WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,301–4,350 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 87 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Popup Box Plugin ays-popup-box Cross-Site Request Forgery Cross-Site Request Forgery to Popup Status Change No login needed ≤ 6.1.1 CVE-2026-1165 Wordfence
5.4 Medium SupportCandy – Helpdesk & Customer Support Ticket System Plugin supportcandy Broken Access Control Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 3.4.4 CVE-2026-1251 Wordfence
6.5 Medium SupportCandy – Helpdesk & Customer Support Ticket System Plugin supportcandy SQL Injection Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter ≤ 3.4.4 CVE-2026-0683 Wordfence
5.3 Medium Ajax Load More – Infinite Scroll, Lazy Load & Load More Plugin ajax-load-more Broken Access Control Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure No login needed ≤ 7.8.1 CVE-2025-15525 Wordfence
5.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Unauthenticated Booking Details Exposure No login needed ≤ 10.14.13 CVE-2026-1431 Wordfence
5.3 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 9.1.8 CVE-2025-15510 Wordfence
5.3 Medium WP Adminify Plugin adminify Information Disclosure Unauthenticated Sensitive Information Exposure via 'get-addons-list' REST API No login needed ≤ 4.0.7.7 CVE-2026-1060 Wordfence
4.3 Medium Stop Spammers Classic Plugin stop-spammer-registrations-plugin Cross-Site Request Forgery Cross-Site Request Forgery via Email Allowlist No login needed ≤ 2026.1 CVE-2025-14795 Wordfence
6.4 Medium Passster – Password Protect Pages and Content Plugin content-protector Cross-Site Scripting Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.2.24 CVE-2025-14865 Wordfence
4.4 Medium WP Google Ad Manager Plugin wp-google-ad-manager-plugin Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings ≤ 1.1.0 CVE-2026-1399 Wordfence
4.3 Medium Change WP URL Plugin change-wp-url Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1398 Wordfence
4.3 Medium Recooty Plugin recooty Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed 1.0.1 – 1.0.6 CVE-2025-14616 Wordfence
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.14 CVE-2025-14283 Wordfence
6.1 Medium SEO Links Interlinking Plugin seo-links-interlinking Cross-Site Scripting Reflected Cross-Site Scripting via 'google_error' Parameter No login needed ≤ 1.7.9.9.1 CVE-2025-14063 Wordfence
4.3 Medium Bitcoin Donate Button Plugin bitcoin-donate-button Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1380 Wordfence
5.3 Medium Vzaar Media Management Plugin vzaar-media-management Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 1.2 CVE-2026-1391 Wordfence
5.3 Medium Rupantorpay Plugin rupantorpay Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.0.0 CVE-2025-15511 Wordfence
4.3 Medium imwptip Plugin imwptip Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.1 CVE-2026-1377 Wordfence
4.4 Medium Ivory Search Plugin add-search-to-menu Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters ≤ 5.5.13 CVE-2026-1053 Wordfence
4.4 Medium Order Minimum/Maximum Amount Limits for WooCommerce Plugin order-minimum-amount-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Hide Add to Cart Content Fields ≤ 4.6.8 CVE-2026-1381 Wordfence
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary Settings Modification No login needed ≤ 6.0.7.4 CVE-2026-1054 Wordfence
4.3 Medium Document Embedder Plugin document-emberdder Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry Deletion ≤ 2.0.4 CVE-2026-1389 Wordfence
5.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Broken Access Control Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion No login needed ≤ 1.6.6 CVE-2026-1310 Wordfence
6.4 Medium Simple Folio Plugin simple-folio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Client name' and 'Link' Meta Fields ≤ 1.1.1 CVE-2025-14039 Wordfence
6.4 Medium Interactions – Create Interactive Experiences in the Block Editor Plugin Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-12709 Wordfence
6.4 Medium Buy Now Plus Plugin buy-now-plus Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0.2 CVE-2026-1295 Wordfence
6.4 Medium WPBITS Addons For Elementor Plugin wpbits-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8 CVE-2025-9082 Wordfence
5.3 Medium Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Broken Access Control Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export No login needed ≤ 1.4.5 CVE-2026-0825 Wordfence
6.4 Medium Forms Bridge Plugin forms-bridge Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 4.2.5 CVE-2026-1244 Wordfence
5.3 Medium User Activity Log Plugin Broken Access Control Unauthenticated Limited Arbitrary Option Update No login needed ≤ 2.2 CVE-2025-13471 WPScan
4.4 Medium Appointment Hour Booking – Booking Calendar Plugin appointment-hour-booking Cross-Site Scripting Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration ≤ 1.5.60 CVE-2026-1083 Wordfence
4.3 Medium Easy Replace Image Plugin easy-replace-image Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement ≤ 3.5.2 CVE-2026-1298 Wordfence
6.4 Medium Target Video Easy Publish Plugin brid-video-easy-publish Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter ≤ 3.8.8 CVE-2025-8072 Wordfence
6.4 Medium AI Engine Plugin ai-engine Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 3.3.2 CVE-2026-0746 Wordfence
5.3 Medium Link Invoice Payment for WooCommerce Plugin invoice-payment-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation No login needed ≤ 2.8.0 CVE-2025-14971 Wordfence
6.8 Medium Recipe Card Blocks Plugin SQL Injection Contributor+ SQLi < 3.4.13 Fixed in 3.4.13 CVE-2025-14973 WPScan
4.3 Medium CubeWP – All-in-One Dynamic Content Framework Plugin cubewp-framework Information Disclosure All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php ≤ 1.1.27 CVE-2025-6461 Wordfence
5.3 Medium WP Go Maps (formerly WP Google Maps) Plugin wp-google-maps Broken Access Control Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification No login needed ≤ 10.0.04 CVE-2026-0593 Wordfence
6.1 Medium Save as PDF Plugin by PDFCrowd Plugin save-as-pdf-by-pdfcrowd Cross-Site Scripting Reflected Cross-Site Scripting via options No login needed ≤ 4.5.5 CVE-2026-0862 Wordfence
5.3 Medium WP Directory Kit Plugin wpdirectorykit Information Disclosure Unauthenticated Email Exposure via wdk_public_action No login needed ≤ 1.4.9 CVE-2025-13920 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed ≤ 2.5.2 CVE-2025-13205 Wordfence
6.1 Medium Timeline Event History Plugin timeline-event-history Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2 CVE-2026-1127 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
4.3 Medium Friendly Functions for Welcart Plugin friendly-functions-for-welcart Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.5 CVE-2026-1208 Wordfence
4.4 Medium JavaScript Notifier Plugin javascript-notifier Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.2.8 CVE-2026-1191 Wordfence
4.4 Medium Responsive Header Plugin responsive-header Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters ≤ 1.0 CVE-2026-1300 Wordfence
6.4 Medium LeadBI Plugin leadbi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_id' Shortcode Attribute ≤ 1.7 CVE-2026-1189 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed ≤ 2.5.2 CVE-2025-13139 Wordfence
6.4 Medium CM CSS Columns Plugin cm-css-columns Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute ≤ 1.2.1 CVE-2026-1098 Wordfence
4.4 Medium Meta-box GalleryMeta Plugin meta-box-gallerymeta Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Image Caption ≤ 3.0.1 CVE-2026-1302 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only