WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 351–400 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.6 Critical Gravity Forms Plugin gravityforms Arbitrary File Deletion No login needed ≤ 2.10.0.1 Fixed in 2.10.1 CVE-2026-48866 Patchstack
9.8 Critical AIWU Plugin ai-copilot-content-generator Privilege Escalation No login needed ≤ 1.4.17 Fixed in 1.4.19 CVE-2026-48879 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-42761 Patchstack
9.8 Critical WebinarIgnition Plugin webinar-ignition Privilege Escalation No login needed ≤ 4.08.253 Fixed in 4.08.253 CVE-2026-42758 Patchstack
9.9 Critical WebinarIgnition Plugin webinar-ignition Arbitrary File Deletion ≤ 4.08.253 Fixed in 4.08.253 CVE-2026-42757 Patchstack
9.9 Critical QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly Plugin quickwebp Arbitrary File Deletion Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion ≤ 3.2.7 Fixed in 3.2.8 CVE-2026-42756 Patchstack
9.3 Critical TableOn Plugin posts-table-filterable SQL Injection No login needed ≤ 1.0.5.1 Fixed in 1.0.6 CVE-2026-42755 Patchstack
9.9 Critical WPify Woo Czech Plugin wpify-woo Arbitrary File Upload ≤ 5.4.1 Fixed in 5.4.2 CVE-2026-42748 Patchstack
9.3 Critical Easy Form Builder Plugin easy-form-builder SQL Injection No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2026-42747 Patchstack
9.3 Critical Tainacan Plugin tainacan SQL Injection No login needed ≤ 1.0.3 Fixed in 1.1.0 CVE-2026-42740 Patchstack
9.8 Critical miniorange otp verification Plugin miniorange-otp-verification Privilege Escalation No login needed ≤ 5.4.9 Fixed in 5.5.0 CVE-2026-42731 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2026-42727 Patchstack
9.3 Critical eMagicOne Store Manager Plugin store-manager-connector SQL Injection No login needed ≤ 1.3.2 CVE-2026-42773 Patchstack
9.3 Critical JetEngine Plugin jet-engine SQL Injection No login needed ≤ 3.8.8.1 Fixed in 3.8.8.2 CVE-2026-42774 Patchstack
9.3 Critical WP Directory Kit Plugin wpdirectorykit SQL Injection No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2026-39531 Patchstack
10.0 Critical Gift Cards For WooCommerce Pro Plugin giftware Arbitrary File Upload No login needed ≤ 4.2.6 Fixed in 4.2.7 CVE-2026-45444 Patchstack
9.8 Critical Peugeot Music Plugin Arbitrary File Upload WordPress Plugin Peugeot Music 1.0 Arbitrary File Upload No login needed 1.0 CVE-2018-25335 VulnCheck
9.8 Critical WP Super Edit Plugin wp-super-edit Arbitrary File Upload WordPress Plugin WP Super Edit 2.5.4 Unrestricted File Upload No login needed ≤ 2.5.4 CVE-2021-47965 VulnCheck
9.8 Critical Download From Files Plugin download-from-files Arbitrary File Upload WordPress Download From Files 1.48 Arbitrary File Upload No login needed ≤ 1.48 CVE-2021-47940 VulnCheck
9.8 Critical MStore API Plugin mstore-api Arbitrary File Upload WordPress MStore API 2.0.6 Arbitrary File Upload No login needed 2.0.6 CVE-2021-47933 VulnCheck
9.3 Critical WebinarIgnition Plugin webinar-ignition SQL Injection No login needed ≤ 4.08.253 CVE-2026-40797 Patchstack
9.8 Critical Directorist Social Login Plugin directorist-social-login Privilege Escalation No login needed < 2.1.4 Fixed in 2.1.4 CVE-2026-22337 Patchstack
9.3 Critical Directorist Booking Plugin directorist-booking SQL Injection No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-22336 Patchstack
9.9 Critical FunnelFormsPro Plugin funnelforms-pro Remote Code Execution ≤ 3.8.1 CVE-2026-39440 Patchstack
9.8 Critical Sendmachine Plugin sendmachine Privilege Escalation Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests No login needed ≤ 1.0.20 CVE-2026-6235 Wordfence
9.6 Critical Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Remote Code Execution No login needed ≤ 3.2 CVE-2026-39640 Patchstack
9.6 Critical Appointment Plugin appointment Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 3.5.5 CVE-2026-39620 Patchstack
9.6 Critical Busiprof Plugin busiprof Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2026-39619 Patchstack
9.6 Critical Bluestreet Plugin bluestreet Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary Plugin Installation No login needed ≤ 1.7.3 CVE-2026-39617 Patchstack
9.1 Critical Nelio AB Testing Plugin nelio-ab-testing Remote Code Execution ≤ <= 8.2.7 Fixed in 8.2.8 CVE-2026-32573 Patchstack
9.3 Critical PublishPress Revisions Plugin revisionary SQL Injection No login needed ≤ <= 3.7.23 Fixed in 3.7.24 CVE-2026-32539 Patchstack
9.9 Critical Green Downloads Plugin halfdata-paypal-green-downloads Arbitrary File Upload ≤ <= 2.08 Fixed in 2.09 CVE-2026-32536 Patchstack
9.9 Critical JetFormBuilder Plugin jetformbuilder Remote Code Execution ≤ <= 3.5.6.1 Fixed in 3.5.6.2 CVE-2026-32525 Patchstack
9.1 Critical Photo Engine Plugin wplr-sync Arbitrary File Upload ≤ <= 6.4.9 Fixed in 6.5.0 CVE-2026-32524 Patchstack
9.9 Critical WPJAM Basic Plugin wpjam-basic Arbitrary File Upload ≤ <= 6.9.2 Fixed in 6.9.2.1 CVE-2026-32523 Patchstack
9.8 Critical RewardsWP Plugin rewardswp Privilege Escalation No login needed ≤ <= 1.0.4 Fixed in 1.0.5 CVE-2026-32520 Patchstack
9.0 Critical Bit SMTP Plugin bit-smtp Authentication Bypass Broken Authentication No login needed ≤ <= 1.2.2 Fixed in 1.2.3 CVE-2026-32519 Patchstack
9.8 Critical Pelicula Theme pelicula-video-production-and-movie-theme PHP Object Injection No login needed ≤ < 1.10 Fixed in 1.10 CVE-2026-32512 Patchstack
9.8 Critical Borgholm Theme borgholm-marketing-agency-theme PHP Object Injection No login needed ≤ < 1.6 Fixed in 1.6 CVE-2026-32502 Patchstack
9.3 Critical ChatBot Plugin chatbot SQL Injection No login needed ≤ <= 7.7.9 Fixed in 7.8.0 CVE-2026-32499 Patchstack
9.9 Critical Ona Plugin ona Arbitrary File Upload ≤ < 1.24 Fixed in 1.24 CVE-2026-32482 Patchstack
9.3 Critical Product Rearrange for WooCommerce Plugin products-rearrange-woocommerce SQL Injection No login needed ≤ <= 1.2.2 CVE-2026-31920 Patchstack
9.8 Critical Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation PHP Object Injection No login needed ≤ 5.6.0 CVE-2026-27095 Patchstack
9.8 Critical Buisson Theme buisson PHP Object Injection No login needed ≤ 1.1.11 CVE-2026-27084 Patchstack
9.8 Critical Work & Travel Company Theme work-travel-company PHP Object Injection No login needed ≤ 1.2 CVE-2026-27083 Patchstack
9.8 Critical Love Story Theme lovestory PHP Object Injection No login needed ≤ 1.3.12 CVE-2026-27082 Patchstack
9.1 Critical WPCafe Plugin wp-cafe Broken Access Control No login needed ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-27071 Patchstack
9.8 Critical Golo Plugin golo Privilege Escalation No login needed ≤ 1.7.0 CVE-2026-27051 Patchstack
9.8 Critical Jobica Core Plugin jobica-core Privilege Escalation Account Takeover No login needed ≤ 1.4.2 CVE-2026-27049 Patchstack
9.9 Critical Total Poll Lite Plugin totalpoll-lite Remote Code Execution ≤ 4.12.0 CVE-2026-27044 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only