WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,251–4,300 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 86 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Menu Icons by ThemeIsle Plugin menu-icons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 0.13.20 CVE-2026-1755 Wordfence
6.5 Medium Passster Plugin content-protector Broken Access Control ≤ 4.2.25 Fixed in 4.2.26 CVE-2026-25036 Patchstack
5.4 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-25028 Patchstack
5.4 Medium ThirstyAffiliates Plugin thirstyaffiliates Cross-Site Request Forgery No login needed ≤ 3.11.9 Fixed in 3.11.10 CVE-2026-25024 Patchstack
5.3 Medium Run Contests, Raffles, and Giveaways with ContestsWP Plugin contest-code-checker Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.7 Fixed in 2.1.1 CVE-2026-25023 Patchstack
5.4 Medium Mizan Demo Importer Plugin mizan-demo-importer Broken Access Control ≤ 0.1.3 Fixed in 0.1.4 CVE-2026-25021 Patchstack
4.3 Medium WP Sync for Notion Plugin wp-sync-for-notion Broken Access Control ≤ 1.7.0 Fixed in 1.7.1 CVE-2026-25020 Patchstack
5.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2026-25019 Patchstack
4.3 Medium Nelio Popups Plugin nelio-popups Broken Access Control ≤ 1.3.5 Fixed in 1.3.6 CVE-2026-25016 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.53 Fixed in 1.2.54 CVE-2026-25015 Patchstack
4.3 Medium Enter Addons Plugin enteraddons Cross-Site Request Forgery No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-25014 Patchstack
5.3 Medium WP Bannerize Pro Plugin wp-bannerize-pro Broken Access Control No login needed ≤ 1.11.0 Fixed in 1.11.1 CVE-2026-25012 Patchstack
4.3 Medium WP Custom Admin Interface Plugin wp-custom-admin-interface Broken Access Control ≤ 7.41 Fixed in 7.42 CVE-2026-25011 Patchstack
5.3 Medium Share This Image Plugin share-this-image Broken Access Control No login needed ≤ 2.09 Fixed in 2.10 CVE-2026-25010 Patchstack
5.3 Medium Hustle Plugin wordpress-popup Information Disclosure Sensitive Data Exposure No login needed ≤ 7.8.9.2 Fixed in 7.8.9.3 CVE-2026-24998 Patchstack
5.3 Medium Wired Impact Volunteer Management Plugin wired-impact-volunteer-management Broken Access Control No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2026-24997 Patchstack
4.3 Medium WPElemento Importer Plugin wpelemento-importer Broken Access Control ≤ 0.6.4 Fixed in 0.6.5 CVE-2026-24996 Patchstack
4.3 Medium Latest Post Shortcode Plugin latest-post-shortcode Broken Access Control ≤ 14.2.0 Fixed in 14.2.1 CVE-2026-24995 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.5.7.2 Fixed in 3.5.7.3 CVE-2026-24994 Patchstack
5.3 Medium Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2026-24992 Patchstack
5.3 Medium Extensions For CF7 Plugin extensions-for-cf7 Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-24991 Patchstack
5.4 Medium WP Docs Plugin wp-docs Broken Access Control ≤ 2.2.8 Fixed in 2.2.9 CVE-2026-24990 Patchstack
6.5 Medium The Events Calendar Shortcode & Block Plugin the-events-calendar-shortcode Cross-Site Scripting ≤ 3.1.1 Fixed in 3.1.2 CVE-2026-24988 Patchstack
5.4 Medium Simple Membership WP user Import Plugin simple-membership-wp-user-import Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-24986 Patchstack
4.3 Medium WP Forms Signature Contract Add-On Plugin wp-forms-signature-contract-add-on Broken Access Control Broken Access Control to Notice Dismissal ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-24985 Patchstack
6.5 Medium Visual Link Preview Plugin visual-link-preview Broken Access Control ≤ 2.2.9 Fixed in 2.3.0 CVE-2026-24984 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control No login needed ≤ 2.19.17 Fixed in 2.19.18 CVE-2026-24982 Patchstack
5.3 Medium Amelia Plugin ameliabooking Broken Access Control No login needed ≤ 1.2.38 Fixed in 2.0 CVE-2026-24967 Patchstack
4.3 Medium Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-24966 Patchstack
4.3 Medium Contest Gallery Plugin contest-gallery Broken Access Control ≤ 28.1.1 Fixed in 28.1.2 CVE-2026-24965 Patchstack
4.3 Medium Sigmize Plugin sigmize Cross-Site Request Forgery No login needed ≤ 0.0.9 Fixed in 0.0.10 CVE-2026-24962 Patchstack
5.4 Medium Grand Blog Theme grandblog Server-Side Request Forgery No login needed ≤ 3.1.5 Fixed in 3.1.5 CVE-2026-24961 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.12.2 Fixed in 2.7.12.3 CVE-2026-24958 Patchstack
6.5 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control ≤ 3.2.20 Fixed in 3.2.21 CVE-2026-24957 Patchstack
6.5 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Scripting ≤ 3.14.1 Fixed in 3.14.2 CVE-2026-24952 Patchstack
4.3 Medium myCred Plugin mycred Broken Access Control ≤ 2.9.7.3 Fixed in 2.9.7.4 CVE-2026-24951 Patchstack
4.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control ≤ 1.5.6.3 Fixed in 1.5.6.3 CVE-2026-24947 Patchstack
5.3 Medium Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Broken Access Control No login needed ≤ 3.5.34 Fixed in 3.5.35 CVE-2026-24945 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-24942 Patchstack
4.3 Medium Travelfic Toolkit Plugin travelfic-toolkit Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-24940 Patchstack
4.3 Medium Modula Image Gallery Plugin modula-best-grid-gallery Broken Access Control ≤ 2.13.6 Fixed in 2.13.7 CVE-2026-24939 Patchstack
5.9 Medium Better Search Plugin better-search Cross-Site Scripting ≤ 4.2.1 Fixed in 4.2.2 CVE-2026-24938 Patchstack
5.3 Medium Tutor LMS Plugin tutor Information Disclosure Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action No login needed ≤ 3.9.5 CVE-2026-1371 Wordfence
5.4 Medium Mail Mint Plugin mail-mint Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.19.2 CVE-2026-1447 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via '_elementor_data' Meta Field ≤ 3.20.7 CVE-2026-1210 Wordfence
5.3 Medium Spectra Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Information Disclosure Unauthenticated Information Disclosure in Sensitive Data No login needed ≤ 2.19.17 CVE-2026-0950 Wordfence
5.4 Medium Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Border Hero Widget ≤ 2.0.1 CVE-2025-14274 Wordfence
5.3 Medium WP ULike Plugin wp-ulike Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Log Deletion via 'id' Parameter No login needed ≤ 4.8.3.1 CVE-2026-0909 Wordfence
4.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Cross-Site Request Forgery Arbitrary Bookings Deletion via CSRF No login needed < 2.7.9 Fixed in 2.7.9 CVE-2026-0658 WPScan
6.4 Medium Stripe Green Downloads Plugin Cross-Site Scripting Stripe Green Downloads Wordpress Plugin 2.03 Persistent XSS via Settings 2.03 CVE-2022-50797 VulnCheck

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only