Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesWordPress vulnerabilities this week

WordPress vulnerabilities this week

This page lists WordPress vulnerabilities published in the last 7 days, newest first. Use the live table to check the affected software, severity, vulnerable versions and whether a fixed version is available.

515 published in the last 7 days. Last checked 1 min ago.

Plugin or themeVulnerabilitySeverityAffectedFixPublished
LatePoint - Appointment Booking & ReservationBroken access control
CVE-2026-17538
Medium 5.4Up to 5.6.9Check for an update24 min ago
Aurora Heatmap
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-94154
Medium 6.1Up to 1.7.2Fixed in a later version (latest 1.7.3)24 min ago
Forminator Forms - Contact Form, Payment Form & Custom Form Builder
600,000+ installs
Broken access control
CVE-2026-96335
High 7.5Up to 1.57.2Fixed in a later version (latest 1.57.3)6 h ago
The Events Calendar
600,000+ installs
PHP object injection
CVE-2026-95606
Critical 9.8Up to 6.17.4Fixed in a later version (latest 6.18.0)6 h ago
WP Data Access - App Builder for Tables, Forms, Charts, Maps & Dashboards
10,000+ installs
SQL injection
CVE-2026-95605
Critical 9.3Up to 5.5.82Fixed in a later version (latest 5.5.85)6 h ago
Disable and Remove Google Fonts | GDPR & DSGVO friendly
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-95595
High 7.1Up to 2.0.2Fixed in a later version (latest 2.0.3)6 h ago
Unlimited Elements for Elementor
300,000+ installs
PHP object injection
CVE-2026-95534
High 8.8Up to 2.0.19Fixed in a later version (latest 2.0.21)6 h ago
Everest Forms - Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI
90,000+ installs
Cross-site scripting (XSS)
CVE-2026-94670
High 7.1Up to 3.6.1Fixed in a later version (latest 3.6.2)6 h ago
Unlimited Elements for Elementor
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-94662
High 7.1Up to 2.0.19Fixed in a later version (latest 2.0.21)6 h ago
WP Post Author - Author Box, Multiple Authors, Guest Authors & Custom Avatars
10,000+ installs
SQL injection
CVE-2026-42708
High 7.6Up to 4.0.0No fixed version yet11 h ago
Slider by 10Web - Responsive Image Slider
10,000+ installs
SQL injection
CVE-2026-42710
High 7.6Up to 1.2.63No fixed version yet11 h ago
Post title marquee scrollSQL injection
CVE-2026-42713
High 7.6Up to 9.9Check for an update12 h ago
Pix por Piggly (para Woocommerce)
4,000+ installs
SQL injection
CVE-2026-42714
High 7.6Up to 2.1.2No fixed version yet12 h ago
Dynamic User Directory
1,000+ installs
SQL injection
CVE-2026-42720
High 7.6Up to 2.4No fixed version yet13 h ago
affiliate-toolkit - Multi-Network Affiliate & Amazon Product Display
2,000+ installs
SQL injection
CVE-2026-42721
High 7.6Up to 3.9.1No fixed version yet13 h ago
sc Internet Vivoo WP Rentals wprentalsBroken access control
CVE-2026-27434
Medium 5.3Up to 3.14.2Check for an update14 h ago
Booktics - Appointment Booking Calendar for Service Businesses
800+ installs
Broken access control
CVE-2026-104390
Medium 4.3Up to 1.0.27No fixed version yet14 h ago
Modula Image Gallery - Photo Grid & Video Gallery
100,000+ installs
Broken access control
CVE-2026-105876
Medium 5.3Up to 3.0.11No fixed version yet14 h ago
HappyAddons for Elementor - 160 Elementor Widgets, GSAP Animations & Templates
400,000+ installs
Cross-site scripting (XSS)
CVE-2026-104393
Medium 6.5Up to 3.50.0No fixed version yet14 h ago
Prime Slider - Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-105875
Medium 6.5Up to 4.6.2No fixed version yet14 h ago
Quiz and Survey Master (QSM) - Quiz Maker & Survey Maker
40,000+ installs
Cross-site scripting (XSS)
CVE-2026-104391
Medium 6.5Up to 11.2.7No fixed version yet14 h ago
Hustle - Email Marketing, Lead Generation, Optins, Popups
90,000+ installs
Broken access control
CVE-2026-103075
Medium 4.3Up to 7.8.14.2No fixed version yet14 h ago
LazyLoad Plugin - Lazy Load Images, Videos, and Iframes
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-105884
Medium 6.5Up to 2.4.0Fixed in a later version (latest 2.4.1)14 h ago
Element Pack Addons for Elementor - Elementor Widgets, Elementor Templates, Elementor Addons
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-105873
Medium 6.5Up to 8.8.6No fixed version yet14 h ago
Media Library Assistant
70,000+ installs
Cross-site scripting (XSS)
CVE-2026-97294
Medium 6.5Up to 3.41Fixed in a later version (latest 3.42)14 h ago
Element Pack Addons for Elementor - Elementor Widgets, Elementor Templates, Elementor Addons
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-105871
Medium 6.5Up to 8.8.6No fixed version yet14 h ago
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-89417
High 7.2Up to 6.3.10Fixed in a later version (latest 6.3.12)15 h ago
Nexi XPay BuildSecurity weakness
CVE-2026-82212
High 7.5Up to 7.6.2Check for an update17 h ago
Nexi XPay BuildBroken access control
CVE-2026-82211
High 8.2Up to 7.6.2Check for an update17 h ago
Magee ShortcodesSecurity weakness
CVE-2026-105322
Medium 5.3Up to 2.1.1Check for an update17 h ago
MetForm - Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor
600,000+ installs
Content injection
CVE-2026-86833
Medium 5.4Before 4.3.1Fixed in 4.3.117 h ago
PowerPress Podcasting plugin by Blubrry
20,000+ installs
Server-side request forgery (SSRF)
CVE-2026-97354
Medium 4.1Before 11.17.11Fixed in 11.17.1117 h ago
User Private Files - Secure File Sharing and Client Portal Plugin
1,000+ installs
Sensitive data exposure
CVE-2026-97331
Medium 4.3Before 2.1.9Fixed in 2.1.917 h ago
String locator
100,000+ installs
Remote code execution
CVE-2026-97188
High 8.8Before 2.6.8Fixed in 2.6.817 h ago
Optimole - Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization
200,000+ installs
Sensitive data exposure
CVE-2026-96530
Medium 6.5Before 4.2.15Fixed in 4.2.1517 h ago
If-So Dynamic Content - Elementor & All Page Builders Personalization
7,000+ installs
Cross-site scripting (XSS)
CVE-2026-87971
High 7.1Before 1.10.2Fixed in 1.10.217 h ago
Koinonia Link
10+ installs
Privilege escalation
CVE-2026-87782
High 8.8Before 1.1.5Fixed in 1.1.517 h ago
WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System
5,000+ installs
Sensitive data exposure
CVE-2026-86816
Medium 5.3Before 3.0.21Fixed in 3.0.2117 h ago
Magee ShortcodesCross-site scripting (XSS)
CVE-2026-105316
High 7.1Up to 2.1.1Check for an update17 h ago
MPG - Multiple Page Generator, Bulk Landing Pages & Programmatic SEO
2,000+ installs
SQL injection
CVE-2026-104953
Medium 6.8Before 4.2.3Fixed in 4.2.317 h ago
CP Media Player - Audio Player and Video Player
3,000+ installs
Broken access control
CVE-2026-104678
Low 2.7Before 1.3.4Fixed in 1.3.417 h ago
WP Coder - Insert & Manage Code Snippets
10,000+ installs
Remote code execution
CVE-2026-104677
High 7.2Before 4.5.2Fixed in 4.5.217 h ago
Animated Number Counters
2,000+ installs
SQL injection
CVE-2026-104667
Medium 6.8Before 3.1Fixed in 3.117 h ago
Envira Gallery - Image Photo Gallery, Albums, Video Gallery, Slideshows & More
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-104653
Medium 6.8Before 1.16.1Fixed in 1.16.117 h ago
Envira Gallery - Image Photo Gallery, Albums, Video Gallery, Slideshows & More
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-104652
Medium 6.8Before 1.16.1Fixed in 1.16.117 h ago
Yaad Sarig Payment Gateway For WC
2,000+ installs
Broken access control
CVE-2026-104651
Medium 4.3Before 2.2.13Fixed in 2.2.1317 h ago
Academy LMS - AI Course Builder, Quizzes, Certificates & eLearning
2,000+ installs
Broken access control
CVE-2026-104050
Medium 4.3Before 4.0.0Fixed in 4.0.017 h ago
Academy LMS - AI Course Builder, Quizzes, Certificates & eLearning
2,000+ installs
Broken access control
CVE-2026-104049
Medium 4.3Before 4.0.0Fixed in 4.0.017 h ago
Frontend Dashboard
500+ installs
Broken access control
CVE-2026-103681
Medium 4.3Before 3.0.0Fixed in 3.0.017 h ago
Geliver Akıllı Kargo Pazaryeri
400+ installs
Sensitive data exposure
CVE-2026-103378
Medium 6.5Before 3.1.1Fixed in 3.1.117 h ago
Integration for Epos Now and WooCommerce
300+ installs
Broken access control
CVE-2026-103323
Medium 5.9Before 4.11.2Fixed in 4.11.217 h ago
Kirki - Freeform Page Builder, Website Builder & Customizer
500,000+ installs
Cross-site scripting (XSS)
CVE-2026-102173
High 7.2Up to 6.3.1Fixed in a later version (latest 6.3.2)18 h ago
WordPress coreSensitive data exposure
CVE-2026-66666
Medium 6.9Up to 6.6.9Check for an update1 d ago
Motors - Car Dealership & Classified Listings Plugin
9,000+ installs
Sensitive data exposure
CVE-2026-104399
Medium 6.9Up to 1.4.124No fixed version yet1 d ago
Paid Membership Subscriptions - Effortless Memberships, Recurring Payments & Content Restriction
10,000+ installs
SQL injection
CVE-2026-105317
High 8.5Up to 3.1.1No fixed version yet1 d ago
SiteVault - Backup, Restore, Migration & Cloning
30+ installs
Sensitive data exposure
CVE-2026-105071
High 7.5Up to 1.5.17Fixed in a later version (latest 1.5.18)1 d ago
Salon Booking System - Appointment Booking for Salons, Barbershops & Spas
2,000+ installs
Privilege escalation
CVE-2026-105070
High 8.8Up to 10.31.7No fixed version yet1 d ago
WP Mailster
300+ installs
Cross-site scripting (XSS)
CVE-2026-105061
High 7.1Up to 1.9.0.0No fixed version yet1 d ago
WP Comment Cleaner - Delete All Comments, Disable Comments, Bulk Delete & Remove Comments
20,000+ installs
Broken access control
CVE-2026-105059
Medium 6.5Up to 7.1Fixed in a later version (latest 7.2)1 d ago
WP User Profiles
200+ installs
Privilege escalation
CVE-2026-105058
High 8.8Up to 2.7.3Fixed in a later version (latest 2.7.4)1 d ago
Zero Spam for WordPress
20,000+ installs
Security weakness
CVE-2026-105057
Medium 5.3Up to 5.7.11No fixed version yet1 d ago
Form Block
200+ installs
Cross-site scripting (XSS)
CVE-2026-104814
High 7.1Up to 1.8.1Fixed in a later version (latest 1.8.2)1 d ago
Import and export users and customers
70,000+ installs
Privilege escalation
CVE-2026-104757
High 7.2Up to 2.5.5No fixed version yet1 d ago
HaakenPHP object injection
CVE-2026-104747
High 8.1Up to 1.5Check for an update1 d ago
GiveWP - Donation Plugin and Fundraising Platform
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-104672
High 7.1Up to 4.17.0No fixed version yet1 d ago
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses
70,000+ installs
Cross-site scripting (XSS)
CVE-2026-104670
High 7.1Up to 4.4.9Fixed in a later version (latest 4.4.9.1)1 d ago
picu - Online Photo Proofing Gallery
2,000+ installs
Broken access control
CVE-2026-104406
High 7.3Up to 3.10.1Fixed in a later version (latest 3.10.2)1 d ago
GiveWP - Donation Plugin and Fundraising Platform
100,000+ installs
Privilege escalation
CVE-2026-104405
High 8.1Up to 4.17.0No fixed version yet1 d ago
picu - Online Photo Proofing Gallery
2,000+ installs
Cross-site scripting (XSS)
CVE-2026-104395
High 7.1Up to 3.10.1Fixed in a later version (latest 3.10.2)1 d ago
Charitable - Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns)
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-104394
High 7.1Up to 1.8.12.3Fixed in a later version (latest 1.8.13)1 d ago
PowerPress Podcasting plugin by Blubrry
20,000+ installs
Broken access control
CVE-2026-104387
High 7.2Up to 11.17.9No fixed version yet1 d ago
Groundhogg - CRM, Newsletters, and Marketing Automation
2,000+ installs
Sensitive data exposure
CVE-2026-104385
High 7.5Up to 4.8.3No fixed version yet1 d ago
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)
10,000+ installs
Broken access control
CVE-2026-102915
High 8.5Up to 44.1No fixed version yet1 d ago
XServer Migrator
10,000+ installs
Sensitive data exposure
CVE-2026-102387
High 7.5Up to 1.6.6Fixed in a later version (latest 1.6.7)1 d ago
Advanced Google reCAPTCHA
200,000+ installs
Authentication bypass
CVE-2026-100518
Medium 5.3Up to 5.40No fixed version yet1 d ago
Login Lockdown & Protection
100,000+ installs
Security weakness
CVE-2026-97308
Medium 4.8Up to 2.17No fixed version yet1 d ago
SMS Alert - SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery
3,000+ installs
Privilege escalation
CVE-2026-95594
High 8.1Up to 4.0.0No fixed version yet1 d ago
BEAR - Bulk Editor for WooCommerce Professional. AI assistant on board (MCP Server)
30,000+ installs
Broken access control
CVE-2026-95526
High 7.3Up to 1.2.2Fixed in a later version (latest 1.2.4)1 d ago
Fluent Forms Pro Add On PackCross-site scripting (XSS)
CVE-2026-94675
High 7.1Up to 6.2.13Check for an update1 d ago
The7Broken access control
CVE-2026-66588
High 7.5Up to 14.2.2Check for an update1 d ago
Progress Planner
100+ installs
Broken access control
CVE-2026-62072
High 8.8Up to 1.10.0Fixed in a later version (latest 1.10.1)1 d ago
Sermon'eBroken access control
CVE-2026-48199
High 7.5Up to 1.0.2Check for an update1 d ago
PublishPress Capabilities: User Role Access Control, Admin Area Permissions
100,000+ installs
Privilege escalation
CVE-2026-48197
High 7.2Up to 2.45.0Fixed in a later version (latest 2.52.0)1 d ago
Easy Digital Downloads - eCommerce Payments and Subscriptions made easy
40,000+ installs
Broken access control
CVE-2026-42638
High 7.5Up to 3.7.1No fixed version yet1 d ago
PayPlug for WooCommerce (Official)
4,000+ installs
Broken access control
CVE-2026-42637
Medium 6.5Up to 3.1.0No fixed version yet1 d ago
WPLP Cookie Consent - Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode
9,000+ installs
Cross-site scripting (XSS)
CVE-2026-42636
High 7.1Up to 4.4.6No fixed version yet1 d ago
WooCommerce Simple AuctionsCross-site scripting (XSS)
CVE-2026-42635
High 7.1Up to 3.0.10Check for an update1 d ago
Video Background Block - Add Stunning Video Backgrounds to Any Section
2,000+ installs
Cross-site scripting (XSS)
CVE-2026-42634
High 7.1Up to 2.0.3No fixed version yet1 d ago
Social Rocket - Social Sharing Plugin
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-42418
High 7.1Up to 1.3.5No fixed version yet1 d ago
ARMember PremiumSQL injection
CVE-2026-42417
Critical 9.3Up to 7.8Check for an update1 d ago
UDesign CoreSQL injection
CVE-2026-42416
High 8.5Up to 4.15.0Check for an update1 d ago
Porto Theme - FunctionalitySQL injection
CVE-2026-42415
Critical 9.3Up to 3.9.3Check for an update1 d ago
ListingProSQL injection
CVE-2026-42414
High 8.5Up to 2.9.12Check for an update1 d ago
Snapshotify - All-in-One Backup & Restore & MigrateSensitive data exposure
CVE-2026-42413
High 7.5Up to 1.3.2No fixed version yet1 d ago
Norvis BackupSensitive data exposure
CVE-2026-41562
High 7.5Up to 1.1.0Check for an update1 d ago
Museder RestoreOne
10+ installs
Sensitive data exposure
CVE-2026-41561
High 7.5Up to 2.7.276No fixed version yet1 d ago
WXD Backup LiteBroken access control
CVE-2026-41560
High 7.5Up to 1.0.2No fixed version yet1 d ago
SafeSnap - Verified WordPress Backup & RestoreSensitive data exposure
CVE-2026-41559
High 7.5Up to 2.1.2Check for an update1 d ago
Newsletter Subscription Form - User Subscriptions Form, Capture Email
1,000+ installs
SQL injection
CVE-2026-41555
Critical 9.3Up to 1.5.9No fixed version yet1 d ago
CF7 Views - Complete Entry Management for Contact Form 7
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-40807
High 7.1Up to 3.2.6No fixed version yet1 d ago
Blog, Posts and Category Filter for Elementor
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-40806
High 7.1Up to 2.1.0No fixed version yet1 d ago
TrueBooker - Appointment Booking and Scheduler System
600+ installs
Broken access control
CVE-2026-39798
Medium 6.5Up to 1.2.9No fixed version yet1 d ago
The GDPR Framework By Data443
10,000+ installs
PHP object injection
CVE-2026-39797
Critical 9.8Up to 2.5.0No fixed version yet1 d ago
Advanced Posts Listing - Show Post List Easily
3,000+ installs
Broken access control
CVE-2026-39796
High 7.5Up to 1.0.8No fixed version yet1 d ago
SendPress NewslettersSQL injection
CVE-2026-39795
Critical 9.3Up to 1.26.1.20Check for an update1 d ago
WCFM - Multivendor Marketplace REST API for WooCommerce
1,000+ installs
Broken access control
CVE-2026-39794
High 7.5Up to 1.6.3No fixed version yet1 d ago
Simple JWT Login - Allows you to use JWT on REST endpoints.
4,000+ installs
Authentication bypass
CVE-2026-39793
High 8.8Not yet publishedCheck for an update1 d ago
Simple File ListArbitrary file deletion
CVE-2026-39792
High 8.6Up to 6.3.11Check for an update1 d ago
Mailjet Email Marketing
10,000+ installs
Sensitive data exposure
CVE-2026-39791
Medium 5.3Up to 6.2.3No fixed version yet1 d ago
VikRentCar Car Rental Management System
4,000+ installs
Cross-site scripting (XSS)
CVE-2026-39790
High 7.1Up to 1.4.6No fixed version yet1 d ago
Front End PM
4,000+ installs
Cross-site scripting (XSS)
CVE-2026-39788
Medium 6.5Up to 11.4.6No fixed version yet1 d ago
10WebSocial
10,000+ installs
Broken access control
CVE-2026-39787
Medium 6.5Up to 1.4.35No fixed version yet1 d ago
Gmedia Photo Gallery
7,000+ installs
SQL injection
CVE-2026-39785
Critical 9.3Up to 1.25.1No fixed version yet1 d ago
Hotel Booking
4,000+ installs
Cross-site scripting (XSS)
CVE-2026-39784
High 7.1Up to 3.8No fixed version yet1 d ago
Document Gallery
8,000+ installs
Cross-site scripting (XSS)
CVE-2026-39781
High 7.1Up to 5.1.1No fixed version yet1 d ago
Youzify - BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress
5,000+ installs
Cross-site scripting (XSS)
CVE-2026-39780
High 7.1Up to 1.3.7No fixed version yet1 d ago
Ansar Import - One Click Starter Sites - for Elementor & Themes
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-39778
High 7.1Up to 2.1.2No fixed version yet1 d ago
Tabs Responsive - With WooCommerce Product Tabs ExtensionRemote code execution
CVE-2026-39776
High 8.0Up to 2.5Check for an update1 d ago
JobZilla - Job Board WordPress ThemePrivilege escalation
CVE-2026-39775
High 8.8Up to 2.2Check for an update1 d ago
Tourfic ProPrivilege escalation
CVE-2026-39774
High 8.8Up to 1.17.3Check for an update1 d ago
Doctreat CorePrivilege escalation
CVE-2026-39773
Critical 10.0Up to 1.7.0Check for an update1 d ago
Captcha by BestWebSoft - Advanced Spam Protection, Math & OCR-Friendly Captcha for Site Forms
10,000+ installs
Security weakness
CVE-2026-39772
Medium 5.3Up to 5.2.8No fixed version yet1 d ago
Buddyboss PlatformSQL injection
CVE-2026-39771
High 8.5Up to 3.1.0Check for an update1 d ago
DoctreatArbitrary file upload
CVE-2026-39770
Critical 10.0Up to 1.7.0Check for an update1 d ago
Graphina - Charts and Graphs For Elementor
10,000+ installs
Authentication bypass
CVE-2026-39769
High 7.5Up to 3.1.12No fixed version yet1 d ago
Security Plugin, Firewall & Malware Scanner with Auto Removal
40,000+ installs
Cross-site scripting (XSS)
CVE-2026-39768
High 7.1Up to 2.189No fixed version yet1 d ago
WPBase Cache
3,000+ installs
Denial of service
CVE-2026-39767
Medium 6.5Up to 5.5.6No fixed version yet1 d ago
ARFormsCross-site scripting (XSS)
CVE-2026-39766
High 7.1Up to 7.1.2Check for an update1 d ago
PDF Invoices & Packing Slips for WooCommerce - Challan
8,000+ installs
Privilege escalation
CVE-2026-39765
High 7.2Up to 3.7.88No fixed version yet1 d ago
Radius Booking - Appointment Booking Calendar & Scheduling for Services & Events
400+ installs
SQL injection
CVE-2026-39764
Critical 9.3Up to 1.0.19No fixed version yet1 d ago
Autoship Cloud for WooCommerce Subscription Products
100+ installs
Broken access control
CVE-2026-39762
Medium 6.5Up to 2.17.1No fixed version yet1 d ago
Meta Box AIOPrivilege escalation
CVE-2026-39761
Critical 9.8Up to 3.7.1Check for an update1 d ago
Workreap CoreArbitrary file upload
CVE-2026-39759
Critical 9.9Up to 3.4.5Check for an update1 d ago
Midtrans-WooCommerce
5,000+ installs
Cross-site scripting (XSS)
CVE-2026-39758
High 7.1Up to 2.32.3No fixed version yet1 d ago
TaskbotArbitrary file upload
CVE-2026-39757
Critical 9.9Up to 6.6Check for an update1 d ago
Appointment Bookings for Zoom GoogleMeet and more - Wappointment
1,000+ installs
Broken access control
CVE-2026-39756
Medium 6.5Up to 2.7.7No fixed version yet1 d ago
WP Duplicate - WordPress Migration Plugin
200+ installs
Arbitrary file upload
CVE-2026-39755
Critical 9.9Up to 1.1.11No fixed version yet1 d ago
Piotnet Addons For Elementor
20,000+ installs
Arbitrary file read
CVE-2026-39754
Medium 6.5Up to 7.1.71No fixed version yet1 d ago
TaskbotPrivilege escalation
CVE-2026-39753
Critical 9.8Up to 6.6Check for an update1 d ago
Job Postings
10,000+ installs
Arbitrary file deletion
CVE-2026-39752
High 7.7Up to 2.8.2No fixed version yet1 d ago
PayPlug for WooCommerce (Official)
4,000+ installs
Broken access control
CVE-2026-39751
High 7.5Up to 3.1.0No fixed version yet1 d ago
StoreGrowth - Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce
2,000+ installs
Cross-site scripting (XSS)
CVE-2026-39750
High 7.1Up to 2.0.6Fixed in a later version (latest 2.2.0)1 d ago
App for Cloudflare®
1,000+ installs
Broken access control
CVE-2026-39749
Medium 6.5Up to 1.10.1No fixed version yet1 d ago
EduMallCross-site scripting (XSS)
CVE-2026-39748
High 7.1Up to 4.5.3Check for an update1 d ago
WofficeSQL injection
CVE-2026-39747
High 8.5Up to 5.4.35Check for an update1 d ago
BookneticSQL injection
CVE-2026-39746
Critical 9.3Up to 4.8.5Check for an update1 d ago
Contact Form to DB by BestWebSoft - Messages Database Plugin For WordPress
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-39745
High 7.1Up to 1.7.6No fixed version yet1 d ago
Database for CF7Cross-site scripting (XSS)
CVE-2026-39731
High 7.1Up to 1.2.6Check for an update1 d ago
Wise Chat
5,000+ installs
Broken access control
CVE-2026-39730
High 7.1Up to 3.4.3No fixed version yet1 d ago
Edwiser Bridge - WordPress Moodle Integration
4,000+ installs
Sensitive data exposure
CVE-2026-39729
High 7.2Up to 4.3.4No fixed version yet1 d ago
Instapage Plugin
4,000+ installs
Server-side request forgery (SSRF)
CVE-2026-39728
High 7.2Up to 3.7.2No fixed version yet1 d ago
WC Fields Factory
7,000+ installs
Cross-site scripting (XSS)
CVE-2026-39727
Medium 6.5Up to 4.1.12No fixed version yet1 d ago
Lumise Product DesignerCross-site scripting (XSS)
CVE-2026-39726
High 7.1Up to 2.1.1Check for an update1 d ago
Content Visibility for Divi Builder
2,000+ installs
Remote code execution
CVE-2026-39725
High 8.8Up to 5.03No fixed version yet1 d ago
HTTP Requests Manager
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-39724
High 7.1Up to 1.3.11No fixed version yet1 d ago
WPLMSCross-site scripting (XSS)
CVE-2026-39722
High 7.1Up to 4.972Check for an update1 d ago
Mapster WP Maps
3,000+ installs
Cross-site scripting (XSS)
CVE-2026-39720
High 7.1Up to 2.0.4No fixed version yet1 d ago
PDF Smart Viewer for Elementor
1,000+ installs
Server-side request forgery (SSRF)
CVE-2026-39719
High 7.2Up to 1.0.4No fixed version yet1 d ago
Mooberry Book Manager
1,000+ installs
SQL injection
CVE-2026-32581
High 7.1Not yet publishedCheck for an update1 d ago
WooCommerce LotterySQL injection
CVE-2026-32580
High 7.5Up to 2.2.9Check for an update1 d ago
Kognetiks Chatbot
500+ installs
Arbitrary file upload
CVE-2026-32579
Critical 10.0Up to 2.4.9No fixed version yet1 d ago
ECPay Ecommerce for WooCommerce
2,000+ installs
Broken access control
CVE-2026-32578
High 7.1Up to 1.1.2606090No fixed version yet1 d ago
Frontend File Manager PluginCross-site scripting (XSS)
CVE-2026-32577
High 7.1Up to 23.6Check for an update1 d ago
SUMO Affiliates ProCross-site scripting (XSS)
CVE-2026-32575
High 7.1Up to 11.7.0Check for an update1 d ago
Smart Forms - when you need more than just a contact form
5,000+ installs
Cross-site scripting (XSS)
CVE-2026-32574
High 7.1Up to 2.6.104No fixed version yet1 d ago
WP User Frontend ProCross-site scripting (XSS)
CVE-2026-32572
High 7.1Up to 4.2.13Check for an update1 d ago
Ohio ExtraCross-site scripting (XSS)
CVE-2026-32571
Medium 6.5Up to 3.6.8Check for an update1 d ago
Progressify - Progressive Web App (PWA)Cross-site scripting (XSS)
CVE-2026-32570
High 7.1Up to 1.6.0Check for an update1 d ago
WP Media folderCross-site scripting (XSS)
CVE-2026-32569
High 7.1Up to 6.2.2Check for an update1 d ago
WooCommerce Designer ProRemote code execution
CVE-2026-32568
Critical 9.9Up to 1.9.33Check for an update1 d ago
WooCommerce AppointmentsSQL injection
CVE-2026-32557
Critical 9.3Up to 5.3.2Check for an update1 d ago
WP2LEADS | WordPress und KlickTipp einfach verbinden - WooCommerce und KlickTipp einfach verbinden
70+ installs
SQL injection
CVE-2026-25434
High 8.5Up to 3.5.7No fixed version yet1 d ago
WP2LEADS | WordPress und KlickTipp einfach verbinden - WooCommerce und KlickTipp einfach verbinden
70+ installs
Broken access control
CVE-2026-25433
High 7.1Up to 3.5.7No fixed version yet1 d ago
Crocoblock JetElements For Elementor jet-elementsCross-site scripting (XSS)
CVE-2026-105879
Medium 6.5Up to 2.9.2.2Check for an update1 d ago
Payflex Payment Gateway
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-103346
High 7.1Up to 2.7.1Fixed in a later version (latest 2.8.0)1 d ago
ACPT (Premium)Remote code execution
CVE-2026-105701
High 8.8Up to 2.0.66Check for an update1 d ago
File Media RenamerBroken access control
CVE-2026-94278
Medium 5.5Up to 1.3Check for an update1 d ago
Fast CourierBroken access control
CVE-2026-89289
Medium 5.3Up to 5.2.3Check for an update1 d ago
Slider Pro
4,000+ installs
Sensitive data exposure
CVE-2026-86786
Medium 5.3Up to 1.0.0Fixed in a later version (latest 4.8.16)1 d ago
elegro Crypto PaymentBroken access control
CVE-2026-94299
Medium 6.5Up to 1.0.1Check for an update1 d ago
Deema Payment GatewayAuthentication bypass
CVE-2026-94271
Medium 5.3Up to 1.1.2Check for an update1 d ago
Deema Payment GatewayAuthentication bypass
CVE-2026-94270
Medium 5.3Up to 1.1.2Check for an update1 d ago
Post SMTP - Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-75962
High 7.2Up to 4.0.1Fixed in a later version (latest 4.0.2)1 d ago
Eventin - Events Calendar, Tickets, Registration, Booking & WooCommerce
10,000+ installs
Broken access control
CVE-2026-97300
Medium 6.5Up to 4.1.25No fixed version yet1 d ago
SitemovrSensitive data exposure
CVE-2026-41563
High 7.5Up to 1.0.1No fixed version yet1 d ago
WP Synchro - The Ultimate WordPress Migration Tool
2,000+ installs
Security weakness
CVE-2026-41558
High 7.5Up to 1.16.1No fixed version yet1 d ago
Fluent Affiliate ProBroken access control
CVE-2026-39789
High 7.5Up to 1.6.4Check for an update1 d ago
Real3D Flipbook - 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-39760
High 7.1Up to 5.5No fixed version yet1 d ago
Morning for WooCommerce
1,000+ installs
Broken access control
CVE-2026-39723
High 7.5Up to 2.4.1No fixed version yet1 d ago
WDS MCP Content Manager
10+ installs
Broken access control
CVE-2026-39599
Medium 4.3Up to 3.10.4No fixed version yet1 d ago
IATO MCP
100+ installs
Broken access control
CVE-2026-32582
Medium 6.5Up to 1.11.0No fixed version yet1 d ago
Faktur Pro for WooCommerce
900+ installs
Broken access control
CVE-2026-32576
Medium 6.5Up to 3.2.2No fixed version yet1 d ago
FluentBooking ProBroken access control
CVE-2026-105072
High 7.5Before 2.5.0Fixed in 2.5.01 d ago
Simple Event Planner
1,000+ installs
PHP object injection
CVE-2026-97257
High 8.8Up to 1.5.7Fixed in a later version (latest 1.5.8)2 d ago
WP BASE Booking of Appointments, Services and Events
200+ installs
SQL injection
CVE-2026-103066
High 8.5Up to 6.4.0Fixed in a later version (latest 6.5.0)2 d ago
VK Google Job Posting Manager
2,000+ installs
PHP object injection
CVE-2026-100511
High 8.8Up to 1.3.1Fixed in a later version (latest 1.4.0)2 d ago
WP Spell Check
2,000+ installs
PHP object injection
CVE-2026-100506
High 7.2Up to 12.1Fixed in a later version (latest 12.2)2 d ago
Sunshine Photo Cart - Client Photo Gallery & Photo Proofing for Photographers
1,000+ installs
PHP object injection
CVE-2026-93617
High 7.2Up to 3.7.1Fixed in a later version (latest 3.7.2)2 d ago
Export All Posts, Products, Orders & Users | WP Ultimate Exporter | WordPress CSV Export
6,000+ installs
PHP object injection
CVE-2026-103348
High 7.2Up to 3.0Fixed in a later version (latest 3.1)2 d ago
SmartyParcel - Shipping Automation & Order Tracking for GLS, InPost, Nova Post and more
7,000+ installs
Broken access control
CVE-2026-103337
Medium 6.5Up to 1.23.2Fixed in a later version (latest 1.23.3)2 d ago
Scratch & Win - Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more
200+ installs
Broken access control
CVE-2026-97303
High 7.6Up to 3.0.2Fixed in a later version (latest 3.1.0)2 d ago
Product Feed PRO for WooCommerce by AdTribes - Product Feeds for WooCommerce
80,000+ installs
PHP object injection
CVE-2026-103349
High 7.2Up to 13.5.7Fixed in a later version (latest 13.5.8)2 d ago
RepairBuddy - Repair Shop CRM & Booking Plugin for WordPress
400+ installs
Broken access control
CVE-2026-97309
High 7.1Up to 4.1226Fixed in a later version (latest 4.1231)2 d ago
Hyve Lite - AI Chatbot Trained on WordPress Posts, Pages, Products & More with ChatGPT
7,000+ installs
Broken access control
CVE-2026-97305
Medium 6.9Up to 2.0.2Fixed in a later version (latest 2.0.3)2 d ago
Advanced Post Manager
4,000+ installs
PHP object injection
CVE-2026-97283
Critical 9.8Up to 4.5.5Fixed in a later version (latest 4.5.6)2 d ago
BuildKit - Product Builder for WooCommerce - Custom PC Builder
300+ installs
Security weakness
CVE-2026-97275
Medium 5.3Up to 1.0.28Fixed in a later version (latest 1.0.29)2 d ago
Cozy Blocks - Website Builder for WordPress Block Editor | Gutenberg Blocks, Patterns & Templates
6,000+ installs
Broken access control
CVE-2026-97070
Medium 6.9Up to 2.2.23Fixed in a later version (latest 2.2.25)2 d ago
WP BASE Booking of Appointments, Services and Events
200+ installs
SQL injection
CVE-2026-103352
Critical 9.3Up to 6.4.0Fixed in a later version (latest 6.5.0)2 d ago
Five Star Restaurant Reservations - WordPress Booking Plugin
10,000+ installs
Sensitive data exposure
CVE-2026-103334
High 7.5Up to 2.7.24Fixed in a later version (latest 2.8.0)2 d ago
Timetics - Appointment Booking Calendar & Scheduling
2,000+ installs
Broken access control
CVE-2026-97304
Medium 6.5Up to 1.0.63Fixed in a later version (latest 1.0.64)2 d ago
UsersWP - Front-end login form, User Registration, User Profile & Members Directory plugin for WP
20,000+ installs
Broken access control
CVE-2026-103086
Medium 6.5Up to 1.2.74Fixed in a later version (latest 1.2.76)2 d ago
WP User Manager - Registration Form, Login Form, User Profile & Member Directory
10,000+ installs
Privilege escalation
CVE-2026-103085
Medium 6.5Up to 2.9.20Fixed in a later version (latest 2.9.21)2 d ago
Lookzy LookBook for WooCommerce
200+ installs
Broken access control
CVE-2026-102383
Medium 6.5Up to 1.1.14Fixed in a later version (latest 1.1.15)2 d ago
Photo Reviews for WooCommerce
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-100515
High 7.1Up to 1.2.30Fixed in a later version (latest 1.2.31)2 d ago
RepairBuddy - Repair Shop CRM & Booking Plugin for WordPress
400+ installs
Cross-site scripting (XSS)
CVE-2026-100509
Medium 6.5Up to 4.1225Fixed in a later version (latest 4.1231)2 d ago
AdsmonetizerCross-site scripting (XSS)
CVE-2025-15643
High 7.1Up to 3.2.4Check for an update2 d ago
Image Slider
4,000+ installs
Cross-site scripting (XSS)
CVE-2026-42700
Medium 6.5Up to 1.1.130No fixed version yet2 d ago
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses
70,000+ installs
Cross-site scripting (XSS)
CVE-2026-105397
Medium 5.4Up to 4.4.9.1No fixed version yet2 d ago
Kit (formerly ConvertKit) for WooCommerce
4,000+ installs
Broken access control
CVE-2026-105421
Medium 5.3Up to 2.2.0Fixed in a later version (latest 2.2.1)2 d ago
Polylang
800,000+ installs
Broken access control
CVE-2026-39783
Medium 4.3Up to 3.8.7Fixed in a later version (latest 3.8.10)2 d ago
Eventin - Events Calendar, Tickets, Registration, Booking & WooCommerce
10,000+ installs
Broken access control
CVE-2026-103684
Medium 5.3Up to 4.1.25No fixed version yet2 d ago
Eventin - Events Calendar, Tickets, Registration, Booking & WooCommerce
10,000+ installs
Broken access control
CVE-2026-105073
Medium 5.3Up to 4.1.25No fixed version yet2 d ago
WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformproBroken access control
CVE-2026-94669
Medium 5.3Up to 6.2.13Check for an update2 d ago
WP Dummy Content Generator
5,000+ installs
Broken access control
CVE-2026-39763
Medium 4.3Up to 4.0.0No fixed version yet2 d ago
Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg
1m+ installs
Broken access control
CVE-2026-39721
Medium 5.4Up to 4.7.7Fixed in a later version (latest 4.7.8)2 d ago
Unlimited Elements for Elementor
300,000+ installs
Broken access control
CVE-2026-105064
Medium 6.5Up to 2.0.22No fixed version yet2 d ago
E-cab Taxi Booking Manager for Woocommerce
2,000+ installs
Security weakness
CVE-2026-103351
Medium 5.3Up to 2.1.1Fixed in a later version (latest 2.1.2)2 d ago
Image Optimizer, Resizer and CDN - Sirv
1,000+ installs
SQL injection
CVE-2026-104389
High 8.5Up to 8.2.5No fixed version yet2 d ago
PowerPress Podcasting plugin by Blubrry
20,000+ installs
Broken access control
CVE-2026-104388
Medium 5.3Up to 11.17.9No fixed version yet2 d ago
Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg
1m+ installs
Cross-site scripting (XSS)
CVE-2026-102393
Medium 6.5Up to 4.7.7Fixed in a later version (latest 4.7.8)2 d ago
JS Help Desk - AI-Powered Support & Ticketing System
7,000+ installs
Broken access control
CVE-2026-103079
Medium 5.4Up to 4.0.0No fixed version yet2 d ago
Name Directory
2,000+ installs
Cross-site scripting (XSS)
CVE-2026-104396
Medium 6.5Up to 1.34.2No fixed version yet2 d ago
Presto Player
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-102914
Medium 6.5Up to 4.5.2Fixed in a later version (latest 4.5.3)2 d ago
Event Tickets and Registration
90,000+ installs
Broken access control
CVE-2026-104675
Medium 4.3Up to 5.30.0No fixed version yet2 d ago
Premium Addons for Elementor - AI-Ready Elementor Addons, Widgets & Templates
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-103084
Medium 6.5Up to 4.11.109No fixed version yet2 d ago
Name Directory
2,000+ installs
Broken access control
CVE-2026-104397
Medium 5.3Up to 1.34.2No fixed version yet2 d ago
Logo Showcase - Logo Slider, Carousel & Sponsors GalleryCross-site scripting (XSS)
CVE-2026-105060
Medium 6.5Up to 4.0.4Check for an update2 d ago
MP3 Audio Player - Music Player, Podcast Player & Radio by Sonaar
20,000+ installs
Cross-site scripting (XSS)
CVE-2026-104673
Medium 6.5Up to 5.14.2No fixed version yet2 d ago
eCommerce Product Catalog
7,000+ installs
Cross-site scripting (XSS)
CVE-2026-105056
Medium 6.5Up to 3.6.2No fixed version yet2 d ago
Groundhogg - CRM, Newsletters, and Marketing Automation
2,000+ installs
SQL injection
CVE-2026-104408
High 7.6Up to 4.8.3No fixed version yet2 d ago
Video Conferencing with Zoom
10,000+ installs
Sensitive data exposure
CVE-2026-103335
Medium 5.3Up to 4.6.10Fixed in a later version (latest 4.6.11)2 d ago
WP Mailster
300+ installs
Broken access control
CVE-2026-105055
Medium 5.3Up to 1.9.0.0No fixed version yet2 d ago
CURCY - Multi Currency for WooCommerce
20,000+ installs
Broken access control
CVE-2026-97071
Medium 5.3Up to 2.2.17No fixed version yet2 d ago
WP Admin Audit
1,000+ installs
Broken access control
CVE-2026-105062
Medium 4.3Up to 1.2.17Fixed in a later version (latest 1.2.18)2 d ago
JS Help Desk - AI-Powered Support & Ticketing System
7,000+ installs
Broken access control
CVE-2026-103078
Medium 4.3Up to 4.0.0No fixed version yet2 d ago
PowerPress Podcasting plugin by Blubrry
20,000+ installs
Cross-site request forgery (CSRF)
CVE-2026-104407
High 7.1Up to 11.17.9No fixed version yet2 d ago
WPVR - 360 Panorama viewer and Virtual Tour Builder for WordPress
10,000+ installs
Broken access control
CVE-2026-104386
Medium 6.5Up to 9.1.3No fixed version yet2 d ago
QR Redirector
4,000+ installs
Cross-site scripting (XSS)
CVE-2026-105069
Medium 6.5Up to 2.0.5No fixed version yet2 d ago
GiveWP - Donation Plugin and Fundraising Platform
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-104404
Medium 6.5Up to 4.17.0No fixed version yet2 d ago
Events Manager - Calendar, Bookings, Tickets, Appointments and more!
60,000+ installs
Sensitive data exposure
CVE-2026-105068
Medium 5.3Up to 7.4.5No fixed version yet2 d ago
Memberful - Membership Plugin
1,000+ installs
Broken access control
CVE-2026-104401
Medium 4.3Up to 1.81.2No fixed version yet2 d ago
bBlocks - Essential Gutenberg Blocks & Patterns Collection
700+ installs
Cross-site scripting (XSS)
CVE-2026-104400
Medium 6.5Up to 2.1.8Fixed in a later version (latest 2.1.9)2 d ago
Image Photo Gallery Final Tiles Grid
20,000+ installs
Cross-site scripting (XSS)
CVE-2026-104409
Medium 6.5Up to 3.6.13Fixed in a later version (latest 3.6.14)2 d ago
UPI QR Code Payment Gateway
1,000+ installs
Broken access control
CVE-2026-84169
Medium 5.3Up to 1.4.3No fixed version yet2 d ago
File Uploads Addon for WooCommerceBroken access control
CVE-2026-78371
Medium 5.9Before 1.7.6Fixed in 1.7.62 d ago
File Uploads Addon for WooCommerceBroken access control
CVE-2026-13607
Medium 5.9Up to 1.7.6Check for an update2 d ago
Mindio Magic MCPSensitive data exposure
CVE-2026-104402
Medium 4.3Up to 0.5.6Fixed in a later version (latest 0.7.1)3 d ago
Cost Calculator Builder
20,000+ installs
Sensitive data exposure
CVE-2026-97307
High 7.5Up to 4.0.17Fixed in a later version (latest 4.0.18)3 d ago
Unlimited Elements for Elementor
300,000+ installs
SQL injection
CVE-2026-103355
Critical 9.3Up to 2.0.20Fixed in a later version (latest 2.0.21)3 d ago
Unlimited Elements for Elementor
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-103344
High 7.1Up to 2.0.20Fixed in a later version (latest 2.0.21)3 d ago
WP Statistics - Simple, privacy-friendly Google Analytics alternative
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-97276
High 7.1Up to 14.16.14Fixed in a later version (latest 14.16.15)3 d ago
TranslatePress - Translate Multilingual sites with AI Translation
400,000+ installs
Cross-site scripting (XSS)
CVE-2026-103062
High 7.1Up to 3.3.6Fixed in a later version (latest 3.3.7)3 d ago
Kadence Blocks - Page Builder Toolkit for Gutenberg Editor
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-103354
High 7.1Up to 3.7.11.1Fixed in a later version (latest 3.7.12)3 d ago
User Private Files - Secure File Sharing and Client Portal Plugin
1,000+ installs
Broken access control
CVE-2026-97332
Medium 5.3Before 2.2.0Fixed in 2.2.03 d ago
CoCart - Headless REST API for WooCommerce
900+ installs
Cross-site request forgery (CSRF)
CVE-2026-93549
High 8.8Before 4.9.7Fixed in 4.9.73 d ago
Five Star Business Profile and Schema
7,000+ installs
Sensitive data exposure
CVE-2026-86817
Medium 4.9Before 2.4.0Fixed in 2.4.03 d ago
Simple Shopping Cart
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-104119
Low 3.5Before 5.2.6Fixed in 5.2.63 d ago
Razorpay for WooCommerce
100,000+ installs
Broken access control
CVE-2026-104118
Medium 5.3Before 4.8.8Fixed in 4.8.83 d ago
Horizontal scrolling announcementsCross-site scripting (XSS)
CVE-2026-17005
Medium 6.8Up to 2.6Check for an update3 d ago
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
200,000+ installs
Privilege escalation
CVE-2026-96451
High 8.8Up to 2.13.1Fixed in a later version (latest 2.14.0)4 d ago
Unlimited Elements for Elementor
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-103342
High 7.1Up to 2.0.20Fixed in a later version (latest 2.0.21)4 d ago
Kirki - Freeform Page Builder, Website Builder & Customizer
500,000+ installs
Security weakness
CVE-2026-103065
High 8.2Up to 6.3.1Fixed in a later version (latest 6.3.2)4 d ago
Twenty20 Image Before-After
20,000+ installs
Cross-site scripting (XSS)
CVE-2026-92767
Medium 6.4Up to 2.0.5Fixed in a later version (latest 2.1.0)4 d ago
Beaver Builder Page Builder - Drag and Drop Website Builder
100,000+ installs
Remote code execution
CVE-2026-92084
Critical 9.1Up to 2.11.0.5Fixed in a later version (latest 2.11.0.6)4 d ago
WP Ultimate Review
60,000+ installs
Remote code execution
CVE-2026-100157
Medium 6.5Up to 2.4.3Fixed in a later version (latest 2.4.4)4 d ago
Smart Manager - WooCommerce Bulk Edit: Products, Orders, Users & More (Spreadsheet)
10,000+ installs
SQL injection
CVE-2026-18443
High 8.8Up to 8.97.0Fixed in a later version (latest 8.98.0)4 d ago
WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System
5,000+ installs
Broken access control
CVE-2026-11601
Medium 5.3Up to 3.0.19Fixed in a later version (latest 3.0.21)4 d ago
WP Visitor Statistics (Real Time Traffic)
20,000+ installs
SQL injection
CVE-2026-96267
High 7.5Up to 8.7Fixed in a later version (latest 8.7.1)4 d ago
Nelio Content - Editorial Calendar & Social Media Auto-Posting
4,000+ installs
Broken access control
CVE-2026-94505
High 8.1Up to 4.5.0Fixed in a later version (latest 4.5.1)4 d ago
WPC Estimated Delivery Date for WooCommerce
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-104313
Medium 6.1Up to 4.0.1Fixed in a later version (latest 4.0.2)4 d ago
VikAppointments Services Booking Calendar
500+ installs
Remote code execution
CVE-2026-87115
Critical 9.1Up to 1.2.21Fixed in a later version (latest 1.2.22)4 d ago
WP Ultimate Review
60,000+ installs
Remote code execution
CVE-2026-103519
Medium 5.4Up to 2.4.3Fixed in a later version (latest 2.4.4)4 d ago
WPFront Notification Bar
50,000+ installs
Cross-site scripting (XSS)
CVE-2026-93896
Medium 6.1Up to 3.5.1Fixed in a later version (latest 3.5.2)4 d ago
Mail logging & Catcher
20,000+ installs
Cross-site scripting (XSS)
CVE-2026-93889
High 7.2Up to 2.1.12Fixed in a later version (latest 2.2.0)4 d ago
WPCafe - Restaurant Menu, Online Food Ordering & Table Booking System
5,000+ installs
File inclusion
CVE-2026-75028
High 7.5Up to 3.0.18Fixed in a later version (latest 3.0.21)4 d ago
WPC Product Options for WooCommerce
4,000+ installs
Cross-site scripting (XSS)
CVE-2026-97660
High 7.2Up to 4.0.5Fixed in a later version (latest 4.0.6)4 d ago
Photo Gallery by 10Web - Mobile-Friendly Image Gallery
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-92974
Medium 6.1Up to 1.8.46Fixed in a later version (latest 1.8.47)4 d ago
Responsive Starter Templates - Elementor Templates & Starter Sites
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-15795
Medium 6.4Up to 3.5.3Fixed in a later version (latest 3.5.4)4 d ago
WPMobile.App - Android and iOS App Builder
3,000+ installs
Cross-site scripting (XSS)
CVE-2026-103421
Medium 5.4Up to 11.84Fixed in a later version (latest 11.85)4 d ago
Burst Statistics - Simple WordPress Analytics (Google Analytics Alternative)
200,000+ installs
Authentication bypass
CVE-2026-97343
Medium 4.3Up to 3.7.1Fixed in a later version (latest 3.7.2)4 d ago
Pie Register - User Registration, Profiles & Content Restriction
1,000+ installs
Sensitive data exposure
CVE-2026-96962
Low 3.7Before 3.8.4.14Fixed in 3.8.4.144 d ago
Loco Translate
1m+ installs
Cross-site scripting (XSS)
CVE-2026-94239
Medium 6.8Before 2.8.9Fixed in 2.8.94 d ago
Loco Translate
1m+ installs
Path traversal
CVE-2026-94238
Medium 6.8Before 2.8.9Fixed in 2.8.94 d ago
Unlimited Elements for Elementor
300,000+ installs
SQL injection
CVE-2026-92923
Medium 6.3Before 2.0.21Fixed in 2.0.214 d ago
Mailchimp for WooCommerce
200,000+ installs
Broken access control
CVE-2026-92437
Medium 5.3Before 6.3Fixed in 6.34 d ago
TillKitAuthentication bypass
CVE-2026-91078
High 8.2Before 1.0.5Fixed in 1.0.54 d ago
SaveTo Wishlist Lite - WooCommerce Wishlist
500+ installs
SQL injection
CVE-2026-89236
High 8.6Before 1.1.5Fixed in 1.1.54 d ago
Kubio AI Page Builder
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-88783
High 8.8Before 2.9.3Fixed in 2.9.34 d ago
Kubio AI Page Builder
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-88782
Medium 6.8Before 2.9.3Fixed in 2.9.34 d ago
MetForm - Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor
600,000+ installs
Sensitive data exposure
CVE-2026-86834
Low 3.7Before 4.3.1Fixed in 4.3.14 d ago
MetForm - Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor
600,000+ installs
Sensitive data exposure
CVE-2026-86832
Medium 5.3Before 4.3.1Fixed in 4.3.14 d ago
Unlimited Elements for Elementor
300,000+ installs
SQL injection
CVE-2026-85568
Medium 6.8Before 2.0.21Fixed in 2.0.214 d ago
Unlimited Elements for Elementor
300,000+ installs
Remote code execution
CVE-2026-85015
Medium 6.6Before 2.0.21Fixed in 2.0.214 d ago
WP Ultimate CSV Importer - WordPress CSV, XML & Excel Import Export
20,000+ installs
Sensitive data exposure
CVE-2026-80518
Low 3.7Before 9.2Fixed in 9.24 d ago
WP Ultimate CSV Importer - WordPress CSV, XML & Excel Import Export
20,000+ installs
Cross-site scripting (XSS)
CVE-2026-80517
Low 3.5Before 9.2Fixed in 9.24 d ago
WP 2FA - Two-factor authentication for WordPress
100,000+ installs
Authentication bypass
CVE-2026-103514
High 7.5Before 4.1.0Fixed in 4.1.04 d ago
MPG - Multiple Page Generator, Bulk Landing Pages & Programmatic SEO
2,000+ installs
Arbitrary file read
CVE-2026-103293
Medium 6.8Before 4.2.3Fixed in 4.2.34 d ago
WP Ultimate Review
60,000+ installs
Cross-site scripting (XSS)
CVE-2026-101162
Medium 6.4Before 2.4.4Fixed in 2.4.44 d ago
WP Ultimate Review
60,000+ installs
Denial of service
CVE-2026-101161
High 7.5Before 2.4.4Fixed in 2.4.44 d ago
WP Ultimate Review
60,000+ installs
Denial of service
CVE-2026-101160
High 7.5Before 2.4.4Fixed in 2.4.44 d ago
WP Ultimate Review
60,000+ installs
Cross-site scripting (XSS)
CVE-2026-101159
High 7.5Before 2.4.4Fixed in 2.4.44 d ago
Calculated Fields Form - AI Form Builder for WordPress - Contact, Payment, Quote, Quiz & More
40,000+ installs
Cross-site scripting (XSS)
CVE-2026-103909
Medium 6.1Up to 5.5.1.5No fixed version yet4 d ago
WPC Smart Quick View for WooCommerce
90,000+ installs
Cross-site scripting (XSS)
CVE-2026-103888
Medium 6.1Up to 4.4.0No fixed version yet4 d ago
Transliterator - Multilingual and Multi-script Text Conversion
3,000+ installs
Cross-site scripting (XSS)
CVE-2026-96575
High 7.2Up to 2.5.8Fixed in a later version (latest 2.5.10)4 d ago
SEOPress - AI SEO Plugin & On-site SEO
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-101357
Medium 4.9Up to 10.2Fixed in a later version (latest 10.3)4 d ago
Rich Showcase for Google Reviews
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-100148
Medium 6.4Up to 7.1.3Fixed in a later version (latest 7.1.4)4 d ago
Welcart e-Commerce
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-87091
High 7.2Up to 2.12.2Fixed in a later version (latest 2.12.4)4 d ago
Photo Reviews for WooCommerce
10,000+ installs
Broken access control
CVE-2026-101923
High 8.1Up to 1.2.30Fixed in a later version (latest 1.2.31)4 d ago
WPZOOM Connect: AI Chat, Click to Chat, Social Icons & Share Buttons
90,000+ installs
Sensitive data exposure
CVE-2026-100149
Medium 5.3Up to 4.7.3Fixed in a later version (latest 4.7.4)4 d ago
Simple Membership
40,000+ installs
Authentication bypass
CVE-2026-97337
High 7.5Up to 4.8.3Fixed in a later version (latest 4.8.4)4 d ago
All in One SEO - AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
2m+ installs
Remote code execution
CVE-2026-100152
Medium 6.5Up to 5.0.2No fixed version yet4 d ago
Ultra Addons Lite for Elementor
700+ installs
Cross-site scripting (XSS)
CVE-2025-12828
Medium 6.4Up to 1.3.2Fixed in a later version (latest 1.3.3)4 d ago
Strong Testimonials
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-96650
High 7.2Up to 3.3.11Fixed in a later version (latest 3.3.12)4 d ago
SEOPress - AI SEO Plugin & On-site SEO
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-96564
High 7.2Up to 10.2Fixed in a later version (latest 10.3)4 d ago
Magic Tooltips For Contact Form 7
700+ installs
Cross-site scripting (XSS)
CVE-2026-101928
High 7.2Up to 1.0.34Fixed in a later version (latest 1.0.35)4 d ago
Visitor Traffic Real Time Statistics
30,000+ installs
Cross-site scripting (XSS)
CVE-2026-97341
High 7.2Up to 8.16Fixed in a later version (latest 8.17)4 d ago
GD Rating System
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-93430
High 7.2Up to 3.7.1No fixed version yet4 d ago
GeoDirectory - WP Business Directory Plugin and Classified Listings Directory
10,000+ installs
SQL injection
CVE-2026-103913
High 7.5Up to 2.8.186No fixed version yet4 d ago
Wp Social Login and Register Social Counter
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-97344
Medium 6.4Up to 3.2.1Fixed in a later version (latest 3.2.2)4 d ago
Alt Text AI - Automatically generate image alt text for SEO and accessibility
20,000+ installs
Broken access control
CVE-2026-91108
Medium 4.3Up to 1.10.41No fixed version yet4 d ago
Helpdesk Support Ticket System for WooCommerceBroken access control
CVE-2026-11399
Medium 4.3Up to 2.1.6Check for an update4 d ago
EmbedPress - PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-92727
Medium 6.4Up to 4.6.6Fixed in a later version (latest 4.6.7)4 d ago
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses
70,000+ installs
Cross-site scripting (XSS)
CVE-2026-92538
Medium 6.1Up to 4.4.7Fixed in a later version (latest 4.4.9.1)4 d ago
Groundhogg - CRM, Newsletters, and Marketing Automation
2,000+ installs
Privilege escalation
CVE-2026-97644
High 8.8Up to 4.9No fixed version yet4 d ago
Real Cookie Banner: GDPR & ePrivacy Cookie Consent
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-92977
High 7.2Up to 5.3.5Fixed in a later version (latest 5.3.8)4 d ago
EWWW Image Optimizer
1m+ installs
Cross-site scripting (XSS)
CVE-2026-92826
Medium 6.1Up to 8.7.7Fixed in a later version (latest 8.8.0)4 d ago
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-92551
Medium 6.1Up to 4.17.4Fixed in a later version (latest 4.17.5)4 d ago
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content - ProfilePress
100,000+ installs
Remote code execution
CVE-2026-92536
High 8.8Up to 4.17.4Fixed in a later version (latest 4.17.5)4 d ago
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
200,000+ installs
Broken access control
CVE-2026-93428
High 7.5Up to 2.13.1Fixed in a later version (latest 2.14.0)4 d ago
SupportCandy - AI Customer Support Ticket System & Live Chatbot Agent
10,000+ installs
SQL injection
CVE-2026-94539
Medium 6.5Up to 3.5.3Fixed in a later version (latest 3.5.4)4 d ago
SupportCandy - AI Customer Support Ticket System & Live Chatbot Agent
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-94378
Medium 6.4Up to 3.5.3Fixed in a later version (latest 3.5.4)4 d ago
Ivory Search - WordPress Search Plugin
90,000+ installs
Cross-site scripting (XSS)
CVE-2026-92243
Medium 6.1Up to 5.5.18No fixed version yet4 d ago
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
200,000+ installs
Cross-site scripting (XSS)
CVE-2026-96270
High 7.2Up to 2.13.1Fixed in a later version (latest 2.14.0)4 d ago
Beaver Builder Page Builder - Drag and Drop Website Builder
100,000+ installs
SQL injection
CVE-2026-95865
Medium 6.5Up to 2.11.0.5Fixed in a later version (latest 2.11.0.6)4 d ago
Jeg Kit for Elementor - Powerful Addons for Elementor, Widgets & Templates for WordPress
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-100180
Medium 5.4Up to 3.2.19Fixed in a later version (latest 3.2.20)4 d ago
Webriti Wallstreet wallstreetCross-site request forgery (CSRF)
CVE-2026-39718
High 8.8Up to 2.8.6Check for an update5 d ago
CodeArt - Google MP3 PlayerArbitrary file read
CVE-2014-125130
High 7.5Up to 1.0.11Check for an update5 d ago
All in One SEO - AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
2m+ installs
Security weakness
CVE-2026-19856
Medium 6.5Before 5.0.2.1Fixed in 5.0.2.15 d ago
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses
70,000+ installs
Broken access control
CVE-2026-39717
Medium 4.3Up to 4.4.9.1No fixed version yet5 d ago
Booking Calendar
40,000+ installs
Security weakness
CVE-2026-39601
Low 3.7Up to 11.8.4No fixed version yet5 d ago
Aculect AI Companion
10+ installs
Open redirect
CVE-2026-39600
Medium 4.7Up to 0.8.2No fixed version yet5 d ago
Issues and Series for Newspapers, Magazines, Publishers, Writers
2,000+ installs
Broken access control
CVE-2026-39444
Medium 5.4Up to 3.1.3Fixed in a later version (latest 3.1.4)5 d ago
WebSamurai
10+ installs
Broken access control
CVE-2026-39439
Medium 6.5Up to 1.0.7No fixed version yet5 d ago
Airano MCP Bridge
70+ installs
Broken access control
CVE-2026-32585
Medium 6.5Up to 2.11.0No fixed version yet5 d ago
Smart One Click Setup - Complete Demo Import & Export
100+ installs
Sensitive data exposure
CVE-2026-32584
Medium 5.3Up to 1.4.3No fixed version yet5 d ago
JetAppointmentCross-site scripting (XSS)
CVE-2026-93875
High 7.2Up to 2.5.2.1Check for an update5 d ago
Divi MembershipPrivilege escalation
CVE-2026-19652
Critical 9.8Up to 2.2.0Check for an update5 d ago
ThemeREX Group ThemeREX Addons trx_addonsServer-side request forgery (SSRF)
CVE-2026-102797
Medium 6.4Up to 2.46.0Check for an update5 d ago
ThemeREX Group ThemeREX Addons trx_addonsCross-site scripting (XSS)
CVE-2026-102798
Medium 6.5Up to 2.46.0Check for an update5 d ago
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses
70,000+ installs
Broken access control
CVE-2026-104403
Medium 5.3Up to 4.4.9Fixed in a later version (latest 4.4.9.1)5 d ago
Advanced Ads - Ad Manager & AdSense
100,000+ installs
Sensitive data exposure
CVE-2026-94180
Medium 4.3Up to 2.0.26No fixed version yet5 d ago
Download Manager
100,000+ installs
Sensitive data exposure
CVE-2026-94405
Medium 5.3Up to 3.3.71No fixed version yet5 d ago
WP Statistics - Simple, privacy-friendly Google Analytics alternative
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-97652
Medium 6.1Up to 14.16.14Fixed in a later version (latest 14.16.15)5 d ago
W3 Total Cache
900,000+ installs
Cross-site scripting (XSS)
CVE-2026-87920
High 7.2Up to 2.10.6No fixed version yet5 d ago
All in One SEO - AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights)
2m+ installs
Cross-site scripting (XSS)
CVE-2026-85492
Medium 6.1Up to 5.0.1.1Fixed in a later version (latest 5.0.2)5 d ago
WPMobile.App - Android and iOS App Builder
3,000+ installs
Authentication bypass
CVE-2026-94541
Critical 9.8Up to 11.82Fixed in a later version (latest 11.85)5 d ago
JSON API Auth
600+ installs
Authentication bypass
CVE-2026-97637
Critical 9.8Up to 3.1.2Fixed in a later version (latest 3.1.3)5 d ago
Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress
100,000+ installs
Broken access control
CVE-2026-94432
Medium 5.3Up to 5.7.1Fixed in a later version (latest 5.7.3)5 d ago
Event Tickets and Registration
90,000+ installs
SQL injection
CVE-2026-97634
Medium 6.5Up to 5.29.5Fixed in a later version (latest 5.30.0)5 d ago
Download Manager
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-97338
Medium 6.4Up to 3.3.70Fixed in a later version (latest 3.3.71)5 d ago
Listdom: AI-powered Business Directory with Classifieds Ads Listings
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-96647
Medium 6.4Up to 6.1.1Fixed in a later version (latest 6.1.2)5 d ago
No External Links
4,000+ installs
Cross-site scripting (XSS)
CVE-2026-95670
High 7.2Up to 5.2.0Fixed in a later version (latest 5.3.0)5 d ago
Smash Balloon Social Post Feed - Simple Social Feeds for WordPress
200,000+ installs
Cross-site scripting (XSS)
CVE-2026-93756
High 7.2Up to 4.13.0Fixed in a later version (latest 4.14.0)5 d ago
JetFormBuilder - Dynamic Blocks Form Builder
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-97342
High 7.2Up to 3.6.5.4Fixed in a later version (latest 3.6.6)5 d ago
Mang Board
8,000+ installs
Cross-site scripting (XSS)
CVE-2026-96871
High 7.2Up to 2.4.2Fixed in a later version (latest 2.4.3)5 d ago
Kubio AI Page Builder
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-100107
High 7.2Up to 2.9.2Fixed in a later version (latest 2.9.3)5 d ago
Relevanssi PremiumCross-site scripting (XSS)
CVE-2026-103426
High 7.2Up to 2.31.4Check for an update5 d ago
Newsletter - Send awesome emails from WordPress
200,000+ installs
Cross-site scripting (XSS)
CVE-2026-96566
High 7.2Up to 9.4.0Fixed in a later version (latest 9.4.6)5 d ago
Otter Blocks - Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE
300,000+ installs
Sensitive data exposure
CVE-2026-102002
Low 3.1Up to 3.2.6Fixed in a later version (latest 3.2.7)5 d ago
Relevanssi - A Better Search
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-97641
High 7.2Up to 4.28.3Fixed in a later version (latest 4.28.4)5 d ago
MultiVendorX - WooCommerce Multivendor Marketplace AI Powered Solutions
2,000+ installs
SQL injection
CVE-2026-12951
Medium 6.5Up to 5.0.18Fixed in a later version (latest 5.0.19)5 d ago
Download Monitor
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-100182
High 7.2Up to 5.2.10Fixed in a later version (latest 5.3.1)5 d ago
CMB2
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-97336
High 7.2Up to 2.13.0Fixed in a later version (latest 2.13.2)5 d ago
DoFollow Case by Case
1,000+ installs
Cross-site scripting (XSS)
CVE-2026-95817
High 7.2Up to 3.6.0Fixed in a later version (latest 3.6.1)5 d ago
CMB2
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-102772
High 7.2Up to 2.13.1Fixed in a later version (latest 2.13.2)5 d ago
GSpeech TTS - WordPress Text To Speech Plugin
3,000+ installs
Cross-site scripting (XSS)
CVE-2026-96578
High 7.2Up to 3.22.0Fixed in a later version (latest 3.22.2)5 d ago
MW WP Form
200,000+ installs
Cross-site scripting (XSS)
CVE-2026-96567
High 7.2Up to 5.1.7Fixed in a later version (latest 5.1.8)5 d ago
Greenshift - animation and page builder blocks
70,000+ installs
Cross-site scripting (XSS)
CVE-2026-93880
Medium 6.1Up to 13.2.0Fixed in a later version (latest 13.2.1)5 d ago
Customer Reviews for WooCommerce
80,000+ installs
Cross-site scripting (XSS)
CVE-2026-97663
High 7.2Up to 5.122.0Fixed in a later version (latest 5.123.0)5 d ago
MStore API - Create Native Android & iOS Apps On The Cloud
2,000+ installs
Broken access control
CVE-2026-97219
Medium 4.3Before 4.22.1Fixed in 4.22.15 d ago
Unlimited Elements for Elementor
300,000+ installs
Security weakness
CVE-2026-92924
Medium 5.4Before 2.0.21Fixed in 2.0.215 d ago
WebToffee Gift Cards for WooCommerce
1,000+ installs
Security weakness
CVE-2026-91020
Medium 5.3Before 1.3.1Fixed in 1.3.15 d ago
Easy PayPal & Stripe Buy Now Button
10,000+ installs
Security weakness
CVE-2026-90987
Medium 5.3Before 2.0.6Fixed in 2.0.65 d ago
WP Edit Password ProtectedBroken access control
CVE-2026-90952
Medium 5.3Before 2.0.7Fixed in 2.0.75 d ago
Popup Maker WPBroken access control
CVE-2026-85005
Medium 5.4Up to 1.4.5Check for an update5 d ago
Events CalendarSecurity weakness
CVE-2026-84740
Medium 6.5Before 6.17.5.1Fixed in 6.17.5.15 d ago
WP User FrontendBroken access control
CVE-2026-79618
Medium 4.3Before 4.3.12Fixed in 4.3.125 d ago
WP Mail Logging
300,000+ installs
Content injection
CVE-2026-1661
Medium 4.3Before 1.17.0Fixed in 1.17.05 d ago
CMP - Coming Soon & MaintenanceBroken access control
CVE-2026-13413
Medium 5.3Before 4.1.20Fixed in 4.1.205 d ago
BA Book Everything
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-102565
High 7.2Up to 1.8.28Fixed in a later version (latest 1.8.29)5 d ago
Giveaways and Contests by RafflePress - Get More Website Traffic, Email Subscribers, and Social Followers
20,000+ installs
Open redirect
CVE-2026-97318
Medium 6.1Before 1.12.27Fixed in 1.12.275 d ago
Giveaways and Contests by RafflePress - Get More Website Traffic, Email Subscribers, and Social Followers
20,000+ installs
Sensitive data exposure
CVE-2026-97317
Medium 5.3Before 1.12.27Fixed in 1.12.275 d ago
BuildKit - Product Builder for WooCommerce - Custom PC Builder
300+ installs
SQL injection
CVE-2026-94298
Medium 6.2Before 1.0.29Fixed in 1.0.295 d ago
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
300,000+ installs
Denial of service
CVE-2026-91828
High 7.5Before 6.3.11Fixed in 6.3.115 d ago
Motors - Car Dealership & Classified Listings Plugin
9,000+ installs
Broken access control
CVE-2026-91023
Low 3.1Before 1.4.124Fixed in 1.4.1245 d ago
Motors - Car Dealership & Classified Listings Plugin
9,000+ installs
Cross-site scripting (XSS)
CVE-2026-91022
Medium 6.8Before 1.4.124Fixed in 1.4.1245 d ago
Unlimited Elements for Elementor
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-85016
Medium 6.8Before 2.0.21Fixed in 2.0.215 d ago
Request a QuoteSensitive data exposure
CVE-2026-90988
Medium 5.3Up to 2.5.6Check for an update5 d ago
Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
700,000+ installs
Broken access control
CVE-2026-85004
Medium 4.3Up to 1.4.5Fixed in a later version (latest 1.25.0)5 d ago
Paytm Payment Gateway
3,000+ installs
Authentication bypass
CVE-2026-81740
Medium 5.3Before 2.8.9Fixed in 2.8.95 d ago
Tabs ResponsiveCross-site scripting (XSS)
CVE-2026-13718
Medium 6.8Up to 2.5Check for an update5 d ago
Autoptimize
800,000+ installs
Cross-site scripting (XSS)
CVE-2026-78471
Medium 5.4Up to 3.1.15.1Fixed in a later version (latest 3.1.16)5 d ago
Super Forms - Drag & Drop Form BuilderArbitrary file read
CVE-2026-15896
Critical 9.1Up to 6.3.316Check for an update5 d ago
SiteOrigin Widgets Bundle
400,000+ installs
File inclusion
CVE-2026-92174
High 7.5Up to 1.73.2Fixed in a later version (latest 1.74.3)5 d ago
Ninja Forms - Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-90438
High 7.2Up to 3.15.4Fixed in a later version (latest 3.15.5)5 d ago
Super Forms - Drag & Drop Form BuilderPrivilege escalation
CVE-2026-15897
High 8.8Up to 6.3.316Check for an update5 d ago
Ninja Forms - File UploadsRemote code execution
CVE-2026-92820
High 8.1Up to 3.3.34Check for an update5 d ago
Avada | Website Builder For WordPress & WooCommerceCross-site scripting (XSS)
CVE-2026-84925
Medium 6.1Up to 7.16.1Check for an update5 d ago
Divi MembershipAuthentication bypass
CVE-2026-19660
Critical 9.8Up to 2.3.0Check for an update5 d ago
CTX Feed ProRemote code execution
CVE-2026-10026
High 7.2Up to 7.6.12Check for an update5 d ago
Visitors Traffic Real Time Statistics ProCross-site scripting (XSS)
CVE-2026-93367
High 7.2Up to 11.22Check for an update5 d ago
DevKit ProAuthentication bypass
CVE-2026-14378
Critical 9.8Up to 2.3.0Check for an update5 d ago
Prime Mover - Backup and Migration
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-101890
Medium 5.4Before 2.2.1Fixed in 2.2.16 d ago
Prime Mover - Backup and Migration
10,000+ installs
Path traversal
CVE-2026-101889
Medium 6.5Before 2.2.1Fixed in 2.2.16 d ago
Prime Mover - Backup and Migration
10,000+ installs
Remote code execution
CVE-2026-101888
High 7.2Before 2.2.1Fixed in 2.2.16 d ago
SchemaEngine AI - AI Schema Markup, Reviews & Rich Snippets for SEO
10,000+ installs
Broken access control
CVE-2026-97280
Medium 6.5Not yet publishedCheck for an update6 d ago
hCaptcha for WP
80,000+ installs
Security weakness
CVE-2026-103347
Medium 5.3Up to 5.3.0Fixed in a later version (latest 5.4.0)6 d ago
ByteCoreStack - MCP Connector for AI Tools
30+ installs
Privilege escalation
CVE-2026-103068
High 8.8Up to 1.2.2Fixed in a later version (latest 1.2.4)6 d ago
Parallax Section Block - Add Parallax Scrolling Effects to Sections
3,000+ installs
Cross-site scripting (XSS)
CVE-2026-102378
High 7.1Up to 2.0.4Fixed in a later version (latest 2.1.1)6 d ago
Photo Reviews for WooCommerce
10,000+ installs
Broken access control
CVE-2026-100517
High 7.5Up to 1.2.30Fixed in a later version (latest 1.2.31)6 d ago
REST API Log
5,000+ installs
Broken access control
CVE-2026-100514
High 7.5Up to 1.7.2Fixed in a later version (latest 1.7.3)6 d ago
Gratisfaction- Loyalty, Rewards , Referral, Birthday and Giveaway Program
600+ installs
Broken access control
CVE-2026-97297
High 7.6Up to 4.6.3Fixed in a later version (latest 4.6.4)6 d ago
Icegram Engage - Popups, Optins, CTAs & Lead Generation
10,000+ installs
PHP object injection
CVE-2026-97284
High 8.8Up to 3.1.31Fixed in a later version (latest 3.1.44)6 d ago
Project Manager - AI Powered Project Management, Task Management, Kanban Board & Time Tracker
5,000+ installs
Broken access control
CVE-2026-97281
Medium 6.3Up to 4.0.7Fixed in a later version (latest 4.1.0)6 d ago
Social Boost: Giveaways, Instant win and Contests. Grow followers, shares, subscribers, traffic, referrals, sales and more
100+ installs
Broken access control
CVE-2026-97277
High 7.6Up to 3.6.2Fixed in a later version (latest 3.7.0)6 d ago
Premmerce Wishlist for WooCommerce
100+ installs
Cross-site scripting (XSS)
CVE-2026-97273
High 7.1Up to 1.1.13Fixed in a later version (latest 1.1.15)6 d ago
WPFunnels - Funnel Builder for WooCommerce with Checkout & One Click Upsell
5,000+ installs
Broken access control
CVE-2026-97269
Medium 6.5Up to 3.13.1Fixed in a later version (latest 3.13.3)6 d ago
Premmerce Wishlist for WooCommerce
100+ installs
Cross-site scripting (XSS)
CVE-2026-97268
High 7.1Up to 1.1.13Fixed in a later version (latest 1.1.15)6 d ago
MaxGalleria
2,000+ installs
Cross-site scripting (XSS)
CVE-2026-97260
High 7.1Up to 6.5.3Fixed in a later version (latest 6.5.4)6 d ago
Aruba Migration Tool
600+ installs
Broken access control
CVE-2026-97258
Medium 6.5Up to 1.0.4Fixed in a later version (latest 1.0.5)6 d ago
Bus Ticket Booking with Seat Reservation
800+ installs
Broken access control
CVE-2026-97251
Medium 6.5Up to 5.9.3Fixed in a later version (latest 5.9.5)6 d ago
AcyMailing - An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress
5,000+ installs
Arbitrary file deletion
CVE-2026-95588
High 8.6Up to 11.0.5Fixed in a later version (latest 11.1.0)6 d ago
Hide Shipping Method For WooCommerce
10,000+ installs
PHP object injection
CVE-2026-94390
High 7.2Up to 1.5.4Fixed in a later version (latest 1.5.5)6 d ago
Stripe Payment Forms by WP Full Pay - Accept Credit Card Payments, Donations & Subscriptions
8,000+ installs
Broken access control
CVE-2026-62073
High 7.5Up to 8.5.6Fixed in a later version (latest 8.5.7)6 d ago
Iptanus File Upload
10,000+ installs
SQL injection
CVE-2026-62071
Critical 9.3Up to 5.1.10Fixed in a later version (latest 5.2.0)6 d ago
Authorizer
6,000+ installs
Privilege escalation
CVE-2026-103752
Critical 9.8Up to 3.15.3Fixed in a later version (latest 3.16.0)6 d ago
CF7 Apps - Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
300,000+ installs
Sensitive data exposure
CVE-2026-62058
Medium 5.3Up to 3.7.2Fixed in a later version (latest 3.8.0)6 d ago
Ultimate Member - User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
200,000+ installs
SQL injection
CVE-2026-62059
High 7.6Up to 2.13.1Fixed in a later version (latest 2.14.0)6 d ago
Captivate Sync
1,000+ installs
SQL injection
CVE-2026-62060
High 7.6Up to 3.3.2Fixed in a later version (latest 3.3.3)6 d ago
ProfileGrid - User Profiles, Groups and Communities
5,000+ installs
Broken access control
CVE-2026-62061
Medium 5.3Up to 6.0.0.2Fixed in a later version (latest 6.0.0.3)6 d ago
Travelly - Tour & Travel Booking Manager for WooCommerce
1,000+ installs
Broken access control
CVE-2026-62063
Medium 5.4Up to 2.3.1Fixed in a later version (latest 2.3.2)6 d ago
Essential Addons for Elementor - Popular Elementor Templates & Widgets
1m+ installs
Cross-site scripting (XSS)
CVE-2026-102394
Medium 6.5Up to 6.8.4Fixed in a later version (latest 6.8.5)6 d ago
MetForm - Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-103339
Medium 6.5Up to 4.3.0Fixed in a later version (latest 4.3.1)6 d ago
BuildKit - Product Builder for WooCommerce - Custom PC Builder
300+ installs
SQL injection
CVE-2026-102379
High 8.5Up to 1.0.28Fixed in a later version (latest 1.0.29)6 d ago
ElementsKit Elementor Addons - Advanced Widgets & Templates Addons for Elementor
1m+ installs
Cross-site scripting (XSS)
CVE-2026-103063
Medium 6.5Up to 4.0.6Fixed in a later version (latest 4.0.7)6 d ago
Pie Register - User Registration, Profiles & Content Restriction
1,000+ installs
Sensitive data exposure
CVE-2026-103345
Medium 5.3Up to 3.8.4.13Fixed in a later version (latest 3.8.4.14)6 d ago
ElementsKit Elementor Addons - Advanced Widgets & Templates Addons for Elementor
1m+ installs
Cross-site scripting (XSS)
CVE-2026-103064
Medium 6.5Up to 4.0.6Fixed in a later version (latest 4.0.7)6 d ago
AFFI - Affiliate Marketing for WooCommerce
10+ installs
Broken access control
CVE-2026-102390
Medium 5.3Up to 1.0.9Fixed in a later version (latest 1.0.10)6 d ago
Majestic Support - The Leading-Edge Help Desk & Customer Support Plugin
3,000+ installs
Broken access control
CVE-2026-102382
Medium 4.3Up to 1.2.0Fixed in a later version (latest 1.2.1)6 d ago
Majestic Support - The Leading-Edge Help Desk & Customer Support Plugin
3,000+ installs
Broken access control
CVE-2026-102381
Medium 5.3Up to 1.2.0Fixed in a later version (latest 1.2.1)6 d ago
Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
700,000+ installs
Cross-site scripting (XSS)
CVE-2026-103343
Medium 6.5Up to 6.2.14Fixed in a later version (latest 6.2.15)6 d ago
Unlimited Elements for Elementor
300,000+ installs
Broken access control
CVE-2026-103341
Medium 5.3Up to 2.0.20Fixed in a later version (latest 2.0.21)6 d ago
Site Reviews
60,000+ installs
Broken access control
CVE-2026-103340
Medium 5.3Up to 8.3.2Fixed in a later version (latest 8.3.3)6 d ago
Unlimited Elements for Elementor
300,000+ installs
SQL injection
CVE-2026-103338
High 8.5Up to 2.0.20Fixed in a later version (latest 2.0.21)6 d ago
Memberful - Membership Plugin
1,000+ installs
Cross-site request forgery (CSRF)
CVE-2026-103067
High 8.0Up to 1.81.0Fixed in a later version (latest 1.81.2)6 d ago
WP Ultimate CSV Importer - WordPress CSV, XML & Excel Import Export
20,000+ installs
Sensitive data exposure
CVE-2026-103336
Medium 5.3Up to 9.1Fixed in a later version (latest 9.2)6 d ago
Fluent Forms - Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
700,000+ installs
Broken access control
CVE-2026-103353
Medium 5.3Up to 6.2.14Fixed in a later version (latest 6.2.15)6 d ago
LA-Studio Element Kit for Elementor
10,000+ installs
Server-side request forgery (SSRF)
CVE-2026-103082
High 7.2Up to 1.6.2Fixed in a later version (latest 1.6.3)6 d ago
Forminator Forms - Contact Form, Payment Form & Custom Form Builder
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-92144
High 7.2Up to 1.57.2Fixed in a later version (latest 1.57.3)6 d ago
Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns
200,000+ installs
Cross-site scripting (XSS)
CVE-2026-96256
Medium 6.4Up to 6.4.5Fixed in a later version (latest 6.4.6)6 d ago
Business Essentials for Contact Form 7
7,000+ installs
Cross-site scripting (XSS)
CVE-2026-97661
High 7.2Up to 1.2.1Fixed in a later version (latest 1.2.2)6 d ago
Ad Inserter - Ad Manager & AdSense Ads
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-89427
Medium 6.1Up to 2.8.18Fixed in a later version (latest 2.8.19)6 d ago
Duplicate Post
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-89424
Medium 6.4Up to 1.5.6Fixed in a later version (latest 1.5.7)6 d ago
Form Maker by 10Web - Mobile-Friendly Drag & Drop Contact Form Builder
30,000+ installs
Cross-site scripting (XSS)
CVE-2026-96813
High 7.2Up to 1.15.47Fixed in a later version (latest 1.15.48)6 d ago
Awesome Support - WordPress HelpDesk & Support Plugin
6,000+ installs
Cross-site scripting (XSS)
CVE-2026-96268
Medium 6.4Up to 6.4.0Fixed in a later version (latest 6.4.1)6 d ago
Calculated Fields Form - AI Form Builder for WordPress - Contact, Payment, Quote, Quiz & More
40,000+ installs
Cross-site scripting (XSS)
CVE-2026-100184
Medium 4.7Up to 5.5.1.3Fixed in a later version (latest 5.5.1.5)6 d ago
WPC Shop as a Customer for WooCommerce
400+ installs
Privilege escalation
CVE-2026-95687
High 8.8Up to 2.0.0Fixed in a later version (latest 2.0.1)6 d ago
bbp style pack
6,000+ installs
Cross-site scripting (XSS)
CVE-2026-101925
Medium 6.4Up to 6.4.8Fixed in a later version (latest 6.4.9)6 d ago
Appointment Hour Booking - Booking Calendar
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-96573
High 7.2Up to 1.5.97Fixed in a later version (latest 1.5.98)6 d ago
Forminator Forms - Contact Form, Payment Form & Custom Form Builder
600,000+ installs
Cross-site scripting (XSS)
CVE-2026-85235
High 7.2Up to 1.57.2Fixed in a later version (latest 1.57.3)6 d ago
PDF Invoices & Packing Slips for WooCommerce
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-92244
High 7.2Up to 5.16.1Fixed in a later version (latest 5.16.3)6 d ago
Redux Framework
900,000+ installs
Cross-site scripting (XSS)
CVE-2026-90992
Medium 6.4Up to 4.5.14Fixed in a later version (latest 4.5.15)6 d ago
Super Forms - Drag & Drop Form BuilderRemote code execution
CVE-2026-15983
High 8.1Up to 6.3.316Check for an update6 d ago
Autoptimize
800,000+ installs
Cross-site scripting (XSS)
CVE-2026-14995
High 7.2Up to 3.1.15.1Fixed in a later version (latest 3.1.16)6 d ago
Calculated Fields Form - AI Form Builder for WordPress - Contact, Payment, Quote, Quiz & More
40,000+ installs
Cross-site scripting (XSS)
CVE-2026-100179
Medium 6.1Up to 5.5.1.3Fixed in a later version (latest 5.5.1.5)6 d ago
ByteCoreStack - MCP Connector for AI Tools
30+ installs
Privilege escalation
CVE-2026-19807
High 8.8Up to 1.2.3Fixed in a later version (latest 1.2.4)6 d ago
Ultimate Multisite - WordPress Multisite SaaS & WaaS Platform
70+ installs
Authentication bypass
CVE-2026-75957
Critical 9.8Up to 2.15.0Fixed in a later version (latest 2.16.1)6 d ago
Ad Inserter - Ad Manager & AdSense Ads
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-19902
Medium 6.1Up to 2.8.18Fixed in a later version (latest 2.8.19)6 d ago
Super Forms - Drag & Drop Form BuilderPrivilege escalation
CVE-2026-15989
Critical 9.8Up to 6.3.316Check for an update6 d ago
LearnPress - WordPress LMS Plugin for Create and Sell Online Courses
70,000+ installs
Broken access control
CVE-2026-93882
High 7.5Up to 4.4.8Fixed in a later version (latest 4.4.9.1)6 d ago
Social Media Share Buttons & Social Sharing Icons
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-89047
Medium 6.1Up to 3.0.1Fixed in a later version (latest 3.0.2)6 d ago
Payments for Hubtel
90+ installs
Sensitive data exposure
CVE-2026-96255
High 7.5Before 1.0.2Fixed in 1.0.26 d ago
Payments for Hubtel
90+ installs
Broken access control
CVE-2026-96200
Medium 5.3Before 1.0.2Fixed in 1.0.26 d ago
Payments for Hubtel
90+ installs
Broken access control
CVE-2026-96173
Medium 5.3Before 1.0.2Fixed in 1.0.26 d ago
Five Star Restaurant Reviews
400+ installs
Cross-site scripting (XSS)
CVE-2026-92412
High 7.1Before 2.3.14Fixed in 2.3.146 d ago
WP Fusion Lite - Marketing Automation and CRM Integration for WordPress
5,000+ installs
Broken access control
CVE-2026-90974
Medium 6.5Before 3.48.0Fixed in 3.48.06 d ago
WP Fusion Lite - Marketing Automation and CRM Integration for WordPress
5,000+ installs
Broken access control
CVE-2026-90972
Medium 5.4Before 3.48.0Fixed in 3.48.06 d ago
Pro Like ButtonSQL injection
CVE-2026-89296
High 8.6Before 2.0Fixed in 2.06 d ago
If-So Dynamic Content - Elementor & All Page Builders Personalization
7,000+ installs
Cross-site scripting (XSS)
CVE-2026-87973
Low 3.1Before 1.10.2Fixed in 1.10.26 d ago
If-So Dynamic Content - Elementor & All Page Builders Personalization
7,000+ installs
Cross-site scripting (XSS)
CVE-2026-87970
Medium 4.7Before 1.10.2Fixed in 1.10.26 d ago
Download Manager
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-86610
Medium 6.4Before 3.3.71Fixed in 3.3.716 d ago
Paytm Payment Gateway
3,000+ installs
SQL injection
CVE-2026-81809
High 7.5Before 2.8.9Fixed in 2.8.96 d ago
Paytm Payment Gateway
3,000+ installs
Cross-site scripting (XSS)
CVE-2026-81739
High 7.5Before 2.8.9Fixed in 2.8.96 d ago
Cache Enabler
100,000+ installs
Arbitrary file deletion
CVE-2026-19253
High 8.7Before 1.8.17Fixed in 1.8.176 d ago
BackupSheep WordPress Backup PluginArbitrary file deletion
CVE-2026-101148
Critical 10.0Up to 1.8Check for an update6 d ago
Featured Image from URL (FIFU)
60,000+ installs
Cross-site request forgery (CSRF)
CVE-2026-101147
High 8.8Before 6.0.8Fixed in 6.0.86 d ago
Redux Framework
900,000+ installs
Broken access control
CVE-2026-88999
Medium 4.3Up to 4.5.14Fixed in a later version (latest 4.5.15)6 d ago
Extendify
500,000+ installs
Cross-site scripting (XSS)
CVE-2026-85679
High 7.2Up to 3.1.6Fixed in a later version (latest 3.2.1)6 d ago
Appointment Booking Plugin - LatePoint | Calendar & Scheduling for WordPress
100,000+ installs
Remote code execution
CVE-2026-92966
Critical 9.1Up to 5.7.0Fixed in a later version (latest 5.7.3)6 d ago
WP Popular Posts
100,000+ installs
Sensitive data exposure
CVE-2026-92548
Medium 5.3Up to 7.4.2Fixed in a later version (latest 7.4.3)6 d ago
Advanced Woo Labels - Product Labels & Badges for WooCommerce
10,000+ installs
Cross-site scripting (XSS)
CVE-2026-12241
Medium 5.4Up to 2.51Fixed in a later version (latest 2.52)6 d ago
AI Engine - The Chatbot, AI Framework & MCP for WordPress
90,000+ installs
Cross-site scripting (XSS)
CVE-2026-96561
High 7.2Up to 3.8.0Fixed in a later version (latest 3.8.3)6 d ago
Simply Schedule Appointments
50,000+ installs
Broken access control
CVE-2026-91109
Medium 6.5Up to 1.6.12.31Fixed in a later version (latest 1.6.12.33)6 d ago
Simply Schedule Appointments
50,000+ installs
Broken access control
CVE-2026-92245
High 7.5Up to 1.6.12.32Fixed in a later version (latest 1.6.12.33)6 d ago
Newsletter - Send awesome emails from WordPress
200,000+ installs
Security weakness
CVE-2026-92537
Medium 5.3Up to 9.3.9Fixed in a later version (latest 9.4.6)6 d ago

How to triage new WordPress vulnerabilities

Start with relevance, not the headline severity alone. Check whether the affected plugin, theme or WordPress core version is actually installed on your site, then compare your installed version with the vulnerable range in the record.

Among relevant disclosures, unauthenticated vulnerabilities usually deserve faster attention because an attacker may not need a valid account. High and critical severity issues also merit prompt review, especially where the affected component is public facing. CVSS is useful for severity, but it is not a complete measure of your site's risk, so read the access conditions and affected versions as well.

If a fixed version exists, take a current backup and update promptly. If there is no fix, decide whether the component can be disabled, removed or replaced until a safe release is available. On an important production site, test disruptive changes on staging where possible.

After patching, do not treat the update itself as proof that nothing happened beforehand. If the issue was serious or had been public for some time, review administrator accounts, unexpected file changes, redirects, new pages and security logs. For broader maintenance advice, see our WordPress maintenance guidance.

Sources and further reading

Common questions

Answers to the questions we hear most about this.

How recent are the vulnerabilities on this page?

The table shows WordPress vulnerability records published in the last 7 days, with the newest records first.

Which new WordPress vulnerabilities should I act on first?

Prioritise vulnerabilities that affect software you actually run. Give particular attention to unauthenticated issues, high or critical severity records and disclosures where a fixed version is already available.

What if a vulnerability has no fix yet?

Consider disabling, removing or replacing the affected component until a safe version is available, while accounting for any business function the plugin or theme provides.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support