WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 3,951–4,000 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Themify Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field |
≤ 7.7.6 |
CVE-2026-15096 |
Wordfence | |
| 4.3 Medium | Affilia | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification |
≤ 3.3.3 |
CVE-2026-7559 |
Wordfence | |
| 6.4 Medium | Starboard Suite Reservation Calendars | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 3.1.4 |
CVE-2025-13968 |
Wordfence | |
| 4.3 Medium | PDF Invoices & Packing Slips for WooCommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute |
≤ 5.14.0 |
CVE-2026-13116 |
Wordfence | |
| 4.4 Medium | Print, PDF, Email by PrintFriendly | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter |
≤ 5.5.10 |
CVE-2026-9738 |
Wordfence | |
| 7.2 High | Planyo online reservation system | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter No login needed |
≤ 3.0 |
CVE-2026-3576 |
Wordfence | |
| 5.3 Medium | AI Chatbot & Workflow Automation by AIWU | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear' No login needed |
≤ 1.4.12 |
CVE-2026-6803 |
Wordfence | |
| 4.3 Medium | SurfLink | Broken Access Control Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action |
< 2.6.0 Fixed in 2.6.0 |
CVE-2026-3552 |
Wordfence | |
| 8.8 High | Swiss Toolkit For WP | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via upload_extension_files() |
≤ 1.4.6 |
CVE-2026-2354 |
Wordfence | |
| 6.4 Medium | Themify Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field |
≤ 7.7.6 |
CVE-2026-15097 |
Wordfence | |
| 4.3 Medium | Notification for Telegram | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action |
≤ 3.5.1 |
CVE-2026-7620 |
Wordfence | |
| 8.8 High | WP Ultimate CSV Importer | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter |
≤ 8.0.1 |
CVE-2026-13353 |
Wordfence | |
| 7.2 High | Motors | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info No login needed |
≤ 1.4.112 |
CVE-2026-13114 |
Wordfence | |
| 4.3 Medium | Mux Video Uploader | Information Disclosure Authenticated (Subscriber+) Information Exposure |
≤ 1.1.4 |
CVE-2026-7544 |
Wordfence | |
| 7.5 High | LA-Studio Element Kit for Elementor | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting |
≤ 1.6.1 |
CVE-2026-15338 |
Wordfence | |
| 6.5 Medium | KiviCare | SQL Injection Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder |
≤ 4.5.0 |
CVE-2026-15072 |
Wordfence | |
| 5.3 Medium | Members | Information Disclosure Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel No login needed |
≤ 3.2.22 |
CVE-2026-12426 |
Wordfence | |
| 6.5 Medium | Majestic Support | SQL Injection Authenticated (Subscriber+) SQL Injection via 'val' Parameter |
≤ 1.1.9 |
CVE-2026-13262 |
Wordfence | |
| 4.3 Medium | Points and Rewards for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions |
≤ 2.10.1 |
CVE-2026-10628 |
Wordfence | |
| 4.4 Medium | Lockme OAuth2 calendars integration | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting |
≤ 2.11.0 |
CVE-2026-3367 |
Wordfence | |
| 6.5 Medium | KiviCare | SQL Injection Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController |
≤ 4.5.0 |
CVE-2026-15073 |
Wordfence | |
| 6.4 Medium | Mixed Media Gallery Blocks | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute |
≤ 3.3.3.1 |
CVE-2026-5743 |
Wordfence | |
| 4.3 Medium | MyParcel | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions |
≤ 4.25.1 |
CVE-2026-8678 |
Wordfence | |
| 8.8 High | WP Grid Builder | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter |
≤ 2.3.3 |
CVE-2026-13756 |
Wordfence | |
| 6.5 Medium | UnderConstructionPage PRO | Path Traversal Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter |
≤ 5.76 |
CVE-2026-11426 |
Wordfence | |
| 9.8 Critical | OAuth Single Sign On - SSO (OAuth Client) | Authentication Bypass SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication No login needed |
≤ 38.5.8 Fixed in 38.5.8.1 |
CVE-2026-57807 |
Patchstack | |
| 9.8 Critical | miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) | Authentication Bypass Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow No login needed |
≤ 7.7.0 |
CVE-2026-12761 |
Wordfence | |
| 5.3 Medium | Eventin | Broken Access Control Missing Authorization to Unauthenticated Payment Bypass via REST API No login needed |
4.0.26 – 4.1.15 |
CVE-2026-13039 |
Wordfence | |
| 4.4 Medium | Ajax Load More | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 7.0.1 |
CVE-2026-15295 |
Wordfence | |
| 7.2 High | SEO Plugin by Squirrly SEO | Cross-Site Scripting Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost() No login needed |
≤ 14.0.0 |
CVE-2026-1667 |
Wordfence | |
| 6.4 Medium | Logo Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter |
≤ 5.5 |
CVE-2026-13247 |
Wordfence | |
| 5.3 Medium | KiviCare | Broken Access Control Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint No login needed |
≤ 4.4.0 |
CVE-2026-11990 |
Wordfence | |
| 6.4 Medium | Jeg Kit for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget |
≤ 3.2.6 |
CVE-2026-13710 |
Wordfence | |
| 4.9 Medium | Mail Mint | SQL Injection Authenticated (Administrator+) SQL Injection via 'recipients' Parameter |
≤ 1.24.1 |
CVE-2026-12918 |
Wordfence | |
| 6.5 Medium | JoomSport | SQL Injection Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute |
≤ 5.7.9 |
CVE-2026-13010 |
Wordfence | |
| 4.3 Medium | Invoice123 | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions |
≤ 1.7.0 |
CVE-2026-9857 |
Wordfence | |
| 6.1 Medium | ICS Calendar | Cross-Site Scripting Reflected Cross-Site Scripting via 'htmltagtitle' Parameter No login needed |
≤ 12.0.9 |
CVE-2026-9838 |
Wordfence | |
| 4.3 Medium | Import and export users and customers | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action |
≤ 2.4.0 |
CVE-2026-15026 |
Wordfence | |
| 4.3 Medium | Easy Appointments | Broken Access Control Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation |
≤ 3.12.27 |
CVE-2026-11992 |
Wordfence | |
| 4.3 Medium | Cookie Banner for GDPR / CCPA | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action |
≤ 4.3.6 |
CVE-2026-12955 |
Wordfence | |
| 4.3 Medium | GoodMeet | Cross-Site Request Forgery Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential' No login needed |
≤ 1.1.8 |
CVE-2026-6440 |
Wordfence | |
| 6.6 Medium | HappyForms | Local File Inclusion Authenticated (Admin+) Local File Inclusion |
≤ 1.26.12 |
CVE-2025-11977 |
Wordfence | |
| 4.3 Medium | FlowForms | Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints |
≤ 1.1.1 |
CVE-2026-12400 |
Wordfence | |
| 5.3 Medium | Easy Upload Files During Checkout | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter No login needed |
≤ 3.0.1 |
CVE-2026-6802 |
Wordfence | |
| 4.3 Medium | GW AI Website Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion |
≤ 1.0.1 |
CVE-2026-1946 |
Wordfence | |
| 4.9 Medium | Cookie Banner for GDPR / CCPA | SQL Injection Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter |
≤ 4.3.6 |
CVE-2026-14475 |
Wordfence | |
| 6.4 Medium | Eventin | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter |
≤ 4.1.15 |
CVE-2026-12924 |
Wordfence | |
| 6.4 Medium | Hostel | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode |
≤ 1.1.7 |
CVE-2026-3907 |
Wordfence | |
| 6.5 Medium | BetterDocs | SQL Injection Authenticated (Custom+) SQL Injection via 'lang' Parameter |
≤ 4.6.0 |
CVE-2026-15104 |
Wordfence | |
| 4.4 Medium | Highlighting Code Block | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting |
≤ 2.2.0 |
CVE-2026-12108 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.