WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.
Showing 401–450 of 29,007 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Creator LMS | Other Other vulnerability Type |
≤ 1.2.19 Fixed in 1.2.20 |
CVE-2026-62083 |
Patchstack | |
| 5.4 Medium | Flexible PDF Coupons | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 1.14.11 Fixed in 1.14.12 |
CVE-2026-62081 |
Patchstack | |
| 6.5 Medium | Happy Addons for Elementor | Cross-Site Scripting |
≤ 3.23.1 Fixed in 3.50.0 |
CVE-2026-62080 |
Patchstack | |
| 6.5 Medium | Qi Addons For Elementor | Cross-Site Scripting |
≤ 1.11 Fixed in 1.11.1 |
CVE-2026-62079 |
Patchstack | |
| 6.5 Medium | Premium Addons for Elementor | Cross-Site Scripting |
≤ 4.11.105 Fixed in 4.11.106 |
CVE-2026-62078 |
Patchstack | |
| 7.1 High | WPFunnels | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.13.1 Fixed in 3.13.2 |
CVE-2026-27371 |
Patchstack | |
| 2.7 Low | Astra | Content Injection |
≤ 4.13.12 Fixed in 4.14.0 |
CVE-2026-27085 |
Patchstack | |
| 6.9 Medium | WPMobile.App | Information Disclosure Sensitive Data Exposure No login needed |
≤ 11.83 Fixed in 11.84 |
CVE-2026-96342 |
Patchstack | |
| 6.4 Medium | ReactPress | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'permalink' Parameter |
≤ 3.4.0 |
CVE-2026-92712 |
Wordfence | |
| 7.5 High | Product Designer App | Path Traversal Unauthenticated Arbitrary File Read via 'svg' Parameter in pdapp-render-design No login needed |
≤ 1.1.3 |
CVE-2026-75098 |
Wordfence | |
| 6.4 Medium | Viable URL Media Uploader | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.0 |
CVE-2025-14564 |
Wordfence | |
| 7.2 High | Post Views Stats Counter | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via User-Agent Header No login needed |
≤ 1.1.7 |
CVE-2026-97347 |
Wordfence | |
| 6.4 Medium | Real Estate Manager | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'before_price_text' Parameter |
≤ 7.3 |
CVE-2026-93908 |
Wordfence | |
| 6.5 Medium | WP Directory Kit | SQL Injection Authenticated (Custom+) SQL Injection via 'data_fields_list' Parameter |
≤ 1.5.4 |
CVE-2026-16596 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'background_image' Parameter |
≤ 5.7.2 |
CVE-2026-6173 |
Wordfence | |
| 7.5 High | Motors | SQL Injection Unauthenticated Blind SQL Injection via 'stm_lat'/'stm_lng' Parameters No login needed |
≤ 1.4.109 |
CVE-2026-6806 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute |
≤ 5.7.2 |
CVE-2026-6171 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_css_image_grid 'images' Shortcode Attribute |
≤ 5.7.2 |
CVE-2026-6170 |
Wordfence | |
| 6.4 Medium | Smart Slider 3 | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-href' Attribute in Custom HTML Block |
≤ 3.5.1.38 |
CVE-2026-14876 |
Wordfence | |
| 6.4 Medium | HT Mega Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table 'display_options' Setting |
≤ 3.1.1 |
CVE-2026-11895 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_service title |
≤ 5.7.2 |
CVE-2026-88037 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'caption' Parameter |
≤ 5.7.2 |
CVE-2026-6172 |
Wordfence | |
| 9.1 Critical | GiveWP | Authentication Bypass Broken Authentication No login needed |
≤ 4.16.9 Fixed in 4.17.0 |
CVE-2026-97196 |
Patchstack | |
| 7.5 High | Simply Schedule Appointments | Local File Inclusion Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter |
≤ 1.6.12.27 |
CVE-2026-89294 |
Wordfence | |
| 5.8 Medium | Broken Link Notifier | Server-Side Request Forgery Unauthenticated SSRF via Redirect Bypass No login needed |
1.3.1 – < 2.0.0.1 Fixed in 2.0.0.1 |
CVE-2026-97316 |
WPScan | |
| 5.3 Medium | Course Booking System | Information Disclosure Unauthenticated Attendee PII Disclosure via CSV Export No login needed |
7.0 – < 7.0.9 Fixed in 7.0.9 |
CVE-2026-96886 |
WPScan | |
| 2.7 Low | Media Library Organizer | Broken Access Control Contributor+ Arbitrary Taxonomy Term Creation |
2.0.4 – < 2.1.4 Fixed in 2.1.4 |
CVE-2026-94297 |
WPScan | |
| 5.3 Medium | YayReviews | Information Disclosure Unauthenticated Sensitive Data Disclosure via REST API No login needed |
1.0.4 – < 1.4.1 Fixed in 1.4.1 |
CVE-2026-94274 |
WPScan | |
| 5.3 Medium | InPost for WooCommerce | Broken Access Control Unauthenticated Order Status Forgery via Shipment Webhook No login needed |
1.7.5 – < 1.9.8 Fixed in 1.9.8 |
CVE-2026-93580 |
WPScan | |
| 8.8 High | Verge3D | Cross-Site Scripting Unauthenticated Stored XSS via File Storage API No login needed |
< 4.13.1 Fixed in 4.13.1 |
CVE-2026-92994 |
WPScan | |
| 6.8 Medium | Content Egg | Cross-Site Scripting Contributor+ Stored XSS via Import Queue |
< 11.9.0 Fixed in 11.9.0 |
CVE-2026-92424 |
WPScan | |
| 7.1 High | WP Mobile Menu | Cross-Site Scripting Stored XSS via CSRF No login needed |
2.7.4 – < 2.9 Fixed in 2.9 |
CVE-2026-91832 |
WPScan | |
| 4.4 Medium | EWWW Image Optimizer | Path Traversal Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler |
< 8.8.0 Fixed in 8.8.0 |
CVE-2026-91072 |
WPScan | |
| 6.6 Medium | EWWW Image Optimizer | PHP Object Injection Author+ PHP Object Injection via 'eio_page_settings' Post Meta |
8.6.0 – < 8.8.0 Fixed in 8.8.0 |
CVE-2026-91051 |
WPScan | |
| 4.3 Medium | Image Optimizer by Elementor | Information Disclosure Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks |
< 1.7.7 Fixed in 1.7.7 |
CVE-2026-90953 |
WPScan | |
| 7.5 High | Robin Image Optimizer | Cross-Site Scripting Unauthenticated Stored XSS via WebP URL Delivery HTML Parser No login needed |
2.0.0 – < 2.0.8 Fixed in 2.0.8 |
CVE-2026-89193 |
WPScan | |
| 4.3 Medium | Robin Image Optimizer | Information Disclosure Subscriber+ Plugin Settings Disclosure via fy_ajax |
< 2.0.8 Fixed in 2.0.8 |
CVE-2026-89190 |
WPScan | |
| 7.1 High | Vayu X | Broken Access Control Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation |
< 1.0.6 Fixed in 1.0.6 |
CVE-2026-88797 |
WPScan | |
| 3.4 Low | Safe Redirect Manager | Open Redirect Open Redirect via Wildcard Redirect Rules No login needed |
< 2.3.0 Fixed in 2.3.0 |
CVE-2026-88791 |
WPScan | |
| 6.8 Medium | Hostinger Reach | Cross-Site Scripting Contributor+ Stored XSS via formId Elementor Widget Attribute |
1.0.6 – < 1.8.3 Fixed in 1.8.3 |
CVE-2026-87777 |
WPScan | |
| 5.3 Medium | Connections Business Directory | Information Disclosure Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes No login needed |
≤ 10.4.67 |
CVE-2026-86789 |
WPScan | |
| 4.3 Medium | All in One Files Upload for WooCommerce | Broken Access Control Subscriber+ Arbitrary Plugin Settings Update |
< 2.0.17 Fixed in 2.0.17 |
CVE-2026-85576 |
WPScan | |
| 8.8 High | All in One Files Upload for WooCommerce | Cross-Site Scripting Unauthenticated Stored XSS via SVG Upload No login needed |
2.0.3 – < 2.0.17 Fixed in 2.0.17 |
CVE-2026-85573 |
WPScan | |
| 6.8 Medium | Audio Player Block | Cross-Site Scripting Contributor+ Stored XSS via Audio Download URL |
1.1.0 – < 1.6.3 Fixed in 1.6.3 |
CVE-2026-85415 |
WPScan | |
| 6.8 Medium | EmbedPress | Cross-Site Scripting Contributor+ Stored XSS via Elementor Widget showTitle Attribute |
4.4.9 – < 4.6.7 Fixed in 4.6.7 |
CVE-2026-85001 |
WPScan | |
| 5.3 Medium | New User Approve | Information Disclosure Unauthenticated PII Disclosure via Zapier API Key Bypass No login needed |
3.1.0 – < 3.2.10 Fixed in 3.2.10 |
CVE-2026-83560 |
WPScan | |
| 3.5 Low | Schema & Structured Data for WP & AMP | Cross-Site Scripting Editor+ Stored XSS via Taxonomy Term Fields |
< 1.67 Fixed in 1.67 |
CVE-2026-82127 |
WPScan | |
| 5.3 Medium | Solace Extra | Information Disclosure Unauthenticated Non-Published Post Content Disclosure via Preview Routes No login needed |
< 1.7.2 Fixed in 1.7.2 |
CVE-2026-80333 |
WPScan | |
| 9.8 Critical | Zella | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
< 2.6.3 Fixed in 2.6.3 |
CVE-2026-75873 |
WPScan | |
| 5.3 Medium | WP User Frontend | Broken Access Control Unauthenticated Account Creation with Registration Disabled No login needed |
2.5.8 – < 4.3.12 Fixed in 4.3.12 |
CVE-2026-75824 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.