WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 4,251–4,300 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.4 Medium | Product Video Gallery for Woocommerce | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter |
≤ 1.5.1.8 |
CVE-2026-10104 |
Wordfence | |
| 6.4 Medium | RSS Aggregator by Feedzy | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute |
≤ 5.2.1 |
CVE-2026-13252 |
Wordfence | |
| 5.3 Medium | Kirki | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters No login needed |
≤ 6.0.11 |
CVE-2026-12472 |
Wordfence | |
| 4.3 Medium | JoomSport | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action |
≤ 5.7.8 |
CVE-2026-12134 |
Wordfence | |
| 5.3 Medium | Kirki | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action No login needed |
≤ 6.0.11 |
CVE-2026-12122 |
Wordfence | |
| 5.3 Medium | My Calendar | Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter No login needed |
≤ 3.7.14 |
CVE-2026-11896 |
Wordfence | |
| 5.3 Medium | JetFormBuilder | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter No login needed |
≤ 3.6.3 |
CVE-2026-13459 |
Wordfence | |
| 7.2 High | WP Database Backup | Remote Code Execution Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter |
≤ 7.11 |
CVE-2026-9834 |
Wordfence | |
| 5.3 Medium | LatePoint | Broken Access Control Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter No login needed |
≤ 5.6.2 |
CVE-2026-12657 |
Wordfence | |
| 5.3 Medium | Appointment Bookings for Zoom GoogleMeet and more – Wappointment | Broken Access Control Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter No login needed |
≤ 2.7.6 |
CVE-2026-9188 |
Wordfence | |
| 6.5 Medium | User Registration & Membership | Authentication Bypass Unauthenticated Paid Membership Bypass No login needed |
< 5.2.0 Fixed in 5.2.0 |
CVE-2026-11965 |
WPScan | |
| 2.7 Low | Adminify | Information Disclosure Contributor+ Sensitive Information Disclosure via Global Search AJAX |
< 4.2.10 Fixed in 4.2.10 |
CVE-2026-11781 |
WPScan | |
| 2.7 Low | Fluent Forms | Broken Access Control Form Manager+ Cross-Form Submission Entry Deletion via IDOR |
< 6.2.5 Fixed in 6.2.5 |
CVE-2026-11578 |
WPScan | |
| 6.8 Medium | YOOtheme Pro | Cross-Site Scripting Author+ Stored XSS via UIkit Data Attributes |
< 5.0.35 Fixed in 5.0.35 |
CVE-2026-10077 |
WPScan | |
| 6.4 Medium | GiveWP | Cross-Site Scripting Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form |
≤ 4.16.1 |
CVE-2026-13704 |
Wordfence | |
| 4.3 Medium | Email Subscribers & Newsletters | Broken Access Control Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action |
≤ 5.9.27 |
CVE-2026-11592 |
Wordfence | |
| 6.4 Medium | Insert Pages | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names) |
≤ 3.11.4 |
CVE-2026-10089 |
Wordfence | |
| 5.3 Medium | Academy LMS | Broken Access Control Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure No login needed |
≤ 3.8.1 |
CVE-2026-5348 |
Wordfence | |
| 4.9 Medium | Houzez Property Feed | SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter |
≤ 2.5.46 |
CVE-2026-13357 |
Wordfence | |
| 8.1 High | Image Optimizer | Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection |
≤ 1.7.4 |
CVE-2026-5821 |
Wordfence | |
| 7.5 High | Request a Quote Form | Remote Code Execution Unauthenticated Code Injection via 'path' Parameter No login needed |
≤ 2.5.5 |
CVE-2026-14249 |
Wordfence | |
| 4.3 Medium | Envo's Templates & Widgets for Elementor and WooCommerce | Broken Access Control Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting |
≤ 1.4.26 |
CVE-2026-11600 |
Wordfence | |
| 6.5 Medium | Shortcodes and extra features for Phlox | Cross-Site Scripting |
≤ 2.17.16 |
CVE-2026-57737 |
Patchstack | |
| 7.4 High | HubSpot | Information Disclosure Sensitive Data Exposure |
≤ 11.3.51 |
CVE-2026-57736 |
Patchstack | |
| 7.4 High | VikBooking Hotel Booking Engine & PMS | Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed |
≤ 1.8.12 Fixed in 1.8.13 |
CVE-2026-57723 |
Patchstack | |
| 5.9 Medium | Enable Media Replace | Cross-Site Scripting |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2026-57722 |
Patchstack | |
| 5.3 Medium | ApplyOnline | Broken Access Control No login needed |
≤ 2.6.7.6 Fixed in 2.6.8 |
CVE-2026-57721 |
Patchstack | |
| 4.3 Medium | ThumbPress | Broken Access Control |
≤ 6.3.2 Fixed in 6.3.3 |
CVE-2026-57720 |
Patchstack | |
| 5.3 Medium | Webba Booking | Broken Access Control No login needed |
≤ 6.4.13 Fixed in 6.4.14 |
CVE-2026-27409 |
Patchstack | |
| 9.8 Critical | PrivateContent | Privilege Escalation No login needed |
≤ 9.9.2 |
CVE-2026-57692 |
Patchstack | |
| 8.8 High | LatePoint | Privilege Escalation Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter |
≤ 5.6.3 |
CVE-2026-13228 |
Wordfence | |
| 7.2 High | NEX-Forms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter No login needed |
≤ 9.2.2 |
CVE-2026-12142 |
Wordfence | |
| 6.4 Medium | WP Photo Album Plus | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute |
≤ 9.1.13.005 |
CVE-2026-10095 |
Wordfence | |
| 5.3 Medium | Woffice | Broken Access Control No login needed |
< 5.4.33 Fixed in 5.4.33 |
CVE-2026-27435 |
Patchstack | |
| 6.1 Medium | VikBooking Hotel Booking Engine & PMS | Cross-Site Scripting Reflected Cross-Site Scripting via 'layoutstyle' Parameter No login needed |
≤ 1.8.12 |
CVE-2026-12754 |
Wordfence | |
| 6.5 Medium | MotoPress Appointment Booking | SQL Injection Authenticated (Staff+) SQL Injection via 's' Parameter |
≤ 2.4.5 |
CVE-2026-13454 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute |
≤ 3.3.60 |
CVE-2026-13733 |
Wordfence | |
| 8.8 High | RegistrationMagic | Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter |
≤ 6.0.9.1 |
CVE-2026-12158 |
Wordfence | |
| 4.3 Medium | Slim SEO | Information Disclosure Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter |
≤ 4.9.8 |
CVE-2026-12408 |
Wordfence | |
| 9.8 Critical | SMS Alert | Privilege Escalation Unauthenticated Privilege Escalation via Arbitrary Password Reset No login needed |
≤ 3.9.5 |
CVE-2026-11387 |
Wordfence | |
| 4.3 Medium | Qi Blocks | Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter |
≤ 1.4.9 |
CVE-2026-10096 |
Wordfence | |
| 6.4 Medium | LearnPress | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute |
≤ 4.4.0 |
CVE-2026-12732 |
Wordfence | |
| 4.3 Medium | Motors | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter |
≤ 1.4.111 |
CVE-2026-12435 |
Wordfence | |
| 8.8 High | Dokan Pro | Privilege Escalation Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint |
≤ 5.0.4 |
CVE-2026-12224 |
Wordfence | |
| 4.3 Medium | Salon Booking System | Broken Access Control Subscriber+ Booking Approval Bypass |
< 10.30.20 Fixed in 10.30.20 |
CVE-2026-11887 |
WPScan | |
| 7.2 High | WebAuthn Provider for Two Factor | Authentication Bypass WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass |
< 2.5.6 Fixed in 2.5.6 |
CVE-2026-11883 |
WPScan | |
| 3.1 Low | Fluent Forms | Broken Access Control Subscriber+ Subscription Cancellation via IDOR |
< 6.2.1 Fixed in 6.2.1 |
CVE-2026-11880 |
WPScan | |
| 8.1 High | Advanced Form Integration | Privilege Escalation Unauthenticated Privilege Escalation via Breakdance Form Role Mapping No login needed |
< 2.1.1 Fixed in 2.1.1 |
CVE-2026-11794 |
WPScan | |
| 4.2 Medium | User Submitted Posts | Cross-Site Scripting Unauthenticated Stored XSS via Author Name No login needed |
< 20260608 Fixed in 20260608 |
CVE-2026-11570 |
WPScan | |
| 7.5 High | Product Configurator for WooCommerce | Information Disclosure Unauthenticated Private/Draft Product Data Disclosure via pc_get_data No login needed |
< 1.7.3 Fixed in 1.7.3 |
CVE-2026-11568 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.