7,168 new vulnerabilities
WordPress Vulnerability
Database
10,391 known vulnerabilities across plugins, themes and core. Updated daily from multiple sources.
10,391
Total vulns
669
Critical
2,510
High
5,348
Medium
448
Low
10,179
Plugins
170
Themes
42
Core
25
Closed plugins
| Severity | Title | Type | Slug | CVE | Fixed in | Published |
|---|---|---|---|---|---|---|
| MEDIUM CVSS 6.5 |
WordPress Delete All Comments of wordpress plugin <= 7.1 - Broken Access Control vulnerab… |
plugin | delete-all-comments-of-wordpress |
CVE-2026-105059 | — | Oct 6, 2026 |
| HIGH CVSS 7.5 |
WordPress SafeSnap – Verified WordPress Backup & Restore plugin <= 2.1.2 - Sensitive Data… |
plugin | safesnap-verified-wordpress-backup-amp-restore |
CVE-2026-41559 | — | Oct 6, 2026 |
| CRITICAL CVSS 9.3 |
WordPress Newsletter Subscription Form – User Subscriptions Form, Capture Email plugin <=… |
theme | newsletter-subscription-form-user-subscriptions-form-capture-email |
CVE-2026-41555 | — | Oct 6, 2026 |
| HIGH CVSS 7.5 |
WordPress Advanced Posts Listing – Show Post List Easily plugin <= 1.0.8 - Broken Access … |
plugin | advanced-posts-listing-show-post-list-easily |
CVE-2026-39796 | — | Oct 6, 2026 |
| HIGH CVSS 8.8 |
WordPress JobZilla - Job Board WordPress Theme theme <= 2.2 - Privilege Escalation vulner… |
theme | jobzilla-job-board-wordpress-theme |
CVE-2026-39775 | — | Oct 6, 2026 |
| HIGH CVSS 7.7 |
WordPress Jobs for WordPress plugin <= 2.8.2 - Arbitrary File Deletion vulnerability |
plugin | jobs-for-wordpress |
CVE-2026-39752 | — | Oct 6, 2026 |
| CRITICAL CVSS 10.0 |
WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnera… |
plugin | kognetiks-chatbot-for-wordpress |
CVE-2026-32579 | — | Oct 6, 2026 |
| HIGH CVSS 8.8 |
CVE-2026-39775 — Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme … |
theme | |
CVE-2026-39775 | — | Oct 6, 2026 |
| MEDIUM CVSS 6.5 |
EUVD-2026-93085 (CVE-2026-105059) — Subscriber Broken Access Control in Delete All Commen… |
plugin | |
CVE-2026-105059 | — | Oct 6, 2026 |
| HIGH CVSS 7.5 |
EUVD-2026-93046 (CVE-2026-41559) — Unauthenticated Sensitive Data Exposure in SafeSnap – … |
plugin | |
CVE-2026-41559 | — | Oct 6, 2026 |
| CRITICAL CVSS 9.3 |
EUVD-2026-93045 (CVE-2026-41555) — Unauthenticated SQL Injection in Newsletter Subscripti… |
plugin | |
CVE-2026-41555 | — | Oct 6, 2026 |
| HIGH CVSS 7.5 |
EUVD-2026-93040 (CVE-2026-39796) — Unauthenticated Broken Access Control in Advanced Post… |
plugin | |
CVE-2026-39796 | — | Oct 6, 2026 |
| HIGH CVSS 8.8 |
EUVD-2026-93025 (CVE-2026-39775) — Subscriber Privilege Escalation in JobZilla - Job Boar… |
plugin | |
CVE-2026-39775 | — | Oct 6, 2026 |
| HIGH CVSS 7.7 |
EUVD-2026-93261 (CVE-2026-39752) — Contributor Arbitrary File Deletion in Jobs for WordPr… |
plugin | |
CVE-2026-39752 | — | Oct 6, 2026 |
| CRITICAL CVSS 10.0 |
EUVD-2026-93240 (CVE-2026-32579) — Unauthenticated Arbitrary File Upload in Kognetiks Cha… |
plugin | |
CVE-2026-32579 | — | Oct 6, 2026 |
| UNKNOWN | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat |
plugin | file-media-renamer |
CVE-2026-94278 | — | Oct 6, 2026 |
| UNKNOWN | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update … |
plugin | fast-courier |
CVE-2026-89289 | — | Oct 6, 2026 |
| UNKNOWN | Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_im… |
plugin | slider-pro |
CVE-2026-86786 | — | Oct 6, 2026 |
| UNKNOWN | elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Ca… |
plugin | elegro-crypto-payment |
CVE-2026-94299 | — | Oct 6, 2026 |
| UNKNOWN | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverif… |
plugin | deema-payment-gateway |
CVE-2026-94271 | — | Oct 6, 2026 |
| UNKNOWN | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation vi… |
plugin | deema-payment-gateway |
CVE-2026-94270 | — | Oct 6, 2026 |
| UNKNOWN | CVE-2026-94299 — The elegro Crypto Payment WordPress plugin through 1.0.1 does not requir… |
plugin | |
CVE-2026-94299 | — | Oct 6, 2026 |
| UNKNOWN | CVE-2026-94278 — The File Media Renamer WordPress plugin through 1.3 does not verify that… |
plugin | |
CVE-2026-94278 | — | Oct 6, 2026 |
| UNKNOWN | CVE-2026-94271 — The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify… |
plugin | |
CVE-2026-94271 | — | Oct 6, 2026 |
| UNKNOWN | CVE-2026-94270 — The Deema Payment Gateway WordPress plugin through 1.1.2 does not verify… |
plugin | |
CVE-2026-94270 | — | Oct 6, 2026 |
| UNKNOWN | CVE-2026-89289 — The Fast Courier WordPress plugin through 5.2.3 does not restrict an un… |
plugin | |
CVE-2026-89289 | — | Oct 6, 2026 |
| UNKNOWN | CVE-2026-86786 — The Slider Pro WordPress plugin through 1.0.0 does not perform any capab… |
plugin | |
CVE-2026-86786 | — | Oct 6, 2026 |
| HIGH CVSS 8.8 |
EUVD-2026-92986 (CVE-2026-105701) — The ACPT (Premium) plugin for WordPress is vulnerable… |
plugin | |
CVE-2026-105701 | — | Oct 6, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-92967 (CVE-2026-89289) — The Fast Courier WordPress plugin through 5.2.3 does … |
plugin | |
CVE-2026-89289 | — | Oct 6, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-92968 (CVE-2026-94278) — The File Media Renamer WordPress plugin through 1.3 do… |
plugin | |
CVE-2026-94278 | — | Oct 6, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-92969 (CVE-2026-86786) — The Slider Pro WordPress plugin through 1.0.0 does not… |
plugin | |
CVE-2026-86786 | — | Oct 6, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-92964 (CVE-2026-94270) — The Deema Payment Gateway WordPress plugin through 1.1… |
plugin | |
CVE-2026-94270 | — | Oct 6, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-92965 (CVE-2026-94271) — The Deema Payment Gateway WordPress plugin through 1.1… |
plugin | |
CVE-2026-94271 | — | Oct 6, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-92966 (CVE-2026-94299) — The elegro Crypto Payment WordPress plugin through 1.0… |
plugin | |
CVE-2026-94299 | — | Oct 6, 2026 |
| HIGH CVSS 7.2 |
EUVD-2026-92961 (CVE-2026-75962) — The Post SMTP – Complete Email Deliverability and SMTP… |
plugin | |
CVE-2026-75962 | — | Oct 6, 2026 |
| MEDIUM CVSS 6.9 |
WordPress AI Chatbot for WordPress – Hyve Lite plugin <= 2.0.2 - Insecure Direct Object R… |
theme | ai-chatbot-for-wordpress-hyve-lite |
CVE-2026-97305 | — | Oct 5, 2026 |
| MEDIUM CVSS 6.9 |
EUVD-2026-92586 (CVE-2026-97305) — Authorization Bypass Through User-Controlled Key vulne… |
plugin | |
CVE-2026-97305 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.1 |
EUVD-2026-92444 (CVE-2026-105397) — LearnPress plugin for WordPress through 4.4.9.1 conta… |
plugin | |
CVE-2026-105397 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.3 |
UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery |
plugin | upi-qr-code-payment-gateway |
CVE-2026-84169 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File… |
plugin | file-uploads-addon-for-woocommerce |
CVE-2026-78371 | v1.7.6 | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access |
plugin | file-uploads-addon-for-woocommerce |
CVE-2026-13607 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.3 |
CVE-2026-84169 — The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not … |
plugin | |
CVE-2026-84169 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
CVE-2026-78371 — The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 doe… |
plugin | |
CVE-2026-78371 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
CVE-2026-13607 — The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 st… |
plugin | |
CVE-2026-13607 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.3 |
EUVD-2026-92260 (CVE-2026-84169) — The UPI QR Code Payment Gateway WordPress plugin throu… |
plugin | |
CVE-2026-84169 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
EUVD-2026-92261 (CVE-2026-13607) — The File Uploads Addon for WooCommerce WordPress plugi… |
plugin | |
CVE-2026-13607 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
EUVD-2026-92262 (CVE-2026-78371) — The File Uploads Addon for WooCommerce WordPress plugi… |
plugin | |
CVE-2026-78371 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.3 |
User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrit… |
plugin | user-private-files |
CVE-2026-97332 | v2.2.0 | Oct 4, 2026 |
| HIGH CVSS 8.8 |
CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass |
plugin | cocart |
CVE-2026-93549 | v4.9.7 | Oct 4, 2026 |
| MEDIUM CVSS 4.9 |
Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure… |
plugin | five-star-business-profile-and-schema |
CVE-2026-86817 | v2.4.0 | Oct 4, 2026 |
…