WordPress Vulnerability Database

Search All Vulnerabilities

Tip: You can search by CVE ID, software name or slug, or the researcher name. Expand to read about more advanced search options.

If you want to perform more advanced lookups, you can use keywords to further refine your search.

For example, woocommerce researcher:"chloe chamberland" would search for any vulnerabilities discovered by Chloe Chamberland in software that has WooCommerce in the title.

Keywords are added in keyword:value format. If the value contains spaces, you must enclose it in quotation marks.

You can use the following keywords to add criteria to your search:

title
Searches through the title of each vulnerability for matches.
date
Returns vulnerabilities by publication date. Use YYYY-MM-DD, YYYY-MM or YYYY format.
cvss-rating
Use low, medium, high or critical to limit the search to vulnerabilities with the specified rating.
researcher
Returns vulnerabilities credited to researchers containing the given text.
software
Returns vulnerabilities discovered in software containing the given text.
software-slug
Returns vulnerabilities discovered in software exactly matching the given slug.
software-type
Use plugin, theme or core to limit the search to the specified type of software.
By selecting “Search” you acknowledge that you have read and agree to the Wordfence Intelligence Terms and Conditions.

All Vulnerabilities

9.8
CVE ID Unknown
Apr 17, 2026
Researchers:
Title CVE ID CVSS Researchers Date
Piotnet Forms <= 2.1.40 - Unauthenticated Arbitrary File Upload via Form File Upload CVE-2026-4883 9.8 0xd4rk5id3 May 18, 2026
Contest Gallery Pro <= 29.0.1 - Unauthenticated Privilege Escalation CVE-2026-42680 9.8 daroo May 17, 2026
Receive Notifications After Form Submitting – Form Notify for Any Forms <= 1.1.10 - Unauthenticated Authentication Bypass via LINE OAuth Callback CVE-2026-5229 9.8 Nabil Irawan May 14, 2026
InfusedWoo Pro <= 5.1.2 - Unauthenticated Missing Authorization to Privilege Escalation via 'iwar_save_recipe' CVE-2026-6510 9.8 Osvaldo Noe Gonzalez Del Rio (Os) May 13, 2026
Career Section <= 1.7 - Unauthenticated Arbitrary File Upload CVE-2026-6271 9.8 Paolo Tresso May 13, 2026
Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover CVE-2026-8181 9.8 Chloe Chamberland, Wordfence PRISM May 13, 2026
Custom css-js-php <= 2.0.7 - Unauthenticated Remote Code Execution CVE-2026-6433 9.8 JJOHNNY May 12, 2026
TheCartPress eCommerce Shopping Cart <= 1.5.3.6 - Unauthenticated Privilege Escalation CVE-2021-47932 9.8 spacehen May 10, 2026
GeekyBot <= 1.2.2 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation via 'geekybot_frontendajax' AJAX Action CVE-2026-5294 9.8 kiemtiendinhau May 4, 2026
Mentoring <= 1.2.8 - Unauthenticated Privilege Escalation in mentoring_process_registration CVE-2025-13618 9.8 シルAsuna May 4, 2026
MoreConvert Pro <= 1.9.14 - Authentication Bypass via Waitlist Guest Verification Token Reuse CVE-2026-5722 9.8 Nguyen Ngoc Duc (duc193) May 4, 2026
User Verification by PickPlugins <= 2.0.46 - Unauthenticated Authentication Bypass via OTP Verification REST API Endpoint CVE-2026-7458 9.8 kai63001 May 1, 2026
User Registration Advanced Fields <= 1.6.20 - Unauthenticated Arbitrary File Upload CVE-2026-4882 9.8 0xd4rk5id3 May 1, 2026
Temporary Login <= 1.0.0 - Authentication Bypass to Account Takeover CVE-2026-7567 9.8 TANG Cheuk Hei (siunam) April 30, 2026
Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote CVE-2026-3844 9.8 bashu April 22, 2026
Sendmachine for WordPress <= 1.0.20 - Unauthenticated SMTP Hijack to Privilege Escalation via manage_admin_requests CVE-2026-6235 9.8 Nabil Irawan April 21, 2026
Charity Zone <= 1.1.1 - Authenticated (Subscriber+) Arbitrary File Upload CVE-2026-40749 9.8 Denver Jackson April 20, 2026
Restaurant Zone <= 0.7.8 - Authenticated (Subscriber+) Arbitrary File Upload CVE-2026-40746 9.8 Denver Jackson April 20, 2026
WowShipping Pro 1.0.6 - Injected Backdoor 9.8 April 17, 2026
Riaxe Product Customizer <= 2.1.2 - Missing Authorization to Unauthenticated Arbitrary Options Update to Privilege Escalation via 'install-imprint' AJAX Action CVE-2026-3596 9.8 Kai Aizen April 15, 2026

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation