WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,351–4,400 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 88 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium AdminQuickbar Plugin adminquickbar Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.9.3 CVE-2025-14630 Wordfence
4.4 Medium Postalicious Plugin postalicious Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 3.0.1 CVE-2026-1266 Wordfence
4.3 Medium Meta-box GalleryMeta Plugin meta-box-gallerymeta Broken Access Control Missing Authorization to Authenticated (Author+) Gallery Management ≤ 3.0.1 CVE-2026-0687 Wordfence
4.3 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update 4.1.0 – 4.6.4 CVE-2025-15516 Wordfence
4.3 Medium Moderate Selected Posts Plugin moderate-selected-posts Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.4 CVE-2025-14907 Wordfence
6.4 Medium Administrative Shortcodes Plugin administrative-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'login' and 'logout' Shortcode Attributes ≤ 0.3.4 CVE-2026-1099 Wordfence
4.3 Medium Login Page Editor Plugin login-page-editor Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2 CVE-2026-1088 Wordfence
6.1 Medium JustClick registration Plugin justclick-subscriber Cross-Site Scripting Reflected Cross-Site Scripting via PHP_SELF No login needed ≤ 0.1 CVE-2025-13676 Wordfence
6.4 Medium ThemeRuby Multi Authors Plugin themeruby-multi-authors Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes ≤ 1.0.0 CVE-2026-1097 Wordfence
5.3 Medium Wise Analytics Plugin wise-analytics Broken Access Control Missing Authorization to Unauthenticated Arbitrary Analytics Database Disclosure via 'name' Parameter No login needed ≤ 1.1.9 CVE-2025-14609 Wordfence
4.4 Medium Cookie consent for developers Plugin cookie-consent-for-developers Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Multiple Settings Fields ≤ 1.7.1 CVE-2026-1084 Wordfence
6.4 Medium GZSEO Plugin gzseo Broken Access Control Authenticated (Contributor+) Authorization Bypass to Stored Cross-Site Scripting ≤ 2.0.11 CVE-2025-14941 Wordfence
5.3 Medium Wizit Gateway for WooCommerce Plugin wizit-gateway-for-woocommerce Broken Access Control Missing Authentication to Unauthenticated Arbitrary Order Cancellation No login needed ≤ 1.3.1 CVE-2025-14843 Wordfence
4.3 Medium Set Bulk Post Categories Plugin set-bulk-post-categories Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Post Category Update No login needed ≤ 1.1 CVE-2026-1081 Wordfence
4.3 Medium ZT Captcha Plugin zt-captcha Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.4 CVE-2026-1075 Wordfence
5.3 Medium Alchemist Ajax Upload Plugin alchemist-ajax-upload Broken Access Control Missing Authorization to Unauthenticated Arbitrary Media File Deletion No login needed ≤ 1.1 CVE-2025-14629 Wordfence
5.4 Medium AIKTP Plugin aiktp Broken Access Control Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions ≤ 5.0.04 CVE-2026-1103 Wordfence
6.4 Medium Alpha Blocks Plugin alpha-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alpha_block_css' Post Meta ≤ 1.5.0 CVE-2025-14985 Wordfence
6.4 Medium Canto Testimonials Plugin canto-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'fx' Shortcode Attribute ≤ 1.0 CVE-2026-1095 Wordfence
4.9 Medium WP-ClanWars Plugin wp-clanwars SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 2.0.1 CVE-2026-0806 Wordfence
5.4 Medium Same Category Posts Plugin same-category-posts Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Widget Title Placeholder ≤ 1.1.19 CVE-2025-14797 Wordfence
4.3 Medium Star Review Manager Plugin star-review-manager Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.2 CVE-2026-1076 Wordfence
4.3 Medium WP Youtube Video Gallery Plugin wp-youtube-video-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0 CVE-2025-14906 Wordfence
6.4 Medium VK Google Job Posting Manager Plugin vk-google-job-posting-manager Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Job Description Field ≤ 1.2.23 CVE-2025-12836 Wordfence
4.3 Medium Alex User Counter Plugin user-counter Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 6.0 CVE-2026-1070 Wordfence
4.3 Medium Simple Crypto Shortcodes Plugin simple-crypto-shortcodes Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0.2 CVE-2025-14903 Wordfence
6.5 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion No login needed ≤ 4.6.4 CVE-2025-14947 Wordfence
4.3 Medium Sugar Calendar (Lite) Plugin sugar-calendar-lite Broken Access Control ≤ 3.9.1 Fixed in 3.10.0 CVE-2026-24636 Patchstack
5.3 Medium Ultimate Reviews Plugin ultimate-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.16 Fixed in 3.2.17 CVE-2026-24634 Patchstack
5.3 Medium Add Expires Headers & Optimized Minify Plugin add-expires-headers Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.3.0 CVE-2026-24633 Patchstack
5.9 Medium Delay Redirects Plugin delay-redirects Cross-Site Scripting ≤ 1.0.0 CVE-2026-24632 Patchstack
5.4 Medium Rosebud Theme rosebud Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4 CVE-2026-24631 Patchstack
6.5 Medium Stylish Cost Calculator Plugin stylish-cost-calculator Cross-Site Scripting ≤ 8.2.9 CVE-2026-24630 Patchstack
5.9 Medium Web Accessibility with Max Access Plugin accessibility-toolbar Cross-Site Scripting ≤ 2.1.0 CVE-2026-24629 Patchstack
4.3 Medium Trusona Plugin trusona Broken Access Control ≤ 2.0.0 CVE-2026-24627 Patchstack
5.9 Medium Logo Slider Plugin logo-slider-wp Cross-Site Scripting ≤ 5.1.1 CVE-2026-24626 Patchstack
5.3 Medium File Uploads Addon for WooCommerce Plugin woo-addon-uploads Arbitrary File Upload Broken Access Control No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2026-24625 Patchstack
5.4 Medium Suggestion Toolkit Plugin suggestion-toolkit Broken Access Control ≤ 5.0 CVE-2026-24622 Patchstack
5.9 Medium Terms descriptions Plugin terms-descriptions Cross-Site Scripting ≤ 3.4.9 Fixed in 3.4.10 CVE-2026-24621 Patchstack
5.9 Medium Landing Page Builder Plugin page-builder-add Cross-Site Scripting ≤ 1.5.3.4 Fixed in 1.5.3.5 CVE-2026-24620 Patchstack
5.3 Medium PopCash.Net Code Integration Tool Plugin popcashnet-code-integration-tool Broken Access Control No login needed ≤ 1.8 Fixed in 2.0 CVE-2026-24619 Patchstack
6.5 Medium Easy Modal Plugin easy-modal Cross-Site Scripting ≤ 2.1.0 CVE-2026-24617 Patchstack
6.5 Medium WP Popups Plugin wp-popups-lite Broken Access Control ≤ 2.2.0.5 Fixed in 2.2.0.6 CVE-2026-24616 Patchstack
5.3 Medium Cream Magazine Plugin cream-magazine Broken Access Control No login needed ≤ 2.1.10 CVE-2026-24615 Patchstack
5.9 Medium Flex QR Code Generator Plugin flex-qr-code-generator Cross-Site Scripting ≤ 1.2.10 CVE-2026-24614 Patchstack
5.3 Medium Ecwid Shopping Cart Plugin ecwid-shopping-cart Broken Access Control No login needed ≤ 7.0.6 Fixed in 7.0.7 CVE-2026-24613 Patchstack
5.3 Medium Orchid Store Plugin orchid-store Broken Access Control No login needed ≤ 1.5.15 CVE-2026-24612 Patchstack
5.3 Medium Travel Monster Plugin travel-monster Broken Access Control No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-24607 Patchstack
5.3 Medium Bayarcash WooCommerce Plugin bayarcash-wc Broken Access Control No login needed ≤ 4.3.13 Fixed in 4.3.14 CVE-2026-24606 Patchstack
4.3 Medium X Addons for Elementor Plugin x-addons-elementor Broken Access Control ≤ 1.0.23 CVE-2026-24605 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only