WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,051–4,100 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 82 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin wp-user-frontend Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter No login needed ≤ 4.3.7 CVE-2026-12418 Wordfence
4.3 Medium Memberships and User Profiles for WooCommerce Plugin ecommerce-user-profiles-by-profilegrid Broken Access Control Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation ≤ 3.4 CVE-2026-11359 Wordfence
5.3 Medium GamiPress Plugin gamipress Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter No login needed ≤ 7.9.4 CVE-2026-13450 Wordfence
6.1 Medium Mang Board WP Plugin mangboard Cross-Site Scripting Reflected Cross-Site Scripting via 'stag' Parameter No login needed ≤ 2.3.4 CVE-2026-13334 Wordfence
6.5 Medium ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support Plugin erp SQL Injection Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter ≤ 1.17.5 CVE-2026-13011 Wordfence
5.3 Medium User Frontend Plugin wp-user-frontend Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter No login needed ≤ 4.3.7 CVE-2026-12406 Wordfence
6.4 Medium Bookero.pl Plugin bookeropl Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 2.2 CVE-2026-6910 Wordfence
6.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute ≤ 5.113.0 CVE-2026-13771 Wordfence
6.5 Medium Backup and Staging by WP Time Capsule Plugin wp-time-capsule Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function ≤ 1.22.26 CVE-2026-8996 Wordfence
6.6 Medium WPFunnels Plugin wpfunnels Local File Inclusion Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter ≤ 3.12.7 CVE-2026-13080 Wordfence
5.3 Medium Age Verification & Identity Verification by Token of Trust Plugin token-of-trust Broken Access Control Missing Authorization to Unauthenticated Information Exposure via 'tot_export_table' Parameter No login needed ≤ 4.0.2 CVE-2026-7558 Wordfence
7.2 High Connect Contact Form 7 and Mailchimp Plugin contact-form-7-mailchimp-extension Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values No login needed ≤ 0.9.78.06 CVE-2026-15000 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes ≤ 3.3.61 CVE-2026-14343 Wordfence
6.4 Medium AcyMailing Plugin acymailing Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute ≤ 10.10.2 CVE-2026-12170 Wordfence
6.4 Medium Post Grid Gutenberg Blocks for News, Magazines, Blog Websites Plugin ultimate-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute ≤ 5.0.31 CVE-2026-13253 Wordfence
6.4 Medium Block, Suspend, Report for BuddyPress Plugin bp-toolkit Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter ≤ 3.6.4 CVE-2026-4653 Wordfence
5.3 Medium Fediverse Embeds Plugin fediverse-embeds Server-Side Request Forgery Unauthenticated SSRF via Site Info Endpoint No login needed < 1.5.8 Fixed in 1.5.8 CVE-2026-12517 WPScan
5.3 Medium Fediverse Embeds Plugin fediverse-embeds Server-Side Request Forgery Unauthenticated SSRF via Media Proxy No login needed < 1.5.8 Fixed in 1.5.8 CVE-2026-12516 WPScan
6.5 Medium Everest Forms Plugin everest-forms Broken Access Control Unauthenticated Missing Authorization via Site Assistant REST Endpoints No login needed 3.4.2 – < 3.5.0 Fixed in 3.5.0 CVE-2026-12270 WPScan
5.3 Medium WP Support Plus Responsive Ticket System Plugin Broken Access Control Unauthenticated Support Ticket Access via Session Cookie Forgery No login needed ≤ 9.1.2 CVE-2026-11875 WPScan
5.3 Medium WP DSGVO Tools (GDPR) Plugin shapepress-dsgvo Information Disclosure Unauthenticated Sensitive Information Disclosure via Subject Access Request No login needed < 3.1.40 Fixed in 3.1.40 CVE-2026-11869 WPScan
7.5 High Everest Forms Plugin everest-forms Information Disclosure Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts No login needed < 3.5.0 Fixed in 3.5.0 CVE-2026-11571 WPScan
8.8 High Divi Form Builder Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form ≤ 5.1.8 CVE-2026-5523 Wordfence
9.8 Critical Blocksy Companion Plugin blocksy-companion Arbitrary File Upload Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments No login needed ≤ 2.1.46 Fixed in 2.1.47 CVE-2026-58480 VulnCheck
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field No login needed ≤ 1.8.8 CVE-2026-6820 Wordfence
6.4 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute ≤ 4.7.4 CVE-2026-6740 Wordfence
4.7 Medium Smash Balloon Social Photo Feed – Easy Social Feeds Plugin instagram-feed Cross-Site Request Forgery Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter No login needed ≤ 6.11.1 CVE-2026-12002 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup ≤ 6.6.2 CVE-2026-6459 Wordfence
5.3 Medium User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration Plugin wp-user-frontend Broken Access Control Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite No login needed ≤ 4.3.1 CVE-2026-5459 Wordfence
7.5 High LatePoint - Calendar Booking Plugin for Appointments and Events Plugin latepoint Broken Access Control Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass No login needed ≤ 5.4.0 CVE-2026-5356 Wordfence
6.4 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute ≤ 2026.1 CVE-2026-6742 Wordfence
8.1 High WCFM - WooCommerce Multivendor Membership Plugin wc-multivendor-membership Broken Access Control WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite ≤ 2.11.10 CVE-2026-3688 Wordfence
6.4 Medium Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Plugin coming-soon Cross-Site Scripting Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode ≤ 6.20.2 CVE-2025-14785 Wordfence
6.3 Medium Themehunk Login Registration Plugin themehunk-login-registration Privilege Escalation Unauthenticated Privilege Escalation via 'role' Parameter ≤ 1.0.2 CVE-2026-14250 Wordfence
7.5 High My Calendar Plugin my-calendar SQL Injection Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters No login needed ≤ 3.7.8 CVE-2026-6854 Wordfence
4.9 Medium Recurio Plugin recurio SQL Injection Authenticated (Shop Manager+) SQL Injection via 'data' Parameter ≤ 1.1.3 CVE-2026-12936 Wordfence
7.5 High Tainacan Plugin tainacan SQL Injection Unauthenticated SQL Injection via 'geoquery' REST API Parameter No login needed ≤ 1.0.3 CVE-2026-6230 Wordfence
7.2 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter No login needed ≤ 1.8.8 CVE-2026-6818 Wordfence
8.1 High BookingPress Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.1.28 CVE-2026-12378 WPScan
5.3 Medium Bulk Order Update for WooCommerce Plugin bulk-order-update-for-woocommerce Path Traversal Unauthenticated Arbitrary File Read via 'csv_url' Parameter No login needed ≤ 1.6 CVE-2026-14500 Wordfence
6.4 Medium Sympl Repeater for ACF and Elementor Plugin acf-repeater-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via ACF Repeater Field Values ≤ 2.3 CVE-2026-10570 Wordfence
8.8 High WHMCS Bridge Plugin whmcs-bridge Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'ccce' Parameter ≤ 6.9 CVE-2026-14489 Wordfence
9.8 Critical WP Learn Manager Plugin learn-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action No login needed ≤ 1.1.8 CVE-2026-12153 Wordfence
4.3 Medium Wp Js Detect Plugin wp-js-detect Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0.9 CVE-2026-9731 Wordfence
5.3 Medium User Management Plugin user-management Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 1.2 CVE-2026-12097 Wordfence
4.4 Medium Chatra Live Chat + ChatBot + Cart Saver Plugin chatra-live-chat Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting ≤ 1.0.12 CVE-2026-12041 Wordfence
7.5 High Eventer Plugin SQL Injection Unauthenticated SQL Injection via 'code' Parameter No login needed ≤ 4.4.2 CVE-2026-9700 Wordfence
8.8 High DoLogin Security Plugin dologin Authentication Bypass Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token ≤ 4.3 CVE-2026-14495 Wordfence
6.1 Medium Social Share, Social Login and Social Comments Plugin super-socializer Cross-Site Scripting Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter No login needed ≤ 7.14.5 CVE-2026-11798 Wordfence
9.1 Critical Simple Coherent Form Plugin simple-coherent-form Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via 'id' Parameter No login needed ≤ 2.4.13 CVE-2026-14487 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only