WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,251–4,300 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 86 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium Product Video Gallery for Woocommerce Plugin product-video-gallery-slider-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter ≤ 1.5.1.8 CVE-2026-10104 Wordfence
6.4 Medium RSS Aggregator by Feedzy Plugin feedzy-rss-feeds Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute ≤ 5.2.1 CVE-2026-13252 Wordfence
5.3 Medium Kirki Plugin kirki Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters No login needed ≤ 6.0.11 CVE-2026-12472 Wordfence
4.3 Medium JoomSport Plugin joomsport-sports-league-results-management Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action ≤ 5.7.8 CVE-2026-12134 Wordfence
5.3 Medium Kirki Plugin kirki Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action No login needed ≤ 6.0.11 CVE-2026-12122 Wordfence
5.3 Medium My Calendar Plugin my-calendar Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter No login needed ≤ 3.7.14 CVE-2026-11896 Wordfence
5.3 Medium JetFormBuilder Plugin jetformbuilder Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter No login needed ≤ 3.6.3 CVE-2026-13459 Wordfence
7.2 High WP Database Backup Plugin wp-database-backup Remote Code Execution Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter ≤ 7.11 CVE-2026-9834 Wordfence
5.3 Medium LatePoint Plugin latepoint Broken Access Control Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter No login needed ≤ 5.6.2 CVE-2026-12657 Wordfence
5.3 Medium Appointment Bookings for Zoom GoogleMeet and more – Wappointment Plugin wappointment Broken Access Control Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter No login needed ≤ 2.7.6 CVE-2026-9188 Wordfence
6.5 Medium User Registration & Membership Plugin user-registration Authentication Bypass Unauthenticated Paid Membership Bypass No login needed < 5.2.0 Fixed in 5.2.0 CVE-2026-11965 WPScan
2.7 Low Adminify Plugin adminify Information Disclosure Contributor+ Sensitive Information Disclosure via Global Search AJAX < 4.2.10 Fixed in 4.2.10 CVE-2026-11781 WPScan
2.7 Low Fluent Forms Plugin fluentform Broken Access Control Form Manager+ Cross-Form Submission Entry Deletion via IDOR < 6.2.5 Fixed in 6.2.5 CVE-2026-11578 WPScan
6.8 Medium YOOtheme Pro Theme Cross-Site Scripting Author+ Stored XSS via UIkit Data Attributes < 5.0.35 Fixed in 5.0.35 CVE-2026-10077 WPScan
6.4 Medium GiveWP Plugin give Cross-Site Scripting Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form ≤ 4.16.1 CVE-2026-13704 Wordfence
4.3 Medium Email Subscribers & Newsletters Plugin email-subscribers Broken Access Control Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action ≤ 5.9.27 CVE-2026-11592 Wordfence
6.4 Medium Insert Pages Plugin insert-pages Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names) ≤ 3.11.4 CVE-2026-10089 Wordfence
5.3 Medium Academy LMS Plugin academy Broken Access Control Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure No login needed ≤ 3.8.1 CVE-2026-5348 Wordfence
4.9 Medium Houzez Property Feed Plugin houzez-property-feed SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 2.5.46 CVE-2026-13357 Wordfence
8.1 High Image Optimizer Plugin image-optimization Arbitrary File Deletion Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection ≤ 1.7.4 CVE-2026-5821 Wordfence
7.5 High Request a Quote Form Plugin request-a-quote Remote Code Execution Unauthenticated Code Injection via 'path' Parameter No login needed ≤ 2.5.5 CVE-2026-14249 Wordfence
4.3 Medium Envo's Templates & Widgets for Elementor and WooCommerce Plugin envo-elementor-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting ≤ 1.4.26 CVE-2026-11600 Wordfence
6.5 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Cross-Site Scripting ≤ 2.17.16 CVE-2026-57737 Patchstack
7.4 High HubSpot Plugin leadin Information Disclosure Sensitive Data Exposure ≤ 11.3.51 CVE-2026-57736 Patchstack
7.4 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 1.8.12 Fixed in 1.8.13 CVE-2026-57723 Patchstack
5.9 Medium Enable Media Replace Plugin enable-media-replace Cross-Site Scripting ≤ 4.2.1 Fixed in 4.2.2 CVE-2026-57722 Patchstack
5.3 Medium ApplyOnline Plugin apply-online Broken Access Control No login needed ≤ 2.6.7.6 Fixed in 2.6.8 CVE-2026-57721 Patchstack
4.3 Medium ThumbPress Plugin image-sizes Broken Access Control ≤ 6.3.2 Fixed in 6.3.3 CVE-2026-57720 Patchstack
5.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control No login needed ≤ 6.4.13 Fixed in 6.4.14 CVE-2026-27409 Patchstack
9.8 Critical PrivateContent Plugin private-content Privilege Escalation No login needed ≤ 9.9.2 CVE-2026-57692 Patchstack
8.8 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter ≤ 5.6.3 CVE-2026-13228 Wordfence
7.2 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter No login needed ≤ 9.2.2 CVE-2026-12142 Wordfence
6.4 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute ≤ 9.1.13.005 CVE-2026-10095 Wordfence
5.3 Medium Woffice Theme woffice Broken Access Control No login needed < 5.4.33 Fixed in 5.4.33 CVE-2026-27435 Patchstack
6.1 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Reflected Cross-Site Scripting via 'layoutstyle' Parameter No login needed ≤ 1.8.12 CVE-2026-12754 Wordfence
6.5 Medium MotoPress Appointment Booking Plugin motopress-appointment-lite SQL Injection Authenticated (Staff+) SQL Injection via 's' Parameter ≤ 2.4.5 CVE-2026-13454 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute ≤ 3.3.60 CVE-2026-13733 Wordfence
8.8 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter ≤ 6.0.9.1 CVE-2026-12158 Wordfence
4.3 Medium Slim SEO Plugin slim-seo Information Disclosure Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter ≤ 4.9.8 CVE-2026-12408 Wordfence
9.8 Critical SMS Alert Plugin sms-alert Privilege Escalation Unauthenticated Privilege Escalation via Arbitrary Password Reset No login needed ≤ 3.9.5 CVE-2026-11387 Wordfence
4.3 Medium Qi Blocks Plugin qi-blocks Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter ≤ 1.4.9 CVE-2026-10096 Wordfence
6.4 Medium LearnPress Plugin learnpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute ≤ 4.4.0 CVE-2026-12732 Wordfence
4.3 Medium Motors Plugin motors-car-dealership-classified-listings Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter ≤ 1.4.111 CVE-2026-12435 Wordfence
8.8 High Dokan Pro Plugin Privilege Escalation Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint ≤ 5.0.4 CVE-2026-12224 Wordfence
4.3 Medium Salon Booking System Plugin salon-booking-system Broken Access Control Subscriber+ Booking Approval Bypass < 10.30.20 Fixed in 10.30.20 CVE-2026-11887 WPScan
7.2 High WebAuthn Provider for Two Factor Plugin two-factor-provider-webauthn Authentication Bypass WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass < 2.5.6 Fixed in 2.5.6 CVE-2026-11883 WPScan
3.1 Low Fluent Forms Plugin fluentform Broken Access Control Subscriber+ Subscription Cancellation via IDOR < 6.2.1 Fixed in 6.2.1 CVE-2026-11880 WPScan
8.1 High Advanced Form Integration Plugin Privilege Escalation Unauthenticated Privilege Escalation via Breakdance Form Role Mapping No login needed < 2.1.1 Fixed in 2.1.1 CVE-2026-11794 WPScan
4.2 Medium User Submitted Posts Plugin user-submitted-posts Cross-Site Scripting Unauthenticated Stored XSS via Author Name No login needed < 20260608 Fixed in 20260608 CVE-2026-11570 WPScan
7.5 High Product Configurator for WooCommerce Plugin product-configurator-for-woocommerce Information Disclosure Unauthenticated Private/Draft Product Data Disclosure via pc_get_data No login needed < 1.7.3 Fixed in 1.7.3 CVE-2026-11568 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only