WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 401–450 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Business Directory Plugin business-directory-plugin Cross-Site Scripting ≤ 6.4.24 Fixed in 6.4.25 CVE-2026-61959 Patchstack
5.3 Medium SureCart Plugin surecart Broken Access Control No login needed ≤ 4.6.2 Fixed in 4.6.3 CVE-2026-32548 Patchstack
5.3 Medium CAPTCHA 4WP Plugin advanced-nocaptcha-recaptcha Authentication Bypass Captcha Bypass No login needed ≤ 7.6.0 CVE-2026-32469 Patchstack
5.3 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 8.9.0 Fixed in 8.9.1 CVE-2026-28180 Patchstack
5.9 Medium FiboSearch Plugin ajax-search-for-woocommerce Cross-Site Scripting ≤ 1.33.0 Fixed in 1.34.0 CVE-2026-28179 Patchstack
6.5 Medium Powerkit Plugin powerkit Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2026-28178 Patchstack
5.3 Medium YITH WooCommerce Zoom Magnifier Plugin yith-woocommerce-zoom-magnifier Information Disclosure Sensitive Data Exposure No login needed ≤ 2.52.0 Fixed in 2.52.1 CVE-2026-28169 Patchstack
6.5 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Path Traversal Arbitrary File Download ≤ 2.0.14 Fixed in 2.0.15 CVE-2026-28146 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control No login needed ≤ 3.0.5 Fixed in 3.0.7 CVE-2026-25403 Patchstack
5.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control ≤ 2.0.15 Fixed in 2.0.16 CVE-2026-28147 Patchstack
5.4 Medium WordPress Download Manager Plugin Cross-Site Scripting Author+ Stored XSS via Package Title < 3.3.66 Fixed in 3.3.66 CVE-2026-14292 WPScan
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Podcast Contributor/Group/Role Creation and Deletion via CSRF No login needed < 4.5.3 Fixed in 4.5.3 CVE-2026-13729 WPScan
4.3 Medium WP Maps Plugin wp-google-map-plugin Information Disclosure Sensitive Data Exposure ≤ 4.9.6 Fixed in 4.9.7 CVE-2026-28144 Patchstack
5.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control No login needed ≤ 3.7.39 Fixed in 3.7.40 CVE-2026-28145 Patchstack
6.5 Medium Mailgun Plugin mailgun Broken Access Control Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-14834 WPScan
6.5 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Broken Access Control for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion ≤ 3.7.23 CVE-2026-5060 Wordfence
4.1 Medium Media Cleaner: Clean your WordPress! Plugin media-cleaner Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 7.0.3 CVE-2026-4912 Wordfence
6.5 Medium Anti Spam and list cleaner – AcyChecker Plugin acychecker Cross-Site Scripting AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) ≤ 1.8.1 Fixed in 2.0.0 CVE-2026-65448 Patchstack
6.5 Medium Ad Invalid Click Protector (AICP) Plugin ad-invalid-click-protector Broken Access Control No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2026-65445 Patchstack
5.3 Medium Gillion Theme gillion Broken Access Control No login needed ≤ 4.13 Fixed in 4.14 CVE-2026-66477 Patchstack
4.9 Medium Easy Digital Downloads Plugin easy-digital-downloads Arbitrary File Deletion ≤ 3.6.9 CVE-2026-66476 Patchstack
5.9 Medium Checkout Field Editor for WooCommerce – Checkout Manager Plugin checkout-field-editor-and-manager-for-woocommerce Cross-Site Scripting Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) ≤ 3.0.5 CVE-2026-66475 Patchstack
4.3 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Request Forgery HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2026-66474 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2026-66448 Patchstack
6.5 Medium Open User Map Plugin open-user-map Cross-Site Scripting ≤ 1.4.46 Fixed in 1.4.47 CVE-2026-66445 Patchstack
5.4 Medium YayPricing Plugin yaypricing Broken Access Control ≤ 3.5.6 Fixed in 3.5.7 CVE-2026-66442 Patchstack
5.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2026-66438 Patchstack
4.9 Medium Feedzy Plugin feedzy-rss-feeds Server-Side Request Forgery ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-66437 Patchstack
6.5 Medium Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting ≤ 3.33 Fixed in 3.34 CVE-2026-66434 Patchstack
6.5 Medium Location Weather Plugin location-weather Cross-Site Scripting ≤ 3.0.6 Fixed in 3.0.7 CVE-2026-66433 Patchstack
4.3 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Request Forgery No login needed ≤ 18.4 Fixed in 18.5 CVE-2026-66428 Patchstack
5.0 Medium Visual Composer Website Builder Plugin visualcomposer Broken Access Control ≤ 45.15.0 Fixed in 45.16.0 CVE-2026-65568 Patchstack
5.3 Medium Event Tickets Plugin event-tickets Broken Access Control No login needed ≤ 5.29.0.1 Fixed in 5.29.1 CVE-2026-65567 Patchstack
5.3 Medium MapPress Maps Plugin mappress-google-maps-for-wordpress Information Disclosure Sensitive Data Exposure No login needed ≤ 2.97.6 Fixed in 2.97.7 CVE-2026-65564 Patchstack
5.9 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 3.0.7 Fixed in 3.0.8 CVE-2026-65563 Patchstack
6.5 Medium BetterDocs Plugin betterdocs Cross-Site Scripting ≤ 4.6.2 Fixed in 4.7.0 CVE-2026-65562 Patchstack
6.5 Medium WordPress Social Login and Register Plugin miniorange-login-openid Cross-Site Scripting ≤ 7.8.0 Fixed in 7.8.1 CVE-2026-65561 Patchstack
5.4 Medium AffiliateX Plugin affiliatex Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2026-65558 Patchstack
5.9 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Scripting ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-65557 Patchstack
6.8 Medium Kirki Plugin kirki Arbitrary File Deletion ≤ 6.0.13 Fixed in 6.0.14 CVE-2026-65436 Patchstack
6.5 Medium Thrive Leads Version Plugin thrive-leads Broken Access Control No login needed ≤ 10.9.2 Fixed in 10.9.2.1 CVE-2026-65435 Patchstack
6.5 Medium ЮKassa для WooCommerce Plugin yookassa Information Disclosure Sensitive Data Exposure ≤ 2.16.1 Fixed in 2.16.2 CVE-2026-65434 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Broken Access Control Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-65433 Patchstack
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control ≤ 1.7.8 Fixed in 1.7.9 CVE-2026-59560 Patchstack
6.5 Medium RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg Plugin rt-mega-menu Cross-Site Scripting Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) ≤ 1.5.1 Fixed in 1.5.2 CVE-2026-59559 Patchstack
6.5 Medium Events Made Easy Plugin events-made-easy Broken Access Control No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-59557 Patchstack
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Post Slug (post_name) ≤ 28.0 CVE-2026-15425 Wordfence
6.5 Medium Modula Image Gallery Plugin modula-best-grid-gallery Cross-Site Scripting 2.14.25 – 2.14.30 Fixed in 2.14.31 CVE-2026-65475 Patchstack
6.5 Medium WooCommerce Product Stock Alert Plugin woocommerce-product-stock-alert Information Disclosure Sensitive Data Exposure ≤ 3.0.6 Fixed in 3.1.0 CVE-2026-61945 Patchstack
5.9 Medium Tabs Plugin tabs-responsive Cross-Site Scripting ≤ 2.5 CVE-2026-65550 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only