WordPress Vulnerabilities

28 advisories affecting WordPress

28

Total CVEs

16

Critical

12

High

CVE-2026-3891

Mar 13, 2026

Critical (9.8)

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' ...

Read Advisory

CVE-2026-2599

Mar 5, 2026

Critical (9.8)

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input ...

Read Advisory

CVE-2025-13673

Feb 28, 2026

High (7.5)

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3.9.6 due to insufficient...

Read Advisory

CVE-2026-2471

Feb 28, 2026

High (7.5)

The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.15.0 via deserialization of untrusted input from the email log message field. Thi...

Read Advisory

CVE-2025-12981

Feb 27, 2026

Critical (9.8)

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user regi...

Read Advisory

CVE-2026-23693

Feb 23, 2026

Critical (10.0)

ElementsKit Lite (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts cl...

Read Advisory

CVE-2025-12882

Feb 19, 2026

Critical (9.8)

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set...

Read Advisory

CVE-2025-13563

Feb 19, 2026

Critical (9.8)

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restri...

Read Advisory

CVE-2025-13851

Feb 19, 2026

Critical (9.8)

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugi...

Read Advisory

CVE-2026-0926

Feb 19, 2026

Critical (9.8)

The Prodigy Commerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.9 via the 'parameters[template_name]' parameter. This makes it possible for un...

Read Advisory

CVE-2026-1405

Feb 19, 2026

Critical (9.8)

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and includ...

Read Advisory

CVE-2026-1994

Feb 19, 2026

Critical (9.8)

The s2Member plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 260127. This is due to the plugin not properly validating a user's id...

Read Advisory

CVE-2026-1937

Feb 18, 2026

Critical (9.8)

The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the `yayma...

Read Advisory

CVE-2025-12062

Feb 17, 2026

High (8.8)

The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8.6 via the ...

Read Advisory

CVE-2026-1216

Feb 17, 2026

High (7.2)

The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in all versions up to, and including, 5.0.10 due to insufficient input sanitization...

Read Advisory

CVE-2026-2592

Feb 17, 2026

High (7.7)

The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to Improper Access Control to Payment Status Update in all versions up to and including 5.0.16. This is due to the payment callb...

Read Advisory

CVE-2026-2001

Feb 16, 2026

High (8.8)

The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'Notice::install_activate_plugin' function in all versions up to, and inc...

Read Advisory

CVE-2026-1490

Feb 15, 2026

Critical (9.8)

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoof...

Read Advisory

CVE-2026-1750

Feb 15, 2026

High (8.8)

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.0.7. This is due to a missing capability check in the...

Read Advisory

CVE-2025-8572

Feb 14, 2026

Critical (9.8)

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user ...

Read Advisory

CVE-2026-1306

Feb 14, 2026

Critical (9.8)

The midi-Synth plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type and file extension validation in the 'export' AJAX action in all versions up to, and including, 1.1...

Read Advisory

CVE-2026-0745

Feb 14, 2026

High (7.2)

The User Language Switch plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.10 due to missing URL validation on the 'download_language()' funct...

Read Advisory

CVE-2026-0753

Feb 14, 2026

High (7.2)

The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' parameter in all versions up to, and including, 1.6.2 due to insufficient input s...

Read Advisory

CVE-2026-1843

Feb 14, 2026

High (7.2)

The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versions up to, and including, 5.2.2 due to insufficient input sanitization and outpu...

Read Advisory

CVE-2026-1988

Feb 14, 2026

High (7.5)

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is ...

Read Advisory

CVE-2026-2024

Feb 14, 2026

High (7.5)

The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied para...

Read Advisory

CVE-2026-1357

Feb 11, 2026

Critical (9.8)

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper...

Read Advisory

CVE-2025-15027

Feb 8, 2026

Critical (9.8)

The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user met...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.