CVE Database

WordPress CVEs.All of them.

Every known security vulnerability in WordPress plugins and themes, indexed, searchable, and scored. Updated continuously from the Wordfence Intelligence feed.

142
Critical
891
High
3,204
Medium
1,102
Low
12,000+
CVEs indexed
60,000+
Plugins monitored
11,000+
Themes monitored
Continuous
Updates
Severity:
Live Database

34,482 vulnerabilities indexed

wp-cve-database — live query
CVE IDTitleSeverity
CVE-2026-2233User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.2.8 - Missing Authorization to Unauthenticated Arbitrary Post Modification via 'post_id' Parameter

Missing Authorization

medium
CVE-2026-1947NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_set_entry_update_id

Authorization Bypass Through User-Controlled Key

high
CVE-2026-1883Wicked Folders <= 4.1.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Folder Deletion

Authorization Bypass Through User-Controlled Key

medium
CVE-2026-1870Thim Kit for Elementor <= 1.3.7 - Missing Authorization to Unauthenticated Private Course Disclosure

Missing Authorization

medium
CVE-2026-1948NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.1.9 - Missing Authorization to Authenticated (Subscriber+) License Deactivation via deactivate_license

Missing Authorization

medium
CVE-2026-4063Social Icons Widget & Block <= 4.5.8 - Missing Authorization to Authenticated (Subscriber+) Sharing Configuration Creation

Missing Authorization

medium
CVE-2026-3986Calculated Fields Form <= 5.4.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Form Settings

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

medium
CVE-2026-2257GetGenie <= 4.3.2 - Insecure Direct Object Reference to Authenticated (Author+) Stored Cross-Site Scripting via REST API

Authorization Bypass Through User-Controlled Key

medium
CVE-2026-2879GetGenie <= 4.3.2 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Post Overwrite/Deletion

Authorization Bypass Through User-Controlled Key

medium
CVE-2026-2888Formidable Forms <= 6.28 - Unauthenticated Payment Amount Manipulation via 'item_meta' Parameter

Authorization Bypass Through User-Controlled Key

medium
CVE-2026-2890Formidable Forms <= 6.28 - Missing Authorization to Unauthenticated Payment Integrity Bypass via PaymentIntent Reuse

Missing Authorization

high
CVE-2026-3045Appointment Booking Calendar <= 1.6.9.29 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Settings REST API Endpoint

Missing Authorization

high
CVE-2026-1704Appointment Booking Calendar <= 1.6.9.29 - Insecure Direct Object Reference to Authenticated (Staff+) Sensitive Information Exposure

Authorization Bypass Through User-Controlled Key

medium
CVE-2026-3891Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

Unrestricted Upload of File with Dangerous Type

critical
CVE-2026-2987Simple Ajax Chat <= 20260217 - Unauthenticated Stored Cross-Site Scripting via 'c'

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

medium
CVE-2026-2466DukaPress <= 3.2.4 - Unauthenticated Stored Cross-Site Scripting

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

high
CVE-2026-3657My Sticky Bar <= 2.8.6 - Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

high
CVE-2026-3226LearnPress <= 4.3.2.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Notification Triggering

Missing Authorization

medium
CVE-2026-3231Checkout Field Editor (Checkout Manager) for WooCommerce <= 2.1.7 - Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

high
CVE-2026-3492Gravity Forms <= 2.9.28.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Form Title

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

medium