6,033 new vulnerabilities
WordPress Vulnerability
Database
9,050 known vulnerabilities across plugins, themes and core. Updated daily from multiple sources.
9,050
Total vulns
620
Critical
2,176
High
4,551
Medium
347
Low
8,864
Plugins
156
Themes
30
Core
25
Closed plugins
| Severity | Title | Type | Slug | CVE | Fixed in | Published |
|---|---|---|---|---|---|---|
| UNKNOWN | TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption |
plugin | tiktok |
CVE-2026-92965 | v1.4.2 | Sep 20, 2026 |
| UNKNOWN | Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Admin… |
plugin | import-and-export-users-and-customers |
CVE-2026-92541 | v2.5.2 | Sep 20, 2026 |
| UNKNOWN | Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Admin… |
plugin | import-and-export-users-and-customers |
CVE-2026-92540 | v2.5.2 | Sep 20, 2026 |
| UNKNOWN | Meow Gallery < 5.5.5 - Author+ Draft and Private Post Disclosure via fetch_posts |
plugin | meow-gallery |
CVE-2026-92423 | v5.5.5 | Sep 20, 2026 |
| UNKNOWN | Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_col… |
plugin | meow-gallery |
CVE-2026-92422 | v5.5.5 | Sep 20, 2026 |
| UNKNOWN | Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF |
plugin | sign-up-sheets |
CVE-2026-92410 | v2.4.0 | Sep 20, 2026 |
| UNKNOWN | Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering |
plugin | tripzzy |
CVE-2026-87840 | v1.5.1 | Sep 20, 2026 |
| UNKNOWN | Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion |
plugin | tripzzy |
CVE-2026-87839 | v1.5.1 | Sep 20, 2026 |
| UNKNOWN | Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import |
plugin | forminator-forms |
CVE-2026-87068 | v1.57.2.1 | Sep 20, 2026 |
| UNKNOWN | Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection |
plugin | forminator-forms |
CVE-2026-87067 | v1.57.2.1 | Sep 20, 2026 |
| UNKNOWN | Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection |
plugin | unlimited-elements-for-elementor |
CVE-2026-85017 | v2.0.20 | Sep 20, 2026 |
| UNKNOWN | Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload |
plugin | kirki |
CVE-2026-84223 | v6.3.1 | Sep 20, 2026 |
| UNKNOWN | SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching |
plugin | saml-single-sign-on |
CVE-2026-82842 | v6.0.0 | Sep 20, 2026 |
| UNKNOWN | NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update |
theme | photo-gallery-sliders-proofing-and-themes |
CVE-2026-81654 | v4.5.0 | Sep 20, 2026 |
| UNKNOWN | NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR |
theme | photo-gallery-sliders-proofing-and-themes |
CVE-2026-81653 | v4.5.0 | Sep 20, 2026 |
| UNKNOWN | NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR |
theme | photo-gallery-sliders-proofing-and-themes |
CVE-2026-81652 | v4.5.0 | Sep 20, 2026 |
| UNKNOWN | NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR |
theme | photo-gallery-sliders-proofing-and-themes |
CVE-2026-81651 | v4.5.0 | Sep 20, 2026 |
| UNKNOWN | NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import |
theme | photo-gallery-sliders-proofing-and-themes |
CVE-2026-81650 | v4.5.0 | Sep 20, 2026 |
| UNKNOWN | Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar |
plugin | import-and-export-users-and-customers |
CVE-2026-16542 | v2.4.5 | Sep 20, 2026 |
| UNKNOWN | Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes |
plugin | master-slider |
CVE-2026-14844 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83674 (CVE-2026-92410) — The Sign-up Sheets WordPress plugin before 2.4.0 does … |
plugin | |
CVE-2026-92410 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83675 (CVE-2026-92422) — The Meow Gallery WordPress plugin before 5.5.5 does no… |
plugin | |
CVE-2026-92422 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83676 (CVE-2026-92423) — The Meow Gallery WordPress plugin before 5.5.5 does no… |
plugin | |
CVE-2026-92423 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83677 (CVE-2026-92540) — The Import and export users and customers WordPress pl… |
plugin | |
CVE-2026-92540 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83678 (CVE-2026-92541) — The Import and export users and customers WordPress pl… |
plugin | |
CVE-2026-92541 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83679 (CVE-2026-92965) — The TikTok WordPress plugin before 1.4.2 does not chec… |
plugin | |
CVE-2026-92965 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83670 (CVE-2026-87067) — The Forminator Forms WordPress plugin before 1.57.2.1… |
plugin | |
CVE-2026-87067 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83671 (CVE-2026-87068) — The Forminator Forms WordPress plugin before 1.57.2.1… |
plugin | |
CVE-2026-87068 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83672 (CVE-2026-87839) — The Tripzzy WordPress plugin before 1.5.1 does not ha… |
plugin | |
CVE-2026-87839 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83673 (CVE-2026-87840) — The Tripzzy WordPress plugin before 1.5.1 does not pe… |
plugin | |
CVE-2026-87840 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83665 (CVE-2026-81653) — The Photo Gallery, Sliders, Proofing and WordPress p… |
plugin | |
CVE-2026-81653 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83666 (CVE-2026-81654) — The Photo Gallery, Sliders, Proofing and WordPress p… |
plugin | |
CVE-2026-81654 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83667 (CVE-2026-82842) — The SAML Single Sign On WordPress plugin before 6.0.0… |
plugin | |
CVE-2026-82842 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83668 (CVE-2026-84223) — The Kirki WordPress plugin before 6.3.1 does not sani… |
plugin | |
CVE-2026-84223 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83669 (CVE-2026-85017) — The Unlimited Elements For Elementor WordPress plugin … |
plugin | |
CVE-2026-85017 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83660 (CVE-2026-14844) — The Master Slider WordPress plugin through 3.11.2 doe… |
plugin | |
CVE-2026-14844 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83661 (CVE-2026-16542) — The Import and export users and customers WordPress pl… |
plugin | |
CVE-2026-16542 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83662 (CVE-2026-81650) — The Photo Gallery, Sliders, Proofing and WordPress p… |
plugin | |
CVE-2026-81650 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83663 (CVE-2026-81651) — The Photo Gallery, Sliders, Proofing and WordPress p… |
plugin | |
CVE-2026-81651 | — | Sep 20, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-83664 (CVE-2026-81652) — The Photo Gallery, Sliders, Proofing and WordPress p… |
plugin | |
CVE-2026-81652 | — | Sep 20, 2026 |
| MEDIUM CVSS 6.4 |
YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Missing Authorization to Authentic… |
plugin | ys-leadgen-popup-builder-popup-maker-form-builder-for-wordpress-lead-generation-email-marketing-sales-conversions-opt-ins-subscribers |
CVE-2026-1256 | — | Sep 19, 2026 |
| MEDIUM CVSS 5.3 |
WordLift <= 3.54.10 - Unauthenticated Sensitive Information Exposure in JSON-LD REST API … |
plugin | wordlift-ai-powered-seo-schema |
CVE-2026-9289 | — | Sep 19, 2026 |
| HIGH CVSS 7.5 |
YS LeadGen – Popups, Opt-ins & Lead Capture <= 2.1.4 - Unauthenticated Information Disclo… |
plugin | ys-leadgen-popup-builder-popup-maker-form-builder-for-wordpress-lead-generation-email-marketing-sales-conversions-opt-ins-subscribers |
CVE-2026-1255 | — | Sep 19, 2026 |
| MEDIUM CVSS 6.1 |
MC4WP: Mailchimp for WordPress <= 4.14.0 - Reflected Cross-Site Scripting via 'data' Dyna… |
plugin | mc4wp-mailchimp-for-wordpress |
CVE-2026-87917 | — | Sep 19, 2026 |
| HIGH CVSS 8.8 |
The Welcomizer <= 2.8.1 - Missing Authorization to Authenticated (Subscriber+) Remote Cod… |
plugin | the-welcomizer |
CVE-2026-4327 | — | Sep 19, 2026 |
| MEDIUM CVSS 4.3 |
Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Whitela… |
plugin | search-atlas-seo-otto-ai-seo-automation-for-wordpress |
CVE-2026-15946 | — | Sep 19, 2026 |
| MEDIUM CVSS 6.4 |
AppMySite <= 3.15.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via save_am… |
plugin | appmysite-wordpress-woocommerce-mobile-app-builder-no-code-android-ios-app-maker |
CVE-2026-13770 | — | Sep 19, 2026 |
| MEDIUM CVSS 4.3 |
Search Atlas SEO <= 2.6.23 - Missing Authorization to Authenticated (Subscriber+) Site-Wi… |
plugin | search-atlas-seo-otto-ai-seo-automation-for-wordpress |
CVE-2026-15947 | — | Sep 19, 2026 |
| MEDIUM CVSS 5.3 |
CVE-2026-9289 — The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable… |
core | |
CVE-2026-9289 | — | Sep 19, 2026 |
| MEDIUM CVSS 4.3 |
EUVD-2026-83570 (CVE-2026-9858) — The Partial Shipment for Woocommerce plugin for WordPre… |
plugin | |
CVE-2026-9858 | — | Sep 19, 2026 |
…