WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 4,601–4,650 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | ARForms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'value' Parameter No login needed |
≤ 7.1.3 |
CVE-2026-3652 |
Wordfence | |
| 6.4 Medium | ProfileGrid | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content |
≤ 5.9.9.2 |
CVE-2026-4610 |
Wordfence | |
| 7.5 High | Frontend File Manager | Path Traversal Unauthenticated Arbitrary File Download No login needed |
≤ 23.6 |
CVE-2026-8379 |
WPScan | |
| 5.4 Medium | Frontend File Manager | Cross-Site Scripting Subscriber+ Stored Cross-Site Scripting via File Rename |
≤ 23.6 |
CVE-2026-8378 |
WPScan | |
| 7.1 High | Simple Basic Contact Form | Cross-Site Scripting Reflected XSS No login needed |
≤ 20250114 |
CVE-2026-8172 |
WPScan | |
| 8.8 High | Infility Global | SQL Injection Subscriber+ SQL Injection via order Parameter |
< 2.15.19 Fixed in 2.15.19 |
CVE-2026-8163 |
WPScan | |
| 6.8 Medium | Infility Global | SQL Injection Editor+ SQL Injection via orderby Parameter |
< 2.15.20 Fixed in 2.15.20 |
CVE-2026-7842 |
WPScan | |
| 8.8 High | Vitepos | Privilege Escalation Outlet Manager+ Privilege Escalation |
< 3.4.2 Fixed in 3.4.2 |
CVE-2026-8157 |
WPScan | |
| 5.3 Medium | Motors Car Dealership & Classified Listings | Cross-Site Request Forgery Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media No login needed |
< 1.4.110 Fixed in 1.4.110 |
CVE-2026-7859 |
WPScan | |
| 7.1 High | Transbank Webpay | Cross-Site Scripting Unauthenticated Stored XSS No login needed |
< 1.14.0 Fixed in 1.14.0 |
CVE-2026-6858 |
WPScan | |
| 5.3 Medium | Pie Register | Other Unauthenticated Email Verification Bypass via Predictable Token No login needed |
< 3.8.4.10 Fixed in 3.8.4.10 |
CVE-2026-10530 |
WPScan | |
| 7.1 High | Ultimate WooCommerce Auction Pro | Cross-Site Scripting Reflected XSS via uwa_manage_auctions No login needed |
≤ 2.4.5 |
CVE-2026-4259 |
WPScan | |
| 6.1 Medium | Ultimate WooCommerce Auction Pro | Cross-Site Scripting Reflected XSS via uwa_auctions_bids_list No login needed |
≤ 2.4.5 |
CVE-2026-4110 |
WPScan | |
| 9.8 Critical | WooCommerce | Remote Code Execution WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php No login needed |
7.1.0 |
CVE-2022-50972 |
VulnCheck | |
| 6.5 Medium | Simple File List | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Operations (Deletion / Move / Folder Creation / Download) via 'frontmanage' Shortcode Attribute |
≤ 6.3.7 |
CVE-2026-12119 |
Wordfence | |
| 7.5 High | Simple File List | Broken Access Control Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action No login needed |
≤ 6.3.7 |
CVE-2026-11912 |
Wordfence | |
| 7.5 High | Simple File List | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal in 'eeSubFolder' Parameter No login needed |
≤ 6.3.7 |
CVE-2026-11911 |
Wordfence | |
| 8.1 High | Database for Contact Form 7, WPforms, Elementor forms | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via CF7 File Field POST Value No login needed |
≤ 1.5.1 |
CVE-2026-9843 |
Wordfence | |
| 9.8 Critical | Branda – White Label & Branding, Free Login Page Customizer | Privilege Escalation White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover No login needed |
≤ 3.4.29 |
CVE-2026-11551 |
Wordfence | |
| 5.3 Medium | WP Go Maps | Broken Access Control Unauthenticated Arbitrary Record Creation No login needed |
≤ 10.1.01 |
CVE-2026-12238 |
Wordfence | |
| 5.3 Medium | 2Download Connector for 2DL Hosted Checkout | Broken Access Control Missing Authorization to Unauthenticated Sensitive Customer Subscription Data Exposure via 'ToDownload_email' Parameter No login needed |
≤ 0.1.5 |
CVE-2026-6798 |
Wordfence | |
| 5.3 Medium | STRABL | Broken Access Control Unauthenticated Arbitrary Webhook Creation via REST API Endpoint No login needed |
≤ 4.5 |
CVE-2026-3640 |
Wordfence | |
| 6.5 Medium | WP Hotel Booking | Broken Access Control Subscriber+ Missing Authorization in Multiple AJAX Handlers |
< 2.3.1 Fixed in 2.3.1 |
CVE-2026-9822 |
WPScan | |
| 9.8 Critical | BetterDocs Pro | Local File Inclusion Unauthenticated Local File Inclusion via doc_style No login needed |
≤ 3.8.0 |
CVE-2026-7515 |
Wordfence | |
| 4.4 Medium | Blocksy Companion | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter |
≤ 2.1.45 |
CVE-2026-12430 |
Wordfence | |
| 5.3 Medium | WP DSGVO Tools (GDPR) | Broken Access Control Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters) No login needed |
≤ 3.1.39 |
CVE-2026-10034 |
Wordfence | |
| 9.1 Critical | Avada (Fusion) Builder | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Form Entry Value No login needed |
≤ 3.15.3 |
CVE-2026-8713 |
Wordfence | |
| 6.5 Medium | Royal Addons for Elementor – Addons and Templates Kit for Elementor | Path Traversal Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source |
1.7.1058 – 1.7.1059 |
CVE-2026-8118 |
Wordfence | |
| 6.5 Medium | Bit integrations | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping No login needed |
≤ 2.8.7 |
CVE-2026-11989 |
Wordfence | |
| 4.3 Medium | Bogo | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST API |
≤ 3.9.1 |
CVE-2026-9013 |
Wordfence | |
| 6.4 Medium | Advanced Import: One-Click Demo Import | Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter |
≤ 1.4.6 |
CVE-2026-4328 |
Wordfence | |
| 6.4 Medium | BetterDocs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute |
≤ 4.5.3 |
CVE-2026-12157 |
Wordfence | |
| 4.9 Medium | Woosa | Path Traversal Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter |
≤ 2.0.5 |
CVE-2026-7547 |
Wordfence | |
| 6.4 Medium | Appointment Booking Calendar | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label |
≤ 1.4.4 |
CVE-2026-1856 |
Wordfence | |
| 4.3 Medium | Classified Listing | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters) |
≤ 5.4.2 |
CVE-2026-10779 |
Wordfence | |
| 4.3 Medium | User Admin Simplifier | Cross-Site Request Forgery No login needed |
≤ 3.0.0 |
CVE-2026-11775 |
Wordfence | |
| 6.5 Medium | WP EasyPay | Cross-Site Request Forgery No login needed |
≤ 4.5.0 |
CVE-2026-56024 |
Patchstack | |
| 8.5 High | Media LIbrary Assistant | SQL Injection |
≤ 3.35 Fixed in 3.36 |
CVE-2026-56012 |
Patchstack | |
| 5.9 Medium | Bricksable for Bricks Builder | Cross-Site Scripting |
≤ 1.6.83 Fixed in 1.6.84 |
CVE-2026-56009 |
Patchstack | |
| 5.9 Medium | Ocean Product Sharing | Cross-Site Scripting |
≤ 2.2.2 Fixed in 2.2.3 |
CVE-2026-56007 |
Patchstack | |
| 6.4 Medium | Slideshow Gallery LITE | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute |
≤ 1.8.5 |
CVE-2026-2021 |
Wordfence | |
| 6.4 Medium | Fancy Testimonials | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2026-8039 |
Wordfence | |
| 4.3 Medium | Appointment Booking Calendar | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter |
≤ 1.4.01 |
CVE-2026-12111 |
Wordfence | |
| 6.4 Medium | PowerPress Podcasting plugin by Blubrry | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field |
≤ 11.16.8 |
CVE-2026-12098 |
Wordfence | |
| 7.2 High | CF7 to Webhook | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host No login needed |
≤ 5.0.0 |
CVE-2026-11395 |
Wordfence | |
| 6.1 Medium | SysBasics Customize My Account for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via 'tab' Parameter No login needed |
≤ 4.3.6 |
CVE-2026-12137 |
Wordfence | |
| 2.7 Low | UsersWP | Broken Access Control Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter |
≤ 1.2.63 |
CVE-2026-12102 |
Wordfence | |
| 6.4 Medium | SysBasics Customize My Account for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 4.3.6 |
CVE-2026-12136 |
Wordfence | |
| 6.5 Medium | MagicForm | Arbitrary File Upload Unauthenticated Arbitrary File Upload to RCE No login needed |
≤ 0.1.3 |
CVE-2026-9815 |
WPScan | |
| 6.4 Medium | Services Section Block | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block Attribute |
≤ 1.4.4 |
CVE-2026-11402 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.