7,116 new vulnerabilities
WordPress Vulnerability
Database
10,338 known vulnerabilities across plugins, themes and core. Updated daily from multiple sources.
10,338
Total vulns
665
Critical
2,490
High
5,341
Medium
448
Low
10,130
Plugins
166
Themes
42
Core
25
Closed plugins
| Severity | Title | Type | Slug | CVE | Fixed in | Published |
|---|---|---|---|---|---|---|
| MEDIUM CVSS 5.3 |
UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery |
plugin | upi-qr-code-payment-gateway |
CVE-2026-84169 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File… |
plugin | file-uploads-addon-for-woocommerce |
CVE-2026-78371 | v1.7.6 | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access |
plugin | file-uploads-addon-for-woocommerce |
CVE-2026-13607 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.3 |
CVE-2026-84169 — The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not … |
plugin | |
CVE-2026-84169 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
CVE-2026-78371 — The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 doe… |
plugin | |
CVE-2026-78371 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
CVE-2026-13607 — The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 st… |
plugin | |
CVE-2026-13607 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.3 |
EUVD-2026-92260 (CVE-2026-84169) — The UPI QR Code Payment Gateway WordPress plugin throu… |
plugin | |
CVE-2026-84169 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
EUVD-2026-92261 (CVE-2026-13607) — The File Uploads Addon for WooCommerce WordPress plugi… |
plugin | |
CVE-2026-13607 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.9 |
EUVD-2026-92262 (CVE-2026-78371) — The File Uploads Addon for WooCommerce WordPress plugi… |
plugin | |
CVE-2026-78371 | — | Oct 5, 2026 |
| MEDIUM CVSS 5.3 |
User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrit… |
plugin | user-private-files |
CVE-2026-97332 | v2.2.0 | Oct 4, 2026 |
| HIGH CVSS 8.8 |
CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass |
plugin | cocart |
CVE-2026-93549 | v4.9.7 | Oct 4, 2026 |
| MEDIUM CVSS 4.9 |
Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure… |
plugin | five-star-business-profile-and-schema |
CVE-2026-86817 | v2.4.0 | Oct 4, 2026 |
| LOW CVSS 3.5 |
Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials |
plugin | simple-shopping-cart |
CVE-2026-104119 | v5.2.6 | Oct 4, 2026 |
| MEDIUM CVSS 5.3 |
Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR |
plugin | razorpay-for-woocommerce |
CVE-2026-104118 | v4.8.8 | Oct 4, 2026 |
| MEDIUM CVSS 6.8 |
Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field |
plugin | horizontal-scrolling-announcements |
CVE-2026-17005 | — | Oct 4, 2026 |
| MEDIUM CVSS 5.3 |
CVE-2026-97332 — The User Private Files WordPress plugin before 2.2.0 does not properly … |
plugin | |
CVE-2026-97332 | — | Oct 4, 2026 |
| MEDIUM CVSS 4.9 |
CVE-2026-86817 — The Five Star Business Profile and Schema WordPress plugin before 2.4.0 … |
plugin | |
CVE-2026-86817 | — | Oct 4, 2026 |
| HIGH CVSS 8.8 |
CVE-2026-93549 — The CoCart WordPress plugin before 4.9.7 does not scope its REST API au… |
core | |
CVE-2026-93549 | — | Oct 4, 2026 |
| MEDIUM CVSS 6.8 |
CVE-2026-17005 — The Horizontal scrolling announcements WordPress plugin through 2.6 does… |
plugin | |
CVE-2026-17005 | — | Oct 4, 2026 |
| LOW CVSS 3.5 |
CVE-2026-104119 — The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape … |
plugin | |
CVE-2026-104119 | — | Oct 4, 2026 |
| MEDIUM CVSS 5.3 |
CVE-2026-104118 — The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not per… |
plugin | |
CVE-2026-104118 | — | Oct 4, 2026 |
| MEDIUM CVSS 5.3 |
EUVD-2026-92076 (CVE-2026-97332) — The User Private Files WordPress plugin before 2.2.0 … |
plugin | |
CVE-2026-97332 | — | Oct 4, 2026 |
| MEDIUM CVSS 5.3 |
EUVD-2026-92072 (CVE-2026-104118) — The Razorpay for WooCommerce WordPress plugin before … |
plugin | |
CVE-2026-104118 | — | Oct 4, 2026 |
| LOW CVSS 3.5 |
EUVD-2026-92073 (CVE-2026-104119) — The Simple Shopping Cart WordPress plugin before 5.2.… |
plugin | |
CVE-2026-104119 | — | Oct 4, 2026 |
| MEDIUM CVSS 4.9 |
EUVD-2026-92074 (CVE-2026-86817) — The Five Star Business Profile and Schema WordPress pl… |
plugin | |
CVE-2026-86817 | — | Oct 4, 2026 |
| HIGH CVSS 8.8 |
EUVD-2026-92075 (CVE-2026-93549) — The CoCart WordPress plugin before 4.9.7 does not sco… |
plugin | |
CVE-2026-93549 | — | Oct 4, 2026 |
| MEDIUM CVSS 6.8 |
EUVD-2026-92071 (CVE-2026-17005) — The Horizontal scrolling announcements WordPress plugi… |
plugin | |
CVE-2026-17005 | — | Oct 4, 2026 |
| MEDIUM CVSS 4.3 |
Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link… |
plugin | burst-statistics-simple-wordpress-analytics-google-analytics-alternative |
CVE-2026-97343 | — | Oct 3, 2026 |
| LOW CVSS 3.7 |
Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code |
plugin | pie-register |
CVE-2026-96962 | v3.8.4.14 | Oct 3, 2026 |
| MEDIUM CVSS 6.8 |
Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration |
plugin | loco-translate |
CVE-2026-94239 | v2.8.9 | Oct 3, 2026 |
| MEDIUM CVSS 6.8 |
Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter |
plugin | loco-translate |
CVE-2026-94238 | v2.8.9 | Oct 3, 2026 |
| MEDIUM CVSS 6.3 |
Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output… |
plugin | unlimited-elements-for-elementor |
CVE-2026-92923 | v2.0.21 | Oct 3, 2026 |
| MEDIUM CVSS 5.3 |
Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion |
plugin | mailchimp-for-woocommerce |
CVE-2026-92437 | v6.3 | Oct 3, 2026 |
| HIGH CVSS 8.2 |
TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN |
plugin | tillkit |
CVE-2026-91078 | v1.0.5 | Oct 3, 2026 |
| HIGH CVSS 8.6 |
SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'sort_order' Pa… |
plugin | saveto-wishlist-lite |
CVE-2026-89236 | v1.1.5 | Oct 3, 2026 |
| HIGH CVSS 8.8 |
Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content |
plugin | kubio-ai-page-builder |
CVE-2026-88783 | v2.9.3 | Oct 3, 2026 |
| MEDIUM CVSS 6.8 |
Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attrib… |
plugin | kubio-ai-page-builder |
CVE-2026-88782 | v2.9.3 | Oct 3, 2026 |
| LOW CVSS 3.7 |
MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot Forms Integrati… |
plugin | metform |
CVE-2026-86834 | v4.3.1 | Oct 3, 2026 |
| MEDIUM CVSS 5.3 |
MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API |
plugin | metform |
CVE-2026-86832 | v4.3.1 | Oct 3, 2026 |
| MEDIUM CVSS 6.8 |
Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parame… |
plugin | unlimited-elements-for-elementor |
CVE-2026-85568 | v2.0.21 | Oct 3, 2026 |
| MEDIUM CVSS 6.6 |
Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path T… |
plugin | unlimited-elements-for-elementor |
CVE-2026-85015 | v2.0.21 | Oct 3, 2026 |
| LOW CVSS 3.7 |
WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable… |
plugin | wp-ultimate-csv-importer |
CVE-2026-80518 | v9.2 | Oct 3, 2026 |
| LOW CVSS 3.5 |
WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Upload |
plugin | wp-ultimate-csv-importer |
CVE-2026-80517 | v9.2 | Oct 3, 2026 |
| HIGH CVSS 7.5 |
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay |
plugin | wp-2fa |
CVE-2026-103514 | v4.1.0 | Oct 3, 2026 |
| MEDIUM CVSS 6.8 |
MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import |
plugin | mpg |
CVE-2026-103293 | v4.2.3 | Oct 3, 2026 |
| MEDIUM CVSS 6.4 |
WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings |
plugin | wp-ultimate-review |
CVE-2026-101162 | v2.4.4 | Oct 3, 2026 |
| HIGH CVSS 7.5 |
WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings in wp-reviews… |
plugin | wp-ultimate-review |
CVE-2026-101161 | v2.4.4 | Oct 3, 2026 |
| HIGH CVSS 7.5 |
WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating |
plugin | wp-ultimate-review |
CVE-2026-101160 | v2.4.4 | Oct 3, 2026 |
| HIGH CVSS 7.5 |
WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission |
plugin | wp-ultimate-review |
CVE-2026-101159 | v2.4.4 | Oct 3, 2026 |
| CRITICAL CVSS 9.1 |
EUVD-2026-91966 (CVE-2026-92084) — The The Beaver Builder Page Builder – Drag and Drop We… |
plugin | |
CVE-2026-92084 | — | Oct 3, 2026 |
…