7,116 new vulnerabilities

WordPress Vulnerability
Database

10,338 known vulnerabilities across plugins, themes and core. Updated daily from multiple sources.

10,338
Total vulns
665
Critical
2,490
High
5,341
Medium
448
Low
10,130
Plugins
166
Themes
42
Core
25
Closed plugins
10,338 results
Severity Title Type Slug CVE Fixed in Published
MEDIUM
CVSS 5.3
UPI QR Code Payment Gateway <= 1.4.3 - Unauthenticated Cross-Order Payment-Status Forgery
plugin upi-qr-code-payment-gateway CVE-2026-84169 — Oct 5, 2026
MEDIUM
CVSS 5.9
File Uploads Addon for WooCommerce 1.7.2 - 1.7.5 - Unauthenticated Customer Uploaded File…
plugin file-uploads-addon-for-woocommerce CVE-2026-78371 v1.7.6 Oct 5, 2026
MEDIUM
CVSS 5.9
File Uploads Addon for WooCommerce <= 1.7.6 - Unauthenticated Direct File Access
plugin file-uploads-addon-for-woocommerce CVE-2026-13607 — Oct 5, 2026
MEDIUM
CVSS 5.3
CVE-2026-84169 — The UPI QR Code Payment Gateway WordPress plugin through 1.4.3 does not …
plugin CVE-2026-84169 — Oct 5, 2026
MEDIUM
CVSS 5.9
CVE-2026-78371 — The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 doe…
plugin CVE-2026-78371 — Oct 5, 2026
MEDIUM
CVSS 5.9
CVE-2026-13607 — The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 st…
plugin CVE-2026-13607 — Oct 5, 2026
MEDIUM
CVSS 5.3
EUVD-2026-92260 (CVE-2026-84169) — The UPI QR Code Payment Gateway WordPress plugin throu…
plugin CVE-2026-84169 — Oct 5, 2026
MEDIUM
CVSS 5.9
EUVD-2026-92261 (CVE-2026-13607) — The File Uploads Addon for WooCommerce WordPress plugi…
plugin CVE-2026-13607 — Oct 5, 2026
MEDIUM
CVSS 5.9
EUVD-2026-92262 (CVE-2026-78371) — The File Uploads Addon for WooCommerce WordPress plugi…
plugin CVE-2026-78371 — Oct 5, 2026
MEDIUM
CVSS 5.3
User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrit…
plugin user-private-files CVE-2026-97332 v2.2.0 Oct 4, 2026
HIGH
CVSS 8.8
CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass
plugin cocart CVE-2026-93549 v4.9.7 Oct 4, 2026
MEDIUM
CVSS 4.9
Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure…
plugin five-star-business-profile-and-schema CVE-2026-86817 v2.4.0 Oct 4, 2026
LOW
CVSS 3.5
Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials
plugin simple-shopping-cart CVE-2026-104119 v5.2.6 Oct 4, 2026
MEDIUM
CVSS 5.3
Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR
plugin razorpay-for-woocommerce CVE-2026-104118 v4.8.8 Oct 4, 2026
MEDIUM
CVSS 6.8
Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field
plugin horizontal-scrolling-announcements CVE-2026-17005 — Oct 4, 2026
MEDIUM
CVSS 5.3
CVE-2026-97332 — The User Private Files WordPress plugin before 2.2.0 does not properly …
plugin CVE-2026-97332 — Oct 4, 2026
MEDIUM
CVSS 4.9
CVE-2026-86817 — The Five Star Business Profile and Schema WordPress plugin before 2.4.0 …
plugin CVE-2026-86817 — Oct 4, 2026
HIGH
CVSS 8.8
CVE-2026-93549 — The CoCart WordPress plugin before 4.9.7 does not scope its REST API au…
core CVE-2026-93549 — Oct 4, 2026
MEDIUM
CVSS 6.8
CVE-2026-17005 — The Horizontal scrolling announcements WordPress plugin through 2.6 does…
plugin CVE-2026-17005 — Oct 4, 2026
LOW
CVSS 3.5
CVE-2026-104119 — The Simple Shopping Cart WordPress plugin before 5.2.6 does not escape …
plugin CVE-2026-104119 — Oct 4, 2026
MEDIUM
CVSS 5.3
CVE-2026-104118 — The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not per…
plugin CVE-2026-104118 — Oct 4, 2026
MEDIUM
CVSS 5.3
EUVD-2026-92076 (CVE-2026-97332) — The User Private Files WordPress plugin before 2.2.0 …
plugin CVE-2026-97332 — Oct 4, 2026
MEDIUM
CVSS 5.3
EUVD-2026-92072 (CVE-2026-104118) — The Razorpay for WooCommerce WordPress plugin before …
plugin CVE-2026-104118 — Oct 4, 2026
LOW
CVSS 3.5
EUVD-2026-92073 (CVE-2026-104119) — The Simple Shopping Cart WordPress plugin before 5.2.…
plugin CVE-2026-104119 — Oct 4, 2026
MEDIUM
CVSS 4.9
EUVD-2026-92074 (CVE-2026-86817) — The Five Star Business Profile and Schema WordPress pl…
plugin CVE-2026-86817 — Oct 4, 2026
HIGH
CVSS 8.8
EUVD-2026-92075 (CVE-2026-93549) — The CoCart WordPress plugin before 4.9.7 does not sco…
plugin CVE-2026-93549 — Oct 4, 2026
MEDIUM
CVSS 6.8
EUVD-2026-92071 (CVE-2026-17005) — The Horizontal scrolling announcements WordPress plugi…
plugin CVE-2026-17005 — Oct 4, 2026
MEDIUM
CVSS 4.3
Burst Statistics <= 3.7.1 - Improper Authentication to Account Persistence via Share-Link…
plugin burst-statistics-simple-wordpress-analytics-google-analytics-alternative CVE-2026-97343 — Oct 3, 2026
LOW
CVSS 3.7
Pie Register < 3.8.4.14 - Unauthenticated User Email Disclosure via Invitation Code
plugin pie-register CVE-2026-96962 v3.8.4.14 Oct 3, 2026
MEDIUM
CVSS 6.8
Loco Translate < 2.8.9 - Translator+ Stored XSS via Bundle Configuration
plugin loco-translate CVE-2026-94239 v2.8.9 Oct 3, 2026
MEDIUM
CVSS 6.8
Loco Translate < 2.8.9 - Translator+ Limited File Read via 'path' Parameter
plugin loco-translate CVE-2026-94238 v2.8.9 Oct 3, 2026
MEDIUM
CVSS 6.3
Unlimited Elements For Elementor 1.5.142 - 2.0.20 - Subscriber+ SQLi via get_addon_output…
plugin unlimited-elements-for-elementor CVE-2026-92923 v2.0.21 Oct 3, 2026
MEDIUM
CVSS 5.3
Mailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and Deletion
plugin mailchimp-for-woocommerce CVE-2026-92437 v6.3 Oct 3, 2026
HIGH
CVSS 8.2
TillKit < 1.0.5 - Unauthenticated POS Takeover via Hard-Coded Default Manager PIN
plugin tillkit CVE-2026-91078 v1.0.5 Oct 3, 2026
HIGH
CVSS 8.6
SaveTo Wishlist Lite < 1.1.5 - Unauthenticated SQLi via 'sort_column' and 'sort_order' Pa…
plugin saveto-wishlist-lite CVE-2026-89236 v1.1.5 Oct 3, 2026
HIGH
CVSS 8.8
Kubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment Content
plugin kubio-ai-page-builder CVE-2026-88783 v2.9.3 Oct 3, 2026
MEDIUM
CVSS 6.8
Kubio AI Page Builder < 2.9.3 - Contributor+ Stored XSS via Image Gallery Item URL Attrib…
plugin kubio-ai-page-builder CVE-2026-88782 v2.9.3 Oct 3, 2026
LOW
CVSS 3.7
MetForm 2.2.1 - 4.3.0 - Unauthenticated Debug File Disclosure via HubSpot Forms Integrati…
plugin metform CVE-2026-86834 v4.3.1 Oct 3, 2026
MEDIUM
CVSS 5.3
MetForm < 4.3.1 - Unauthenticated Form Entry Data Disclosure via REST API
plugin metform CVE-2026-86832 v4.3.1 Oct 3, 2026
MEDIUM
CVSS 6.8
Unlimited Elements For Elementor 1.5.139 - 2.0.20 - Unauthenticated SQLi via 'ucs' Parame…
plugin unlimited-elements-for-elementor CVE-2026-85568 v2.0.21 Oct 3, 2026
MEDIUM
CVSS 6.6
Unlimited Elements For Elementor < 2.0.21 - Authenticated Arbitrary File Write via Path T…
plugin unlimited-elements-for-elementor CVE-2026-85015 v2.0.21 Oct 3, 2026
LOW
CVSS 3.7
WP Ultimate CSV Importer < 9.2 - Unauthenticated Imported Data Disclosure via Predictable…
plugin wp-ultimate-csv-importer CVE-2026-80518 v9.2 Oct 3, 2026
LOW
CVSS 3.5
WP Ultimate CSV Importer 7.17 - 9.1 - Admin+ Stored XSS via ZIP Import SVG Upload
plugin wp-ultimate-csv-importer CVE-2026-80517 v9.2 Oct 3, 2026
HIGH
CVSS 7.5
WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code Replay
plugin wp-2fa CVE-2026-103514 v4.1.0 Oct 3, 2026
MEDIUM
CVSS 6.8
MPG < 4.2.3 - Editor+ Arbitrary File Read via Project Import
plugin mpg CVE-2026-103293 v4.2.3 Oct 3, 2026
MEDIUM
CVSS 6.4
WP Ultimate Review < 2.4.4 - Author+ Stored XSS via Review Overview Settings
plugin wp-ultimate-review CVE-2026-101162 v2.4.4 Oct 3, 2026
HIGH
CVSS 7.5
WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Unset Display Settings in wp-reviews…
plugin wp-ultimate-review CVE-2026-101161 v2.4.4 Oct 3, 2026
HIGH
CVSS 7.5
WP Ultimate Review < 2.4.4 - Unauthenticated DoS via Non-Numeric Review Rating
plugin wp-ultimate-review CVE-2026-101160 v2.4.4 Oct 3, 2026
HIGH
CVSS 7.5
WP Ultimate Review < 2.4.4 - Unauthenticated Stored XSS via Review Submission
plugin wp-ultimate-review CVE-2026-101159 v2.4.4 Oct 3, 2026
CRITICAL
CVSS 9.1
EUVD-2026-91966 (CVE-2026-92084) — The The Beaver Builder Page Builder – Drag and Drop We…
plugin CVE-2026-92084 — Oct 3, 2026