WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,101–4,150 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 83 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High 多说社会化评论框 Plugin duoshuo Privilege Escalation Unauthenticated Privilege Escalation via api.php 'option'/'value' Parameters ≤ 1.2 CVE-2026-14482 Wordfence
9.8 Critical Eventer Plugin Privilege Escalation Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation No login needed ≤ 4.4.2 CVE-2026-9701 Wordfence
7.5 High Jssor Slider by jssor.com Plugin jssor-slider Path Traversal Unauthenticated Arbitrary File Read via 'url' Parameter No login needed ≤ 3.1.24 CVE-2026-14244 Wordfence
8.8 High Widget Logic Visual Plugin widget-logic-visual Remote Code Execution Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter ≤ 1.52 CVE-2026-14158 Wordfence
7.5 High Backstage Plugin backstage Privilege Escalation Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities No login needed ≤ 1.4.2 CVE-2026-9842 Wordfence
7.5 High AMP for WP Plugin accelerated-mobile-pages Remote Code Execution Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload ≤ 1.1.12 CVE-2026-6101 Wordfence
9.8 Critical Uncanny Automator Pro Plugin Other Backdoor via Compromised Vendor Update Server No login needed 7.3.0.5 – < 7.3.0.6 Fixed in 7.3.0.6 CVE-2026-12375 WPScan
8.7 High Frontend File Manager Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal No login needed ≤ 23.6 CVE-2026-12277 WPScan
4.6 Medium WP Travel Engine Plugin wp-travel-engine Path Traversal Subscriber+ Arbitrary Media File Move via user_profile_image < 6.8.1 Fixed in 6.8.1 CVE-2026-10834 WPScan
9.0 Critical DoLeads Integrator Plugin Remote Code Execution Unauthenticated RCE No login needed ≤ 0.65 CVE-2026-4375 WPScan
9.8 Critical WPFunnels Plugin wpfunnels Remote Code Execution Unauthenticated Remote Code Execution via 'postData' Parameter No login needed ≤ 3.12.7 CVE-2026-14345 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 2.7.9.8 CVE-2026-11328 Wordfence
6.4 Medium Reviews Widgets for Google, Yelp & TripAdvisor Plugin fb-reviews-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute ≤ 2.7.3 CVE-2026-12154 Wordfence
8.1 High Admin and Site Enhancements Plugin Privilege Escalation Unauthenticated Administrator-Role Restoration via reset-for Parameter No login needed 7.6.3 – < 8.8.4 Fixed in 8.8.4 CVE-2026-12083 WPScan
9.1 Critical Multiple elFinder Plugins Plugin Remote Code Execution Authenticated OS Command Injection < 1.1.9, < 5.4.12, < 2.1.1, … Fixed in 1.1.9 CVE-2026-6382 WPScan
8.8 High FileOrganizer Plugin fileorganizer Arbitrary File Upload Authenticated Arbitrary File Upload via elFinder File Operations < 1.2.0 Fixed in 1.2.0 CVE-2026-11962 WPScan
8.8 High Simple Membership Plugin simple-membership Cross-Site Scripting Unauthenticated Stored XSS via Stripe Webhook API Version No login needed < 4.7.5 Fixed in 4.7.5 CVE-2026-11855 WPScan
8.0 High Ultimate Member Plugin ultimate-member Cross-Site Scripting Subscriber+ Stored XSS via Custom Textarea Profile Fields < 2.12.0 Fixed in 2.12.0 CVE-2026-11766 WPScan
8.8 High AllCoach Plugin allcoach Privilege Escalation Unauthenticated Account Takeover < 1.0.2 Fixed in 1.0.2 CVE-2026-10830 WPScan
7.5 High WANotifier Plugin notifier Local File Inclusion Subscriber+ LFI < 2.6 Fixed in 2.6 CVE-2024-6228 WPScan
4.3 Medium CrawlWP SEO Plugin mihdan-index-now Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2026-59520 Patchstack
5.3 Medium FormLayer Plugin formlayer Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2026-59519 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.9.9 Fixed in 2.8.0 CVE-2026-59511 Patchstack
4.3 Medium RTMKit Plugin rometheme-for-elementor Local File Inclusion Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter ≤ 2.0.7 CVE-2026-5137 Wordfence
5.3 Medium LatePoint Plugin latepoint Broken Access Control Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer Step No login needed ≤ 5.6.1 CVE-2026-11398 Wordfence
6.4 Medium GenerateBlocks Plugin generateblocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute ≤ 2.2.1 CVE-2026-9756 Wordfence
6.4 Medium Zakra Theme zakra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST API ≤ 4.2.0 CVE-2026-4804 Wordfence
4.3 Medium Ad Inserter Plugin ad-inserter Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode Attribute ≤ 2.8.16 CVE-2026-11900 Wordfence
5.4 Medium CURCY Plugin woo-multi-currency Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'exchange' Parameter ≤ 2.2.14 CVE-2026-11778 Wordfence
7.2 High Comments Plugin wpdiscuz Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'Website' Field No login needed ≤ 7.6.56 CVE-2026-9148 Wordfence
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure ≤ 11.1.4 CVE-2026-9230 Wordfence
6.4 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' Parameter ≤ 2.0.7 CVE-2026-8351 Wordfence
6.4 Medium JSON API User Plugin json-api-user Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'content' Parameter ≤ 4.1.0 CVE-2026-9626 Wordfence
5.3 Medium MotoPress Appointment Booking Plugin motopress-appointment-lite Broken Access Control Unauthenticated Insecure Direct Object Reference to 'payment_details.booking_id' Parameter No login needed ≤ 2.4.4 CVE-2026-9180 Wordfence
6.4 Medium CM Business Directory Plugin cm-business-directory Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Business Address Meta Fields ≤ 1.5.7 CVE-2026-8892 Wordfence
5.5 Medium WP Import Export Lite Plugin wp-import-export-lite Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via 'file_url' Parameter ≤ 3.9.30 CVE-2026-11397 Wordfence
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'real_val__' Parameter No login needed ≤ 9.2.2 CVE-2026-13040 Wordfence
9.1 Critical Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.5.2 CVE-2026-9725 Wordfence
7.5 High AR for WooCommerce Plugin ar-for-woocommerce Path Traversal Unauthenticated Path Traversal to Arbitrary File Read via 'file' Parameter No login needed ≤ 8.40 CVE-2026-14352 Wordfence
5.3 Medium Ninja Forms - File Uploads Plugin ninja-forms-uploads Arbitrary File Upload File Uploads <= 3.3.29 - Missing Authorization to Unauthenticated Log Disclosure and Deletion via debug-log/delete-all and debug-log/get-all REST Endpoints No login needed ≤ 3.3.29 CVE-2026-12557 Wordfence
6.4 Medium Ultimate Member Plugin ultimate-member Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Non-HTML Custom Textarea Profile Field ≤ 2.11.4 CVE-2026-8489 Wordfence
7.5 High AR Plugin ar-for-wordpress Path Traversal Unauthenticated Arbitrary File Read via 'file' Parameter No login needed ≤ 8.40 CVE-2026-14327 Wordfence
6.4 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes ≤ 2.3.0 CVE-2026-12731 Wordfence
4.9 Medium Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 4.3.5 CVE-2026-12920 Wordfence
6.4 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute ≤ 2.3.0 CVE-2026-12734 Wordfence
4.3 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action ≤ 2.3.0 CVE-2026-12729 Wordfence
8.1 High TinyPNG Plugin tiny-compress-images Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta ≤ 3.6.13 CVE-2026-7311 Wordfence
9.8 Critical Divi Form Builder Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter No login needed ≤ 5.1.8 CVE-2026-5524 Wordfence
5.3 Medium Sendcloud Shipping Plugin sendcloud-connected-shipping Broken Access Control No login needed ≤ 1.0.29 CVE-2026-57760 Patchstack
7.1 High Slider Revolution Plugin revslider Cross-Site Scripting No login needed 7.0.0 – 7.0.16 Fixed in 7.1.0 CVE-2026-57678 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only