 2.2.2 CVE-2026-4661 Wordfence
4.4 Medium Widgets for Google Reviews Plugin wp-reviews-plugin-for-google Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters ≤ 13.3 CVE-2026-11591 Wordfence
6.4 Medium fresh Podcaster Plugin fresh-podcaster Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes ≤ 1.0.7 CVE-2026-1382 Wordfence
4.9 Medium Catalyst Connect Zoho CRM Client Portal Plugin catalyst-connect-client-portal SQL Injection Authenticated (Administrator+) SQL Injection via uid Parameter ≤ 2.2.0 CVE-2025-5017 Wordfence
4.3 Medium WP Easy Pay Plugin wp-easy-pay Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action ≤ 4.5.0 CVE-2026-12738 Wordfence
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Information Disclosure Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys No login needed ≤ 4.0.11 CVE-2026-10865 Wordfence
5.3 Medium Context Blog Theme context-blog Information Disclosure Unauthenticated Sensitive Information Exposure via 'postID' Parameter No login needed ≤ 1.3.5 CVE-2026-6801 Wordfence
4.4 Medium White Label CMS Plugin white-label-cms Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings ≤ 2.7.12 CVE-2026-11898 Wordfence
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Price Manipulation Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler No login needed ≤ 2.3.1 CVE-2026-11901 Wordfence
8.8 High Code Engine Plugin code-engine Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 0.3.5 CVE-2025-6784 Wordfence
8.1 High SureCart Plugin surecart Privilege Escalation Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook No login needed ≤ 4.2.3 CVE-2026-7655 Wordfence
7.2 High Form Vibes Plugin form-vibes Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field No login needed ≤ 1.5.2 CVE-2026-13378 Wordfence
8.8 High Simple JWT Login Plugin simple-jwt-login Authentication Bypass Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter ≤ 3.6.6 CVE-2026-14262 Wordfence
5.3 Medium AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions No login needed ≤ 1.4.12 CVE-2026-6804 Wordfence
4.3 Medium ThriveDesk Plugin thrivedesk Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cache Deletion ≤ 2.1.7 CVE-2026-1832 Wordfence
7.5 High Booking Package Plugin booking-package SQL Injection Unauthenticated SQL Injection via 'email' Form Parameter No login needed ≤ 1.7.20 CVE-2026-15335 Wordfence
5.3 Medium Solace Extra Plugin solace-extra Broken Access Control Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action No login needed ≤ 1.5.3 CVE-2026-13250 Wordfence
4.9 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter ≤ 4.11.84 CVE-2026-12141 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only