WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 401–450 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control Unauthenticated Payment Hijacking via Unvalidated PayPal Order ID No login needed < 2.0.27 Fixed in 2.0.27 CVE-2026-80342 WPScan
4.3 Medium Directorist Plugin directorist-wpml-integration Information Disclosure Subscriber+ Order and Financial Record Disclosure via REST Orders Endpoint 8.5 – < 8.9.5 Fixed in 8.9.5 CVE-2026-77766 WPScan
5.3 Medium Better Payment Plugin better-payment Price Manipulation Unauthenticated Payment Amount Manipulation No login needed < 2.3.4 Fixed in 2.3.4 CVE-2026-77765 WPScan
4.3 Medium Zportals Plugin Information Disclosure Subscriber+ User Email Disclosure < 6.4.2 Fixed in 6.4.2 CVE-2026-18365 WPScan
4.3 Medium Zportals Plugin Broken Access Control Subscriber+ Arbitrary Plugin Settings Update < 6.4.2 Fixed in 6.4.2 CVE-2026-18364 WPScan
6.5 Medium Newsletters Plugin newsletters-lite Information Disclosure Unauthenticated Subscriber Record Overwrite and PII Disclosure via IDOR No login needed < 4.18.1 Fixed in 4.18.1 CVE-2026-16264 WPScan
6.8 Medium Real3D Flipbook Lite Plugin Cross-Site Scripting Author+ Stored XSS < 5.4 Fixed in 5.4 CVE-2025-15696 WPScan
5.3 Medium Social Commerce for WooCommerce Plugin Broken Access Control Unauthenticated Plugin Option and Product Sync Status Update No login needed ≤ 2.5.4 CVE-2026-86785 WPScan
6.5 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_get_page_content AJAX < 2.1.72 Fixed in 2.1.72 CVE-2026-93344 VulnCheck
6.5 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_admin_vendors_ajax < 2.1.72 Fixed in 2.1.72 CVE-2026-93343 VulnCheck
5.4 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_duplicate_product AJAX < 2.1.72 Fixed in 2.1.72 CVE-2026-93342 VulnCheck
4.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control MarketKing < 2.1.72 Missing Authorization via marketking_send_refund AJAX < 2.1.72 Fixed in 2.1.72 CVE-2026-93341 VulnCheck
4.9 Medium Product Feed Manager for WooCommerce Plugin webappick-product-feed-for-woocommerce Path Traversal Authenticated (Shop Manager+) Path Traversal to File Deletion via 'provider' Parameter ≤ 6.6.43 CVE-2026-15095 Wordfence
4.3 Medium WP User Manager Plugin wp-user-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stripe Account Hijack via Stripe Connect Callback ≤ 2.9.18 CVE-2026-18345 Wordfence
4.3 Medium WP-CRM System Plugin wp-crm-system Information Disclosure Authenticated (Contributor+) Exposure of Sensitive Information via 'contact_id' Parameter ≤ 3.4.6 CVE-2026-9004 Wordfence
4.3 Medium ThumbPress Plugin image-sizes Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation ≤ 6.2.1 CVE-2026-7622 Wordfence
5.3 Medium Handily Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Stripe Payment Settings Modification via 'stripe_publishbale_key' Parameter No login needed ≤ 1.0.3 CVE-2025-14487 Wordfence
6.5 Medium BM Content Builder Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read < 3.17.1 Fixed in 3.17.1 CVE-2025-1280 Wordfence
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Guest Post Takeover via wpforo_post_edit Action / Forged comment_author_email Cookie ≤ 3.1.5 CVE-2026-91092 Wordfence
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Authenticated (Custom+) Insecure Direct Object Reference to Arbitrary Quiz Question/Answer Modification and Deletion via 'payload' Parameter ≤ 4.0.7 CVE-2026-18439 Wordfence
4.4 Medium Hostel Plugin hostel Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_currency' Parameter and Localization file URL Setting ≤ 1.1.8 CVE-2026-1645 Wordfence
4.3 Medium RW Elephant Rental Inventory Plugin rw-elephant-rental-inventory Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'toggle_cache' AJAX Action ≤ 2.3.13 CVE-2026-4123 Wordfence
5.3 Medium PixelPlay Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary API Key Deletion via 'clear_api_type' Parameter No login needed ≤ 1.0.2 CVE-2025-14486 Wordfence
5.3 Medium Image Buzz Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary API Key Modification via 'pixabay_api' Parameter No login needed ≤ 1.0.3 CVE-2025-14484 Wordfence
6.4 Medium Live Composer Plugin live-composer-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content ≤ 2.1.21 CVE-2026-16778 Wordfence
4.3 Medium Custom Field Template Plugin custom-field-template Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Media File Deletion via 'file_field' Parameter ≤ 2.7.8 CVE-2026-12995 Wordfence
6.8 Medium Text Styler Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.1.1 CVE-2026-88788 WPScan
6.1 Medium Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting via 'wpbc_auto_fill' Parameter No login needed ≤ 11.8.3 CVE-2026-93655 Wordfence
6.4 Medium Contextual Related Posts Plugin contextual-related-posts Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'other_attributes' Block Parameter ≤ 4.4.1 CVE-2026-85653 Wordfence
5.4 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting Ditty < 3.1.70 Stored XSS via Layout Tag Wrapper Attribute < 3.1.70 Fixed in 3.1.70 CVE-2026-93339 VulnCheck
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Price Manipulation Unauthenticated Payment Bypass via Sandbox IPN Environment Confusion No login needed < 9.2.1 Fixed in 9.2.1 CVE-2026-92400 WPScan
6.5 Medium GiveWP Plugin give Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Donor Name No login needed 4.13.2 – < 4.16.9 Fixed in 4.16.9 CVE-2026-85113 WPScan
5.3 Medium RestroPress Plugin restropress Price Manipulation Unauthenticated Price Manipulation via Cart Add-ons No login needed < 3.4.6 Fixed in 3.4.6 CVE-2026-85010 WPScan
6.5 Medium Meow Gallery Plugin meow-gallery Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST Route No login needed < 5.5.5 Fixed in 5.5.5 CVE-2026-92422 WPScan
4.3 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Request Forgery Arbitrary Sign-up Deletion via CSRF No login needed < 2.4.0 Fixed in 2.4.0 CVE-2026-92410 WPScan
5.3 Medium Tripzzy Plugin tripzzy Broken Access Control Unauthenticated Booking Data Tampering No login needed 1.3.4 – < 1.5.1 Fixed in 1.5.1 CVE-2026-87840 WPScan
6.6 Medium Forminator Forms Plugin forminator Privilege Escalation Authenticated Privilege Escalation via Quiz Lead-Form Import 1.57.0 – < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87068 WPScan
6.8 Medium Kirki Plugin kirki Cross-Site Scripting Author+ Stored XSS via Unsanitized SVG Upload 6.0.0 – < 6.3.1 Fixed in 6.3.1 CVE-2026-84223 WPScan
4.2 Medium NextGEN Gallery Plugin Broken Access Control Authenticated Arbitrary Gallery Image Deletion via IDOR < 4.5.0 Fixed in 4.5.0 CVE-2026-81653 WPScan
4.1 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Server-Side Request Forgery Admin+ SSRF via bp_avatar < 2.4.5 Fixed in 2.4.5 CVE-2026-16542 WPScan
6.8 Medium Master Slider Plugin master-slider Cross-Site Scripting Contributor+ Stored XSS via ms_slider Shortcode Attributes ≤ 3.11.2 CVE-2026-14844 WPScan
4.3 Medium Partial Shipment for Woocommerce Plugin wc-partial-shipment Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Settings Modification via wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX Actions ≤ 3.4 CVE-2026-9858 Wordfence
4.7 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Reflected Cross-Site Scripting via ESI 'esi' Parameter No login needed ≤ 7.9 CVE-2026-76579 Wordfence
4.3 Medium Datalogics Ecommerce Delivery Plugin datalogics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping) ≤ 2.6.65 CVE-2026-9613 Wordfence
6.4 Medium YS LeadGen – Popups, Opt-ins & Lead Capture Plugin ysleadgen Broken Access Control Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via User Input ≤ 2.1.4 CVE-2026-1256 Wordfence
4.3 Medium Empik for Woocommerce Plugin empik-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Product Meta Update via empik_csv_process_emp_log_classes AJAX Action ≤ 1.5.1 CVE-2026-9766 Wordfence
5.3 Medium WordLift Plugin wordlift Information Disclosure Unauthenticated Sensitive Information Exposure in JSON-LD REST API Endpoints No login needed ≤ 3.54.10 CVE-2026-9289 Wordfence
5.3 Medium TikTok Plugin tiktok-for-business Broken Access Control Missing Authorization to Unauthenticated TikTok Integration Takeover via 'auth_code' Parameter No login needed ≤ 1.4.1 CVE-2026-18346 Wordfence
6.4 Medium Gum Addon for Elementor Plugin gum-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pop_tag' Widget Setting ≤ 1.3.15 CVE-2026-8354 Wordfence
6.4 Medium Redux Framework Plugin redux-framework Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Spinner Field Input ≤ 4.5.13 CVE-2026-5410 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only