7,168 new vulnerabilities

WordPress Vulnerability
Database

10,391 known vulnerabilities across plugins, themes and core. Updated daily from multiple sources.

10,391
Total vulns
669
Critical
2,510
High
5,348
Medium
448
Low
10,179
Plugins
170
Themes
42
Core
25
Closed plugins
10,391 results
Severity Title Type Slug CVE Fixed in Published
MEDIUM
CVSS 6.5
WordPress Delete All Comments of wordpress plugin <= 7.1 - Broken Access Control vulnerab…
plugin delete-all-comments-of-wordpress CVE-2026-105059 — Oct 6, 2026
HIGH
CVSS 7.5
WordPress SafeSnap – Verified WordPress Backup & Restore plugin <= 2.1.2 - Sensitive Data…
plugin safesnap-verified-wordpress-backup-amp-restore CVE-2026-41559 — Oct 6, 2026
CRITICAL
CVSS 9.3
WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <=…
theme newsletter-subscription-form-user-subscriptions-form-capture-email CVE-2026-41555 — Oct 6, 2026
HIGH
CVSS 7.5
WordPress Advanced Posts Listing – Show Post List Easily plugin <= 1.0.8 - Broken Access …
plugin advanced-posts-listing-show-post-list-easily CVE-2026-39796 — Oct 6, 2026
HIGH
CVSS 8.8
WordPress JobZilla - Job Board WordPress Theme theme <= 2.2 - Privilege Escalation vulner…
theme jobzilla-job-board-wordpress-theme CVE-2026-39775 — Oct 6, 2026
HIGH
CVSS 7.7
WordPress Jobs for WordPress plugin <= 2.8.2 - Arbitrary File Deletion vulnerability
plugin jobs-for-wordpress CVE-2026-39752 — Oct 6, 2026
CRITICAL
CVSS 10.0
WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnera…
plugin kognetiks-chatbot-for-wordpress CVE-2026-32579 — Oct 6, 2026
HIGH
CVSS 8.8
CVE-2026-39775 — Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme …
theme CVE-2026-39775 — Oct 6, 2026
MEDIUM
CVSS 6.5
EUVD-2026-93085 (CVE-2026-105059) — Subscriber Broken Access Control in Delete All Commen…
plugin CVE-2026-105059 — Oct 6, 2026
HIGH
CVSS 7.5
EUVD-2026-93046 (CVE-2026-41559) — Unauthenticated Sensitive Data Exposure in SafeSnap – …
plugin CVE-2026-41559 — Oct 6, 2026
CRITICAL
CVSS 9.3
EUVD-2026-93045 (CVE-2026-41555) — Unauthenticated SQL Injection in Newsletter Subscripti…
plugin CVE-2026-41555 — Oct 6, 2026
HIGH
CVSS 7.5
EUVD-2026-93040 (CVE-2026-39796) — Unauthenticated Broken Access Control in Advanced Post…
plugin CVE-2026-39796 — Oct 6, 2026
HIGH
CVSS 8.8
EUVD-2026-93025 (CVE-2026-39775) — Subscriber Privilege Escalation in JobZilla - Job Boar…
plugin CVE-2026-39775 — Oct 6, 2026
HIGH
CVSS 7.7
EUVD-2026-93261 (CVE-2026-39752) — Contributor Arbitrary File Deletion in Jobs for WordPr…
plugin CVE-2026-39752 — Oct 6, 2026
CRITICAL
CVSS 10.0
EUVD-2026-93240 (CVE-2026-32579) — Unauthenticated Arbitrary File Upload in Kognetiks Cha…
plugin CVE-2026-32579 — Oct 6, 2026
UNKNOWN
File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat
plugin file-media-renamer CVE-2026-94278 — Oct 6, 2026
UNKNOWN
Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update …
plugin fast-courier CVE-2026-89289 — Oct 6, 2026
UNKNOWN
Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_im…
plugin slider-pro CVE-2026-86786 — Oct 6, 2026
UNKNOWN
elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Ca…
plugin elegro-crypto-payment CVE-2026-94299 — Oct 6, 2026
UNKNOWN
Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverif…
plugin deema-payment-gateway CVE-2026-94271 — Oct 6, 2026
UNKNOWN
Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation vi…
plugin deema-payment-gateway CVE-2026-94270 — Oct 6, 2026
UNKNOWN
CVE-2026-94299 — The elegro Crypto Payment WordPress plugin through 1.0.1 does not requir…
plugin CVE-2026-94299 — Oct 6, 2026
UNKNOWN
CVE-2026-94278 — The File Media Renamer WordPress plugin through 1.3 does not verify that…
plugin CVE-2026-94278 — Oct 6, 2026
UNKNOWN
CVE-2026-94271 — The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify…
plugin CVE-2026-94271 — Oct 6, 2026
UNKNOWN
CVE-2026-94270 — The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify…
plugin CVE-2026-94270 — Oct 6, 2026
UNKNOWN
CVE-2026-89289 — The Fast Courier WordPress plugin through 5.2.3 does not restrict an un…
plugin CVE-2026-89289 — Oct 6, 2026
UNKNOWN
CVE-2026-86786 — The Slider Pro WordPress plugin through 1.0.0 does not perform any capab…
plugin CVE-2026-86786 — Oct 6, 2026
HIGH
CVSS 8.8
EUVD-2026-92986 (CVE-2026-105701) — The ACPT (Premium) plugin for WordPress is vulnerable…
plugin CVE-2026-105701 — Oct 6, 2026
UNKNOWN
CVSS 0.0
EUVD-2026-92967 (CVE-2026-89289) — The Fast Courier WordPress plugin through 5.2.3 does …
plugin CVE-2026-89289 — Oct 6, 2026
UNKNOWN
CVSS 0.0
EUVD-2026-92968 (CVE-2026-94278) — The File Media Renamer WordPress plugin through 1.3 do…
plugin CVE-2026-94278 — Oct 6, 2026
UNKNOWN
CVSS 0.0
EUVD-2026-92969 (CVE-2026-86786) — The Slider Pro WordPress plugin through 1.0.0 does not…
plugin CVE-2026-86786 — Oct 6, 2026
UNKNOWN
CVSS 0.0
EUVD-2026-92964 (CVE-2026-94270) — The Deema Payment Gateway WordPress plugin through 1.1…
plugin CVE-2026-94270 — Oct 6, 2026
UNKNOWN
CVSS 0.0
EUVD-2026-92965 (CVE-2026-94271) — The Deema Payment Gateway WordPress plugin through 1.1…
plugin CVE-2026-94271 — Oct 6, 2026
UNKNOWN
CVSS 0.0
EUVD-2026-92966 (CVE-2026-94299) — The elegro Crypto Payment WordPress plugin through 1.0…
plugin CVE-2026-94299 — Oct 6, 2026
HIGH
CVSS 7.2
EUVD-2026-92961 (CVE-2026-75962) — The Post SMTP – Complete Email Deliverability and SMTP…
plugin CVE-2026-75962 — Oct 6, 2026
MEDIUM
CVSS 6.9
WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Direct Object R…
theme ai-chatbot-for-wordpress-hyve-lite CVE-2026-97305 — Oct 5, 2026
MEDIUM
CVSS 6.9
EUVD-2026-92586 (CVE-2026-97305) — Authorization Bypass Through User-Controlled Key vulne…
plugin CVE-2026-97305 — Oct 5, 2026
MEDIUM
CVSS 5.1
EUVD-2026-92444 (CVE-2026-105397) — LearnPress plugin for WordPress through 4.4.9.1 conta…
plugin CVE-2026-105397 — Oct 5, 2026
MEDIUM
CVSS 5.3
UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery
plugin upi-qr-code-payment-gateway CVE-2026-84169 — Oct 5, 2026
MEDIUM
CVSS 5.9
File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File…
plugin file-uploads-addon-for-woocommerce CVE-2026-78371 v1.7.6 Oct 5, 2026
MEDIUM
CVSS 5.9
File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access
plugin file-uploads-addon-for-woocommerce CVE-2026-13607 — Oct 5, 2026
MEDIUM
CVSS 5.3
CVE-2026-84169 — The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not …
plugin CVE-2026-84169 — Oct 5, 2026
MEDIUM
CVSS 5.9
CVE-2026-78371 — The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 doe…
plugin CVE-2026-78371 — Oct 5, 2026
MEDIUM
CVSS 5.9
CVE-2026-13607 — The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 st…
plugin CVE-2026-13607 — Oct 5, 2026
MEDIUM
CVSS 5.3
EUVD-2026-92260 (CVE-2026-84169) — The UPI QR Code Payment Gateway WordPress plugin throu…
plugin CVE-2026-84169 — Oct 5, 2026
MEDIUM
CVSS 5.9
EUVD-2026-92261 (CVE-2026-13607) — The File Uploads Addon for WooCommerce WordPress plugi…
plugin CVE-2026-13607 — Oct 5, 2026
MEDIUM
CVSS 5.9
EUVD-2026-92262 (CVE-2026-78371) — The File Uploads Addon for WooCommerce WordPress plugi…
plugin CVE-2026-78371 — Oct 5, 2026
MEDIUM
CVSS 5.3
User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrit…
plugin user-private-files CVE-2026-97332 v2.2.0 Oct 4, 2026
HIGH
CVSS 8.8
CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass
plugin cocart CVE-2026-93549 v4.9.7 Oct 4, 2026
MEDIUM
CVSS 4.9
Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure…
plugin five-star-business-profile-and-schema CVE-2026-86817 v2.4.0 Oct 4, 2026