WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 351–400 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Easy Invoice Plugin easy-invoice Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.4.0 CVE-2026-66676 Patchstack
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.9.21 Fixed in 2.0.0 CVE-2026-66631 Patchstack
7.6 High PublishPress Series Plugin organize-series SQL Injection ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-66630 Patchstack
7.6 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay SQL Injection ≤ 3.8.11 Fixed in 3.8.12 CVE-2026-66628 Patchstack
7.6 High SKT Addons for Elementor Plugin skt-addons-for-elementor SQL Injection ≤ 4.0 Fixed in 4.1 CVE-2026-66626 Patchstack
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.7.2.1 Fixed in 2.7.2.2 CVE-2026-66625 Patchstack
7.6 High WPMasterToolKit Plugin wpmastertoolkit SQL Injection ≤ 2.22.0 Fixed in 2.23.1 CVE-2026-66624 Patchstack
7.6 High Newsletters Plugin newsletters-lite SQL Injection ≤ 4.18 Fixed in 4.18.1 CVE-2026-66619 Patchstack
7.6 High WP Maps Plugin wp-google-map-plugin SQL Injection ≤ 4.9.9 Fixed in 5.0.0 CVE-2026-66618 Patchstack
6.5 Medium PublishPress Series Plugin organize-series Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-66617 Patchstack
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Server-Side Request Forgery ≤ 2.0.19 Fixed in 2.0.20 CVE-2026-66608 Patchstack
8.5 High Product Feed Manager Plugin best-woocommerce-feed SQL Injection ≤ 7.12.0 Fixed in 7.12.1 CVE-2026-66580 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.9.2.1 Fixed in 2.9.2.2 CVE-2026-66579 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.2.6 Fixed in 2.3.0 CVE-2026-66578 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.6.3 Fixed in 3.6.3.1 CVE-2026-66577 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.2.1 CVE-2026-66576 Patchstack
5.3 Medium King Addons for Elementor Plugin king-addons Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 51.1.81 Fixed in 51.1.82 CVE-2026-66575 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 8.8.3 Fixed in 8.8.4 CVE-2026-66574 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.3.3.1 Fixed in 2.3.3.2 CVE-2026-66573 Patchstack
6.5 Medium JetBlog Plugin jet-blog Cross-Site Scripting ≤ 2.4.10 Fixed in 2.4.10.1 CVE-2026-66572 Patchstack
7.1 High Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Cross-Site Request Forgery No login needed ≤ 1.4.0.5 Fixed in 1.4.0.6 CVE-2026-66571 Patchstack
9.8 Critical Headless Single Sign On Plugin headless-single-sign-on Authentication Bypass Broken Authentication No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2026-62108 Patchstack
10.0 Critical Migratico Lite Plugin migratico-lite Remote Code Execution No login needed ≤ 2.6.8 Fixed in 2.7.1 CVE-2026-62104 Patchstack
9.8 Critical EduAdmin Booking Plugin eduadmin-booking Authentication Bypass Broken Authentication No login needed ≤ 5.4.2 Fixed in 6.0.0 CVE-2026-62101 Patchstack
7.1 High Visitor Traffic Real Time Statistics Pro Plugin visitors-traffic-real-time-statistics-pro Cross-Site Scripting No login needed ≤ 11.21 Fixed in 11.22 CVE-2026-90986 Patchstack
5.3 Medium FluentAuth Plugin fluent-security Other Email Verification Bypass No login needed ≤ 2.1.2 Fixed in 3.0.0 CVE-2026-78296 Patchstack
5.4 Medium Blog2Social Plugin blog2social Broken Access Control Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_move_post < 9.1.0 Fixed in 9.1.0 CVE-2026-89031 VulnCheck
4.3 Medium Blog2Social Plugin blog2social Information Disclosure Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user < 9.1.0 Fixed in 9.1.0 CVE-2026-89030 VulnCheck
4.3 Medium Blog2Social Plugin blog2social Broken Access Control Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler < 9.1.0 Fixed in 9.1.0 CVE-2026-89029 VulnCheck
7.6 High WP Mega Menu Plugin wp-megamenu SQL Injection ≤ 1.4.2 CVE-2026-92465 Patchstack
6.1 Medium Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots Plugin bp-better-messages Cross-Site Scripting Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress <= 2.15.22 - Reflected Cross-Site Scripting via 'icn' Parameter No login needed ≤ 2.15.22 CVE-2026-18555 Wordfence
5.1 Medium design-scuole-wordpress-theme Theme Content Injection HTML injection allows open redirection in WordPress theme design-scuole-wordpress-theme 1.0 – 2.17.3 CVE-2026-89307 ENISA
5.1 Medium design-scuole-wordpress-theme Theme Cross-Site Scripting Reflected XSS in WordPress theme design-scuole-wordpress-theme No login needed 1.0 – 2.18.2 CVE-2026-87793 ENISA
8.7 High design-scuole-wordpress-theme Theme Broken Access Control Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme No login needed 1.0 – 2.17.3 CVE-2026-87792 ENISA
8.7 High design-scuole-wordpress-theme Theme Path Traversal Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme No login needed 2.6.0 – 2.18.1 CVE-2026-87791 ENISA
6.4 Medium Bridge - Creative Multipurpose Theme Cross-Site Scripting Creative Multipurpose WordPress Theme <= 30.8.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'circle_line' Shortcode Attribute ≤ 30.8.9.1 CVE-2026-15609 Wordfence
8.8 High Consulting - Business, Finance Theme Privilege Escalation Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX ≤ 6.7.16 CVE-2026-14805 Wordfence
4.2 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR < 4.7.12 Fixed in 4.7.12 CVE-2026-88912 WPScan
7.5 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Unauthenticated SQL Injection via 'compare' Parameter No login needed ≤ 4.7.11 CVE-2026-16482 Wordfence
7.2 High Amelia Plugin Privilege Escalation Amelia Manager+ WordPress Account Takeover < 2.4.10 Fixed in 2.4.10 CVE-2026-77705 WPScan
5.3 Medium ElasticPress Plugin elasticpress Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.4 Fixed in 5.3.5 CVE-2026-62088 Patchstack
7.1 High Master Addons for Elementor Plugin master-addons Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2026-62089 Patchstack
4.3 Medium Site Kit by Google Plugin google-site-kit Cross-Site Request Forgery No login needed ≤ 1.186.0 Fixed in 1.187.0 CVE-2026-62139 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.16.1 Fixed in 45.16.2 CVE-2026-62138 Patchstack
5.3 Medium bbPress Plugin bbpress Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.14 Fixed in 2.6.15 CVE-2026-62137 Patchstack
5.3 Medium Flexible Quantity – Measurement Price Calculator for WooCommerce Plugin flexible-quantity-measurement-price-calculator-for-woocommerce Broken Access Control Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control No login needed ≤ 2.3.21 Fixed in 2.3.22 CVE-2026-62136 Patchstack
5.3 Medium Booktics Plugin booktics Broken Access Control No login needed ≤ 1.0.24 Fixed in 1.0.25 CVE-2026-62135 Patchstack
4.3 Medium Starter Templates Plugin astra-sites Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.7.5 Fixed in 4.7.6 CVE-2026-62134 Patchstack
5.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Request Forgery No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-62133 Patchstack
5.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control LMS plugin <= 3.4.0 - Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62132 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only