Wordpress-plugins
This hub aggregates every CVE we track for Wordpress-plugins, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
3,736
CVEs tracked
254
Critical
1,047
High
1
In CISA KEV
Severity distribution
MEDIUM2,363HIGH1,047CRITICAL254LOW72
Monthly trend
46
62
79
63
123
64
69
74
79
60
43
54
75
62
53
196
114
72
172
47
66
74
67
14
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Wordpress-plugins.
- CVE-2026-66708WordPress Total Upkeep plugin <= 1.17.2 - Broken Access Control vulnerability8.2
- CVE-2026-66703WordPress MailOptin plugin <= 1.2.78.0 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-66701WordPress Profile Builder plugin <= 3.16.5 - Broken Access Control vulnerability5.3
- CVE-2026-66695WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability6.5
- CVE-2026-66688WordPress Ultimate Addons for Elementor plugin <= 1.45.2 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-65579WordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerability9.8
- CVE-2026-65502WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability5.3
- CVE-2026-25403WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Broken Access Control vulnerability6.5
- CVE-2026-18325Forminator Forms <= 1.56.1 - Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field7.2
- CVE-2026-18881TableOn <= 1.0.5.1 - Unauthenticated Blind SQL Injection via 'comment_count' Filter Parameter7.5
- CVE-2025-14073WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure5.3
- CVE-2026-16144Kali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field Parameter8.1
- CVE-2026-18062Kadence Blocks <= 3.7.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Identity Block Inner Image Content6.4
- CVE-2026-18435Kadence Blocks <= 3.7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'toggleIcon' Block Attribute6.4
- CVE-2026-5060MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion6.5
Product normalization is registry-driven with AI assist and human review. How it works