WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 351–400 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium User Registration Plugin user-registration Broken Access Control No login needed ≤ 5.2.6 Fixed in 5.2.7 CVE-2026-73403 Patchstack
5.3 Medium InstaWP Connect Plugin instawp-connect Broken Access Control No login needed ≤ 0.1.3.7 Fixed in 0.1.3.8 CVE-2026-73401 Patchstack
6.5 Medium GiveWP Plugin give Cross-Site Scripting < 4.16.6 Fixed in 4.16.6 CVE-2026-73357 Patchstack
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control No login needed < 4.22.10 Fixed in 4.22.10 CVE-2026-73353 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed < 4.16.6 Fixed in 4.16.6 CVE-2026-73349 Patchstack
5.9 Medium WP Data Access Plugin wp-data-access Cross-Site Scripting ≤ 5.5.79 Fixed in 5.5.80 CVE-2026-73344 Patchstack
6.5 Medium Featured Image from URL Plugin featured-image-from-url Cross-Site Scripting ≤ 5.3.3 Fixed in 6.0.0 CVE-2026-73340 Patchstack
6.5 Medium Motors Plugin motors-car-dealership-classified-listings Broken Access Control ≤ 1.4.113 Fixed in 1.4.114 CVE-2026-66693 Patchstack
6.3 Medium Anti Spam and list cleaner – AcyChecker Plugin acychecker Broken Access Control AcyChecker plugin <= 2.0.0 - Broken Access Control ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-66689 Patchstack
6.5 Medium WpBookingly Plugin service-booking-manager Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2026-66687 Patchstack
6.5 Medium Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Broken Access Control PayPal & Stripe Add-on plugin <= 2.5.1 - Broken Access Control No login needed ≤ 2.5.1 CVE-2026-66660 Patchstack
6.0 Medium Vehica Core Plugin vehica-core Server-Side Request Forgery ≤ 1.0.104 CVE-2026-66654 Patchstack
6.5 Medium Accordion Plugin accordions-wp Cross-Site Scripting ≤ 3.0.6 CVE-2026-66471 Patchstack
6.5 Medium FluentCommunity Plugin fluent-community Cross-Site Scripting ≤ 2.7.5 Fixed in 2.7.7 CVE-2026-66467 Patchstack
6.5 Medium Internal Link Optimiser Plugin internal-link-finder Broken Access Control No login needed ≤ 5.2.7 CVE-2026-66464 Patchstack
6.5 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Cross-Site Scripting ≤ 1.18.1 CVE-2026-66460 Patchstack
6.5 Medium AI for SEO Plugin ai-for-seo Broken Access Control No login needed ≤ 2.4.2 Fixed in 2.4.3 CVE-2026-66459 Patchstack
6.5 Medium Profile Extra Fields by BestWebSoft Plugin profile-extra-fields Cross-Site Scripting ≤ 1.3.4 CVE-2026-66456 Patchstack
6.0 Medium ReactPress Plugin reactpress Broken Access Control ≤ 3.4.0 CVE-2026-66455 Patchstack
6.5 Medium WP Social Avatar Plugin wp-social-avatar Broken Access Control No login needed ≤ 1.5 CVE-2026-66454 Patchstack
6.5 Medium Payment Forms for Paystack Plugin payment-forms-for-paystack Information Disclosure Sensitive Data Exposure ≤ 4.0.5 CVE-2026-66444 Patchstack
6.5 Medium Secure Card Gateway for ePay Paycenter (Piraeus Bank) Plugin secure-card-gateway-for-epay-paycenter-piraeus-bank Broken Access Control No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2026-61978 Patchstack
6.5 Medium AcyMailing SMTP Newsletter Plugin acymailing Cross-Site Scripting ≤ 10.11.1 Fixed in 11.0.0 CVE-2026-28182 Patchstack
6.5 Medium AcyMailing SMTP Newsletter Plugin acymailing Broken Access Control ≤ 10.11.1 Fixed in 11.0.0 CVE-2026-28181 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Information Disclosure Sensitive Data Exposure ≤ 4.1.18 Fixed in 4.1.19 CVE-2026-28174 Patchstack
6.5 Medium Service Finder Booking Plugin sf-booking Broken Access Control ≤ 6.2 CVE-2026-28159 Patchstack
6.5 Medium Do Lasso Plugin lasso Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 358 CVE-2026-28155 Patchstack
6.5 Medium Tourfic Plugin tourfic Broken Access Control ≤ 2.23.1 Fixed in 2.23.2 CVE-2026-27999 Patchstack
6.5 Medium Popup by Supsystic Plugin popup-by-supsystic Cross-Site Scripting ≤ 1.11.2 Fixed in 1.12.0 CVE-2026-27537 Patchstack
5.3 Medium Prevent Direct Access – Protect WordPress Files Plugin prevent-direct-access Broken Access Control Protect WordPress Files <= 2.8.8.8 - Unauthenticated Protected File Access No login needed ≤ 2.8.8.8 CVE-2026-3835 Wordfence
6.5 Medium sucuri-wordpress-plugin Plugin Path Traversal Sucuri WordPress Plugin 2.7.3 Path Traversal via integrity.lib.php ≤ 2.7.3 CVE-2026-73033 VulnCheck
5.4 Medium WP Umbrella Plugin wp-health Cross-Site Request Forgery No login needed 2.24.2 – 2.26.2 Fixed in 2.27.0 CVE-2026-66642 Patchstack
5.9 Medium Subscribe to Comments Plugin subscribe-to-comments Cross-Site Scripting ≤ 2.3.1 CVE-2026-66706 Patchstack
6.5 Medium MailOptin Plugin mailoptin Cross-Site Scripting ≤ 1.2.78.0 Fixed in 1.2.78.1 CVE-2026-66703 Patchstack
5.3 Medium Profile Builder Plugin profile-builder Broken Access Control No login needed ≤ 3.16.5 Fixed in 3.16.6 CVE-2026-66701 Patchstack
5.3 Medium Dokan Plugin dokan-lite Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66699 Patchstack
4.3 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Information Disclosure Sensitive Data Exposure ≤ 3.7.8 Fixed in 3.7.8.1 CVE-2026-66696 Patchstack
6.5 Medium W3 Total Cache Plugin w3-total-cache Path Traversal No login needed ≤ 2.10.2 Fixed in 2.10.3 CVE-2026-66695 Patchstack
4.3 Medium Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66692 Patchstack
6.5 Medium Ultimate Addons for Elementor Plugin ultimate-elementor Cross-Site Scripting ≤ 1.45.2 Fixed in 1.45.2.1 CVE-2026-66688 Patchstack
6.5 Medium Plugins Garbage Collector (Database Cleanup) Plugin plugins-garbage-collector Cross-Site Request Forgery No login needed ≤ 0.14 CVE-2026-66686 Patchstack
5.3 Medium Featured Video Plus Plugin featured-video-plus Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-66685 Patchstack
5.3 Medium Export Import Menus Plugin export-import-menus Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.2 CVE-2026-66684 Patchstack
5.3 Medium Custom CSS and JavaScript Plugin custom-css-and-javascript Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.16 CVE-2026-66683 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery No login needed ≤ 7.1.14 CVE-2026-66681 Patchstack
4.3 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Broken Access Control ≤ 6.1.1 CVE-2026-66678 Patchstack
6.5 Medium Legal Text Connector of the IT-Recht Kanzlei Plugin legal-texts-connector-it-recht-kanzlei Broken Access Control No login needed ≤ 1.0.13 Fixed in 1.0.14 CVE-2026-66452 Patchstack
6.5 Medium WP Event SOlution Plugin wp-event-solution Authentication Bypass Broken Authentication No login needed ≤ 4.1.9 Fixed in 4.1.10 CVE-2026-66451 Patchstack
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Authentication Bypass Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication No login needed ≤ 1.9.0 Fixed in 2.0.0 CVE-2026-66425 Patchstack
5.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Authentication Bypass Captcha Bypass No login needed ≤ 8.7.13 Fixed in 8.7.14 CVE-2026-65502 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only