WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 351–400 of 1,407 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Elementor Website Builder | Cross-Site Scripting |
≤ 3.29.0 Fixed in 3.29.1 |
CVE-2024-50555 |
Patchstack | |
| 7.5 High | Product Table and List Builder for WooCommerce Lite | SQL Injection Unauthenticated Time-Based SQL Injection via 'search' Parameter No login needed |
≤ 4.6.2 |
CVE-2026-2232 |
Wordfence | |
| 6.5 Medium | Fusion Builder | Cross-Site Scripting |
≤ 3.14.1 Fixed in 3.14.2 |
CVE-2026-25472 |
Patchstack | |
| 6.5 Medium | Bold Page Builder | Cross-Site Scripting |
≤ 5.6.9 Fixed in 5.7.0 |
CVE-2026-25451 |
Patchstack | |
| 5.3 Medium | Popup Builder - Create highly converting, mobile friendly marketing popups. | Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed |
≤ 4.4.2 |
CVE-2025-13079 |
Wordfence | |
| 4.3 Medium | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' |
≤ 6.4.7 |
CVE-2026-2386 |
Wordfence | |
| 5.3 Medium | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Price Manipulation Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment No login needed |
≤ 6.0.6.9 |
CVE-2025-14444 |
Wordfence | |
| 4.3 Medium | Taskbuilder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation |
≤ 5.0.2 |
CVE-2026-1640 |
Wordfence | |
| 6.5 Medium | Taskbuilder | SQL Injection Authenticated (Subscriber+) SQL Injection via 'order' and 'sort_by' Parameters |
≤ 5.0.2 |
CVE-2026-1639 |
Wordfence | |
| 4.4 Medium | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Cross-Site Scripting Contact Form, Payment Form & Custom Form Builder <= 1.50.2 - Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.50.2 |
CVE-2026-2002 |
Wordfence | |
| 4.3 Medium | RegistrationMagic | Broken Access Control Subscriber+ Form Creation |
< 6.0.7.2 Fixed in 6.0.7.2 |
CVE-2026-0929 |
WPScan | |
| 5.3 Medium | Easy Form Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Form Response Data Exposure No login needed |
≤ 3.9.3 |
CVE-2025-14067 |
Wordfence | |
| 4.3 Medium | RegistrationMagic | Information Disclosure Subscriber+ Sensitive Data Disclosure |
< 6.0.7.2 Fixed in 6.0.7.2 |
CVE-2025-15520 |
WPScan | |
| 8.8 High | Custom Block Builder – Lazy Blocks | Remote Code Execution Lazy Blocks <= 4.2.0 - Authenticated (Contributor+) Remote Code Execution |
≤ 4.2.0 |
CVE-2026-1560 |
Wordfence | |
| 6.4 Medium | Beaver Builder Page Builder – Drag and Drop Website Builder | Broken Access Control Drag and Drop Website Builder <= 2.10.0.5 - Authenticated (Custom+) Missing Authorization to Stored Cross-Site Scripting via Global Settings |
≤ 2.10.0.5 |
CVE-2026-1231 |
Wordfence | |
| 5.4 Medium | PopupKit | Broken Access Control Missing Authorization to Sensitive Information Disclosure and Data Deletion |
≤ 2.2.0 |
CVE-2025-14895 |
Wordfence | |
| 6.4 Medium | Fluent Forms | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module |
≤ 6.1.14 |
CVE-2026-0996 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Author+) Stored DOM-based Cross-Site Scripting in Post Grid |
≤ 5.5.3 |
CVE-2025-13463 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 5.4.8 |
CVE-2025-12159 |
Wordfence | |
| 6.4 Medium | Bold Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_tabs Shortcode |
≤ 5.5.1 |
CVE-2025-12803 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_accordion_item Shortcode |
≤ 5.6.1 |
CVE-2025-15267 |
Wordfence | |
| 5.4 Medium | GreenShift - Animation and Page Builder Blocks | Broken Access Control Animation and Page Builder Blocks <= 12.6 - Missing Authorization to Authenticated (Subscriber+) Information Disclosure of AI API Keys and Stored Cross-Site Scripting via custom_css |
≤ 12.6 |
CVE-2026-1927 |
Wordfence | |
| 8.2 High | Popup builder with Gamification | SQL Injection Unauthenticated SQL Injection via Multiple REST API Endpoints No login needed |
≤ 2.2.0 |
CVE-2025-13192 |
Wordfence | |
| 9.8 Critical | User Profile Builder | Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed |
1.1.27 – < 3.15.2 Fixed in 3.15.2 |
CVE-2025-15030 |
WPScan | |
| 5.3 Medium | NEX-Forms – Ultimate Forms | Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 9.1.8 |
CVE-2025-15510 |
Wordfence | |
| 6.4 Medium | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library | Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.14 |
CVE-2025-14283 |
Wordfence | |
| 5.3 Medium | RegistrationMagic | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Settings Modification No login needed |
≤ 6.0.7.4 |
CVE-2026-1054 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed |
≤ 2.5.2 |
CVE-2025-13205 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed |
≤ 2.5.2 |
CVE-2025-13194 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed |
≤ 2.5.2 |
CVE-2025-13139 |
Wordfence | |
| 3.7 Low | MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor | Information Disclosure Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value No login needed |
≤ 4.1.0 |
CVE-2026-0633 |
Wordfence | |
| 5.9 Medium | Landing Page Builder | Cross-Site Scripting |
≤ 1.5.3.4 Fixed in 1.5.3.5 |
CVE-2026-24620 |
Patchstack | |
| 5.9 Medium | Livemesh Addons for WPBakery Page Builder | Cross-Site Scripting |
≤ 3.9.4 |
CVE-2026-24594 |
Patchstack | |
| 6.4 Medium | Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder | Cross-Site Scripting Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.10.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 6.10.0.2 |
CVE-2025-15522 |
Wordfence | |
| 5.4 Medium | RegistrationMagic | Cross-Site Request Forgery No login needed |
≤ 6.0.6.9 Fixed in 6.0.7.0 |
CVE-2026-24374 |
Patchstack | |
| 4.3 Medium | Easy Form Builder | Broken Access Control |
≤ 3.9.6 Fixed in 4.0.0 |
CVE-2026-22472 |
Patchstack | |
| 7.5 High | Beaver Builder | Remote Code Execution Arbitrary Code Execution |
≤ 2.9.4.1 Fixed in 2.9.4.2 |
CVE-2025-69319 |
Patchstack | |
| 6.5 Medium | BM Content Builder | Path Traversal Arbitrary File Download |
≤ 3.16.3.3 Fixed in 3.16.3.3 |
CVE-2025-69055 |
Patchstack | |
| 6.5 Medium | Contact Form & Lead Form Elementor Builder | Information Disclosure Sensitive Data Exposure |
≤ 2.0.1 Fixed in 2.0.2 |
CVE-2025-68046 |
Patchstack | |
| 8.1 High | Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy | Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure |
≤ 4.2.4 |
CVE-2025-14977 |
Wordfence | |
| 9.8 Critical | RegistrationMagic | Privilege Escalation Unauthenticated Privilege Escalation via admin_order No login needed |
≤ 6.0.7.1 |
CVE-2025-15403 |
Wordfence | |
| 5.3 Medium | Cost Calculator Builder | Broken Access Control Missing Authorization to Unauthenticated Payment Status Bypass No login needed |
≤ 3.6.9 |
CVE-2025-14757 |
Wordfence | |
| 6.4 Medium | SpiceForms Form Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0 |
CVE-2025-12178 |
Wordfence | |
| 4.4 Medium | Internal Link Builder | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Settings |
≤ 1.0 |
CVE-2025-14725 |
Wordfence | |
| 7.1 High | DASHBOARD BUILDER | Cross-Site Request Forgery Cross-Site Request Forgery to SQL Injection No login needed |
≤ 1.5.7 |
CVE-2025-14615 |
Wordfence | |
| 6.4 Medium | ConvertForce Popup Builder | Cross-Site Scripting Stored Cross-Site Scripting via entrance_animation |
≤ 0.0.7 |
CVE-2025-14506 |
Wordfence | |
| 4.3 Medium | WP Table Builder | Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Table Creation |
≤ 2.0.19 |
CVE-2025-13753 |
Wordfence | |
| 5.3 Medium | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.49.1 - Missing Authorization to Authenticated (Forminator User+) CSV Export |
≤ 1.49.1 |
CVE-2025-14782 |
Wordfence | |
| 6.8 Medium | Nex-Forms Express WP Form Builder | Cross-Site Scripting Authenticated Stored XSS |
< 9.1.8 Fixed in 9.1.8 |
CVE-2025-14803 |
WPScan | |
| 5.3 Medium | Dashboard Welcome for Beaver Builder | Broken Access Control No login needed |
≤ 1.0.8 |
CVE-2026-22488 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.