WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 351–400 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Realtyna Organic IDX plugin + WPL Real Estate Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting Reflected XSS via Location Selector Endpoint No login needed < 5.4.2 Fixed in 5.4.2 CVE-2026-91014 WPScan
8.8 High PuppyFW Plugin Privilege Escalation Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation ≤ 0.4.4 CVE-2026-88904 WPScan
8.8 High Dictionary Plugin Cross-Site Scripting Unauthenticated Stored XSS via Direct Dictionary Update No login needed ≤ 1.0 CVE-2026-88792 WPScan
8.8 High Dewa Kirim Plugin Cross-Site Scripting Unauthenticated Stored XSS via Checkout Coordinates No login needed ≤ 1.0.0 CVE-2026-87786 WPScan
8.8 High WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored XSS via Consent Logs No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85130 WPScan
7.5 High Choose User Role at Registration for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation via Registration Role Request No login needed < 1.3.3 Fixed in 1.3.3 CVE-2026-85128 WPScan
7.1 High Dictionary Plugin Cross-Site Scripting Reflected XSS via Multiple Parameters No login needed ≤ 1.0 CVE-2025-15697 WPScan
8.1 High Paid Downloads Plugin paid-downloads Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'paiddownloads_update_file' Action No login needed ≤ 3.15 CVE-2026-87935 Wordfence
7.6 High WP Mega Menu Plugin wp-megamenu SQL Injection ≤ 1.4.2 CVE-2026-92465 Patchstack
7.1 High LearnPress Plugin learnpress Cross-Site Scripting Reflected XSS via 'skin' Parameter No login needed 4.2.6.4 – < 4.4.7 Fixed in 4.4.7 CVE-2026-86444 WPScan
7.2 High Tutor LMS 2.7.1 Plugin Privilege Escalation < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification 2.7.1 – < 4.0.8 Fixed in 4.0.8 CVE-2026-85569 WPScan
8.1 High GiveWP Plugin give Privilege Escalation Unauthenticated Account Takeover via Donor Email Sanitization Mismatch No login needed 4.16.6 – < 4.16.8.1 Fixed in 4.16.8.1 CVE-2026-85530 WPScan
8.8 High Optimole Plugin optimole-wp Cross-Site Scripting Unauthenticated Stored XSS via Srcset Descriptor Parameter No login needed 4.2.3 – < 4.2.12 Fixed in 4.2.12 CVE-2026-84829 WPScan
8.6 High Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report SQL Injection Unauthenticated SQLi via 'sort' Parameter No login needed < 4.2.0 Fixed in 4.2.0 CVE-2026-78472 WPScan
8.8 High WP Import Export Lite Plugin wp-import-export-lite Arbitrary File Upload Authenticated Arbitrary File Upload via Remote Image Import < 3.9.33 Fixed in 3.9.33 CVE-2026-76552 WPScan
7.2 High WP Import Export Lite Plugin wp-import-export-lite Remote Code Execution Authenticated RCE via Export Field PHP Function < 3.9.33 Fixed in 3.9.33 CVE-2026-76551 WPScan
7.2 High WP Import Export Lite Plugin wp-import-export-lite Remote Code Execution Authenticated RCE via Export Template Path Traversal < 3.9.34 Fixed in 3.9.34 CVE-2026-76550 WPScan
7.1 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control Subscriber+ Arbitrary Store Data and Ownership Overwrite via stores REST Endpoint 5.0.0 – < 5.0.16 Fixed in 5.0.16 CVE-2026-74926 WPScan
7.5 High Online Scheduling and Appointment Booking System Plugin bookly-responsive-appointment-booking-tool Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Data Access and Message Injection via 'conversation_id' Parameter No login needed ≤ 28.1 CVE-2026-89063 Wordfence
8.8 High Contest Gallery Plugin contest-gallery Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter ≤ 32.0.1 CVE-2026-78088 Wordfence
7.2 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via AJAX Cron Handler Request No login needed ≤ 3.8.9 CVE-2026-18595 Wordfence
8.7 High design-scuole-wordpress-theme Theme Broken Access Control Multiple authorization bypass in WordPress theme design-scuole-wordpress-theme No login needed 1.0 – 2.17.3 CVE-2026-87792 ENISA
8.7 High design-scuole-wordpress-theme Theme Path Traversal Path traversal vulnerability in WordPress theme design-scuole-wordpress-theme No login needed 2.6.0 – 2.18.1 CVE-2026-87791 ENISA
7.2 High MotoPress Hotel Booking Plugin motopress-hotel-booking-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Stripe Webhook Event Object 'id' No login needed ≤ 6.2.4 CVE-2026-90650 Wordfence
8.8 High Consulting - Business, Finance Theme Privilege Escalation Business, Finance WordPress Theme <= 6.7.16 - Authenticated (Subscriber+) Privilege Escalation via AJAX ≤ 6.7.16 CVE-2026-14805 Wordfence
7.5 High Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce Plugin wp-event-solution Privilege Escalation Event Calendar, Tickets, Registration, Booking & WooCommerce <= 4.1.23 - Authenticated (Subscriber+) Privilege Escalation via map_meta_cap Filter ≤ 4.1.23 CVE-2026-75983 Wordfence
8.6 High Domain For Sale Plugin domain-for-sale Broken Access Control ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API No login needed < 3.5.2 Fixed in 3.5.2 CVE-2026-89023 VulnCheck
7.5 High MDJM Event Management and Mobile Events Manager Plugin Broken Access Control Unauthenticated Arbitrary Post Deletion No login needed < 1.7.8.5, ≤ 1.4.8.3 Fixed in 1.7.8.5 CVE-2026-88802 WPScan
8.8 High YouTube Embed Plugin Cross-Site Scripting Unauthenticated Stored XSS via youram_server No login needed 10.0 – 10.3 CVE-2026-88793 WPScan
8.8 High Hoo Companion Plugin Cross-Site Scripting Unauthenticated Stored XSS via Theme Settings Import No login needed 1.0.2 – 1.0.2 CVE-2026-85129 WPScan
8.8 High GenieWords Plugin Cross-Site Scripting Unauthenticated Stored XSS and Configuration Overwrite No login needed 1.5.27 – 1.5.34 CVE-2026-74933 WPScan
7.5 High Really Simple Security Plugin really-simple-ssl Authentication Bypass Unauthenticated 2FA Bypass via Email Provider State Demotion 9.5.10.1 – < 9.8.1 Fixed in 9.8.1 CVE-2026-89080 WPScan
7.5 High User Registration & Membership Plugin user-registration Privilege Escalation Subscriber+ Privilege Escalation via Membership Purchase 4.4.6 – < 5.2.8 Fixed in 5.2.8 CVE-2026-86406 WPScan
7.2 High User Registration & Membership Plugin user-registration Privilege Escalation Author+ Privilege Escalation to Administrator < 5.2.8 Fixed in 5.2.8 CVE-2026-80071 WPScan
8.8 High MemberPress Corporate Accounts Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation ≤ 1.5.39 CVE-2026-15451 Wordfence
8.8 High Tutor LMS Plugin tutor PHP Object Injection Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution ≤ 4.0.7 CVE-2026-78175 Wordfence
7.5 High GEO my WP Plugin geo-my-wp Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 4.5.5.3 CVE-2026-85200 Wordfence
7.5 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Unauthenticated SQL Injection via 'compare' Parameter No login needed ≤ 4.7.11 CVE-2026-16482 Wordfence
8.0 High YayPricing Plugin yaypricing Cross-Site Scripting Subscriber+ Stored XSS via save_page_data REST Route < 3.5.7 Fixed in 3.5.7 CVE-2026-87888 WPScan
7.5 High Zonify Plugin zonify Information Disclosure Unauthenticated Account Login Token Disclosure No login needed < 1.0.5 Fixed in 1.0.5 CVE-2026-87842 WPScan
8.8 High Add User Autocomplete Plugin add-user-autocomplete Privilege Escalation Subscriber+ Privilege Escalation < 1.2 Fixed in 1.2 CVE-2026-87759 WPScan
8.1 High IDB Ecommerce (wpStoreCart 5) Plugin PHP Object Injection Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.php No login needed ≤ 5.0.7 CVE-2026-84099 WPScan
8.6 High Album Cover Finder Plugin SQL Injection Unauthenticated SQLi via and_action No login needed ≤ 0.7.0 CVE-2026-84047 WPScan
8.8 High BE REST Endpoints Plugin Cross-Site Scripting Unauthenticated Stored XSS and Widget Manipulation No login needed ≤ 1.0.0 CVE-2026-81742 WPScan
7.1 High Export & Import WPBakery Page Builder Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.2 CVE-2026-81429 WPScan
7.2 High Gpx2Graphics Plugin Arbitrary File Upload Arbitrary File Upload via CSRF ≤ 0.3 CVE-2026-81090 WPScan
8.6 High Yogeta WP Cloud Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.0 CVE-2026-80494 WPScan
8.6 High SAMO Forms Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 1.0.0 CVE-2026-80491 WPScan
7.2 High Temporary Login Without Password Plugin temporary-login-without-password Privilege Escalation Multisite Subsite Admin+ Network Super Admin Privilege Escalation 1.5 – < 1.9.9 Fixed in 1.9.9 CVE-2026-77752 WPScan
7.2 High Amelia Plugin Privilege Escalation Amelia Manager+ WordPress Account Takeover < 2.4.10 Fixed in 2.4.10 CVE-2026-77705 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only