CVE Tools

WordPress plugins

3,841 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for WordPress plugins, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

WordPress plugins CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
WordPress plugins CVEs per month
MonthCVEs
2024-1062
2024-1179
2024-1263
2025-01123
2025-0264
2025-0369
2025-0474
2025-0579
2025-0660
2025-0743
2025-0854
2025-0975
2025-1065
2025-1153
2025-12196
2026-01114
2026-0279
2026-03172
2026-0449
2026-0570
2026-0674
2026-0768
2026-0861
2026-0941

Severity

How the 3,841 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2717%
  • High1,08028%
  • Medium2,40363%
  • Low722%

Latest CVEs

The 15 most recently published vulnerabilities affecting WordPress plugins.

  1. CVE-2026-89406Modula Image Gallery <= 3.0.1 - Missing Authorization to Unauthenticated Private Gallery Image Disclosure via 'modula_gallery_id' and 'modula_image_id' Parameters7.5
  2. CVE-2026-92713Modula Image Gallery <= 3.0.2 - Missing Authorization to Authenticated (Author+) Arbitrary File Deletion (Non-PHP) via 'file' Parameter8.1
  3. CVE-2026-95529WordPress Calculated Fields Form plugin <= 5.5.1.1 - Cross Site Scripting (XSS) vulnerability7.1
  4. CVE-2026-95525WordPress WP User Frontend plugin <= 4.3.11 - Arbitrary File Deletion vulnerability6.5
  5. CVE-2026-95524WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability5.3
  6. CVE-2026-95523WordPress WP User Frontend plugin <= 4.3.11 - Bypass Vulnerability vulnerability6.5
  7. CVE-2026-94500WordPress ElementsKit Elementor addons Lite plugin <= 4.0.5 - Cross Site Scripting (XSS) vulnerability6.5
  8. CVE-2026-94168WordPress Premium Addons for Elementor plugin <= 4.11.105 - Cross Site Scripting (XSS) vulnerability6.5
  9. CVE-2026-94118WordPress Premium Blocks – Gutenberg Blocks for WordPress plugin <= 2.3.17 - Cross Site Scripting (XSS) vulnerability6.5
  10. CVE-2026-93527WordPress Live Copy Paste for Elementor plugin <= 1.5.10 - SQL Injection vulnerability8.5
  11. CVE-2026-92235WP Ultimate Review <= 2.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'xs_submit_review_data[xs_reviw_summery]' Parameter8.1
  12. CVE-2026-85658Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.17.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket)8.1
  13. CVE-2026-92229Forminator Forms <= 1.57.2 - Unauthenticated Arbitrary Shortcode Execution via 'current_url' Parameter9.1
  14. CVE-2026-77820WPComplete <= 2.9.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'empty' Shortcode Attribute6.4
  15. CVE-2026-92622Strong Testimonials <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute6.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store