WordPress plugins
3,841 CVEs tracked. 2 of them are in CISA KEV.
This hub aggregates every CVE we track for WordPress plugins, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
WordPress plugins CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 62 |
| 2024-11 | 79 |
| 2024-12 | 63 |
| 2025-01 | 123 |
| 2025-02 | 64 |
| 2025-03 | 69 |
| 2025-04 | 74 |
| 2025-05 | 79 |
| 2025-06 | 60 |
| 2025-07 | 43 |
| 2025-08 | 54 |
| 2025-09 | 75 |
| 2025-10 | 65 |
| 2025-11 | 53 |
| 2025-12 | 196 |
| 2026-01 | 114 |
| 2026-02 | 79 |
| 2026-03 | 172 |
| 2026-04 | 49 |
| 2026-05 | 70 |
| 2026-06 | 74 |
| 2026-07 | 68 |
| 2026-08 | 61 |
| 2026-09 | 41 |
Severity
How the 3,841 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical271
- High1,080
- Medium2,403
- Low72
Latest CVEs
The 15 most recently published vulnerabilities affecting WordPress plugins.
- CVE-2026-89406Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters7.5
- CVE-2026-92713Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter8.1
- CVE-2026-95529WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability7.1
- CVE-2026-95525WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability6.5
- CVE-2026-95524WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability5.3
- CVE-2026-95523WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability6.5
- CVE-2026-94500WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-94168WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-94118WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2026-93527WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability8.5
- CVE-2026-92235WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter8.1
- CVE-2026-85658Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)8.1
- CVE-2026-92229Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter9.1
- CVE-2026-77820WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute6.4
- CVE-2026-92622Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute6.4
Product grouping is registry-driven, with AI assist and human review. How it works