WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 4,601–4,650 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 93 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High ARForms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'value' Parameter No login needed ≤ 7.1.3 CVE-2026-3652 Wordfence
6.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content ≤ 5.9.9.2 CVE-2026-4610 Wordfence
7.5 High Frontend File Manager Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 23.6 CVE-2026-8379 WPScan
5.4 Medium Frontend File Manager Plugin Cross-Site Scripting Subscriber+ Stored Cross-Site Scripting via File Rename ≤ 23.6 CVE-2026-8378 WPScan
7.1 High Simple Basic Contact Form Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 20250114 CVE-2026-8172 WPScan
8.8 High Infility Global Plugin infility-global SQL Injection Subscriber+ SQL Injection via order Parameter < 2.15.19 Fixed in 2.15.19 CVE-2026-8163 WPScan
6.8 Medium Infility Global Plugin infility-global SQL Injection Editor+ SQL Injection via orderby Parameter < 2.15.20 Fixed in 2.15.20 CVE-2026-7842 WPScan
8.8 High Vitepos Plugin vitepos-lite Privilege Escalation Outlet Manager+ Privilege Escalation < 3.4.2 Fixed in 3.4.2 CVE-2026-8157 WPScan
5.3 Medium Motors Car Dealership & Classified Listings Plugin Cross-Site Request Forgery Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media No login needed < 1.4.110 Fixed in 1.4.110 CVE-2026-7859 WPScan
7.1 High Transbank Webpay Plugin transbank-webpay-plus-rest Cross-Site Scripting Unauthenticated Stored XSS No login needed < 1.14.0 Fixed in 1.14.0 CVE-2026-6858 WPScan
5.3 Medium Pie Register Plugin pie-register Other Unauthenticated Email Verification Bypass via Predictable Token No login needed < 3.8.4.10 Fixed in 3.8.4.10 CVE-2026-10530 WPScan
7.1 High Ultimate WooCommerce Auction Pro Plugin Cross-Site Scripting Reflected XSS via uwa_manage_auctions No login needed ≤ 2.4.5 CVE-2026-4259 WPScan
6.1 Medium Ultimate WooCommerce Auction Pro Plugin Cross-Site Scripting Reflected XSS via uwa_auctions_bids_list No login needed ≤ 2.4.5 CVE-2026-4110 WPScan
9.8 Critical WooCommerce Plugin woocommerce Remote Code Execution WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php No login needed 7.1.0 CVE-2022-50972 VulnCheck
6.5 Medium Simple File List Plugin simple-file-list Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute ≤ 6.3.7 CVE-2026-12119 Wordfence
7.5 High Simple File List Plugin simple-file-list Broken Access Control Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action No login needed ≤ 6.3.7 CVE-2026-11912 Wordfence
7.5 High Simple File List Plugin simple-file-list Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter No login needed ≤ 6.3.7 CVE-2026-11911 Wordfence
8.1 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value No login needed ≤ 1.5.1 CVE-2026-9843 Wordfence
9.8 Critical Branda – White Label & Branding, Free Login Page Customizer Plugin branda-white-labeling Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.4.29 CVE-2026-11551 Wordfence
5.3 Medium WP Go Maps Plugin wp-google-maps Broken Access Control Unauthenticated Arbitrary Record Creation No login needed ≤ 10.1.01 CVE-2026-12238 Wordfence
5.3 Medium 2Download Connector for 2DL Hosted Checkout Plugin 2download-connector Broken Access Control Missing Authorization to Unauthenticated Sensitive Customer Subscription Data Exposure via 'ToDownload_email' Parameter No login needed ≤ 0.1.5 CVE-2026-6798 Wordfence
5.3 Medium STRABL Plugin strabl-a-checkout-solution Broken Access Control Unauthenticated Arbitrary Webhook Creation via REST API Endpoint No login needed ≤ 4.5 CVE-2026-3640 Wordfence
6.5 Medium WP Hotel Booking Plugin wp-hotel-booking Broken Access Control Subscriber+ Missing Authorization in Multiple AJAX Handlers < 2.3.1 Fixed in 2.3.1 CVE-2026-9822 WPScan
9.8 Critical BetterDocs Pro Plugin Local File Inclusion Unauthenticated Local File Inclusion via doc_style No login needed ≤ 3.8.0 CVE-2026-7515 Wordfence
4.4 Medium Blocksy Companion Plugin blocksy-companion Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter ≤ 2.1.45 CVE-2026-12430 Wordfence
5.3 Medium WP DSGVO Tools (GDPR) Plugin shapepress-dsgvo Broken Access Control Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters) No login needed ≤ 3.1.39 CVE-2026-10034 Wordfence
9.1 Critical Avada (Fusion) Builder Plugin fusion-builder Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Form Entry Value No login needed ≤ 3.15.3 CVE-2026-8713 Wordfence
6.5 Medium Royal Addons for Elementor – Addons and Templates Kit for Elementor Plugin royal-elementor-addons Path Traversal Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source 1.7.1058 – 1.7.1059 CVE-2026-8118 Wordfence
6.5 Medium Bit integrations Plugin bit-integrations Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping No login needed ≤ 2.8.7 CVE-2026-11989 Wordfence
4.3 Medium Bogo Plugin bogo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST API ≤ 3.9.1 CVE-2026-9013 Wordfence
6.4 Medium Advanced Import: One-Click Demo Import Plugin advanced-import Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter ≤ 1.4.6 CVE-2026-4328 Wordfence
6.4 Medium BetterDocs Plugin betterdocs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute ≤ 4.5.3 CVE-2026-12157 Wordfence
4.9 Medium Woosa Plugin integration-marktplaats-for-woocommerce Path Traversal Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter ≤ 2.0.5 CVE-2026-7547 Wordfence
6.4 Medium Appointment Booking Calendar Plugin creavi-booking-service Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label ≤ 1.4.4 CVE-2026-1856 Wordfence
4.3 Medium Classified Listing Plugin classified-listing Broken Access Control Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters) ≤ 5.4.2 CVE-2026-10779 Wordfence
4.3 Medium User Admin Simplifier Plugin user-admin-simplifier Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2026-11775 Wordfence
6.5 Medium WP EasyPay Plugin wp-easy-pay Cross-Site Request Forgery No login needed ≤ 4.5.0 CVE-2026-56024 Patchstack
8.5 High Media LIbrary Assistant Plugin media-library-assistant SQL Injection ≤ 3.35 Fixed in 3.36 CVE-2026-56012 Patchstack
5.9 Medium Bricksable for Bricks Builder Plugin bricksable Cross-Site Scripting ≤ 1.6.83 Fixed in 1.6.84 CVE-2026-56009 Patchstack
5.9 Medium Ocean Product Sharing Plugin ocean-product-sharing Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2026-56007 Patchstack
6.4 Medium Slideshow Gallery LITE Plugin slideshow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute ≤ 1.8.5 CVE-2026-2021 Wordfence
6.4 Medium Fancy Testimonials Plugin fancy-testimonials Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.0 CVE-2026-8039 Wordfence
4.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter ≤ 1.4.01 CVE-2026-12111 Wordfence
6.4 Medium PowerPress Podcasting plugin by Blubrry Plugin powerpress Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field ≤ 11.16.8 CVE-2026-12098 Wordfence
7.2 High CF7 to Webhook Plugin cf7-to-zapier Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host No login needed ≤ 5.0.0 CVE-2026-11395 Wordfence
6.1 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'tab' Parameter No login needed ≤ 4.3.6 CVE-2026-12137 Wordfence
2.7 Low UsersWP Plugin userswp Broken Access Control Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter ≤ 1.2.63 CVE-2026-12102 Wordfence
6.4 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.3.6 CVE-2026-12136 Wordfence
6.5 Medium MagicForm Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload to RCE No login needed ≤ 0.1.3 CVE-2026-9815 WPScan
6.4 Medium Services Section Block Plugin services-section Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block Attribute ≤ 1.4.4 CVE-2026-11402 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only