Wordpress-plugins
This hub aggregates every CVE we track for Wordpress-plugins, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
1,037
CVEs tracked
61
Critical
162
High
0
In CISA KEV
Severity distribution
MEDIUM802HIGH162CRITICAL61LOW12
Monthly trend
20
22
17
28
28
21
24
22
16
18
22
13
15
9
42
8
8
22
15
14
30
19
18
7
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Wordpress-plugins.
- CVE-2026-8118Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source6.5
- CVE-2026-11357Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization4.3
- CVE-2026-39595WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability4.7
- CVE-2026-12360JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load More AJAX Endpoint7.5
- CVE-2026-41556WordPress ProfilePress plugin <= 4.16.13 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-7665Essential Addons for Elementor <= 6.6.4 - Missing Authorization to Unauthenticated Information Exposure via 'load_more' AJAX Handler5.3
- CVE-2026-10586Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery7.2
- CVE-2026-7651User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter5.3
- CVE-2026-48968WordPress Master Slider plugin <= 3.10.8 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-42774WordPress JetEngine plugin <= 3.8.8.1 - SQL Injection vulnerability9.3
- CVE-2026-6145User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter5.3
- CVE-2026-6504Royal Addons for Elementor <= 1.7.1058 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Parameter6.4
- CVE-2026-5193Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.5.13 - Authenticated (Author+) Limited Privilege Escalation via register_user6.5
- CVE-2026-6214Forminator Forms <= 1.53.0 - Missing Authorization to Authenticated (Subscriber+) Scheduled Form Submission Export via forminator_export_entries Action on wp_loaded Hook6.5
- CVE-2026-6222Forminator Forms <= 1.51.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'forminator_action' Parameter5.3
Product normalization is registry-driven with AI assist and human review. How it works