WordPress Vulnerability Database

Search All Vulnerabilities

Tip: You can search by CVE ID, software name or slug, or the researcher name. Expand to read about more advanced search options.

If you want to perform more advanced lookups, you can use keywords to further refine your search.

For example, woocommerce researcher:"chloe chamberland" would search for any vulnerabilities discovered by Chloe Chamberland in software that has WooCommerce in the title.

Keywords are added in keyword:value format. If the value contains spaces, you must enclose it in quotation marks.

You can use the following keywords to add criteria to your search:

title
Searches through the title of each vulnerability for matches.
date
Returns vulnerabilities by publication date. Use YYYY-MM-DD, YYYY-MM or YYYY format.
cvss-rating
Use low, medium, high or critical to limit the search to vulnerabilities with the specified rating.
researcher
Returns vulnerabilities credited to researchers containing the given text.
software
Returns vulnerabilities discovered in software containing the given text.
software-slug
Returns vulnerabilities discovered in software exactly matching the given slug.
software-type
Use plugin, theme or core to limit the search to the specified type of software.
By selecting “Search” you acknowledge that you have read and agree to the Wordfence Intelligence Terms and Conditions.

All Vulnerabilities

Title CVE ID CVSS Researchers Date
FluentCRM Pro <= 3.1.12 - Authenticated (Author+) SQL Injection CVE-2026-78270 6.5 Ananda Dhakal August 24, 2026
The WP Remote WordPress Plugin, Malcare Security, and BlogVault Backup & Staging < 6.65 - Unauthenticated Site Takeover via Brute Force CVE-2026-19718 9.8 Jakub Herman August 24, 2026
Shared Files – File Upload & Download Manager <= 1.7.69 - Authenticated (Contributor+) Server-Side Request Forgery CVE-2026-78269 6.4 Cem Bas August 24, 2026
Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Authenticated (Administrator+) Stored Cross-Site Scripting CVE-2026-14325 4.4 Sai Praneeth Koti August 24, 2026
Hash Form – Drag & Drop Form Builder <= 1.4.0 - Cross-Site Request Forgery CVE-2026-78280 4.3 sanghyeok Kim August 24, 2026
Tutor LMS – eLearning and online course solution < 4.0.6 - Unauthenticated SQL Injection CVE-2026-19094 7.5 Jakub Herman August 24, 2026
Fluent Support Pro <= 2.3.1 - Missing Authorization CVE-2026-78272 4.3 Ananda Dhakal August 24, 2026
Security Hardener <= 2.4.4 - Authenticated (Subscriber+) Privilege Escalation via REST API '/wp/v2/users' permission_callback Overwrite CVE-2026-16149 8.8 zickzick2 August 22, 2026
PPWP – Password Protect Pages <= 1.9.18 - Authenticated (Contributor+) PHP Object Injection via post_protection_roles CVE-2026-0551 8.8 Webbernaut August 22, 2026
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter CVE-2026-18027 6.5 daroo August 22, 2026
Image Photo Gallery Final Tiles Grid <= 3.6.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'delay' Shortcode Attribute CVE-2026-4559 6.4 Athiwat Tiprasaharn (Jitlada), Itthidej Aramsri (Boeing777) August 22, 2026
Themify Builder <= 7.8.0 - Missing Authorization to Unauthenticated Arbitrary Builder Data Modification via 'tb_update_old_data' AJAX Action CVE-2026-75027 5.3 Wordfence PRISM August 21, 2026
AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_convertkit_get_forms AJAX Action CVE-2026-76057 4.3 Wordfence PRISM August 21, 2026
AutomatorWP <= 5.8.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via automatorwp_campaign_monitor_get_lists AJAX Action CVE-2026-76074 4.3 Wordfence PRISM August 21, 2026
WPeMatico RSS Feed Fetcher <= 2.8.24 - Authenticated (Subscriber+) Privilege Escalation via Arbitrary Option Update to wpematico_import_settings admin_action CVE-2026-19883 8.8 Supakiad S. (m3ez) August 21, 2026
WP Directory Kit < 1.5.7 - Unauthenticated Information Exposure CVE-2026-18231 5.3 Erwan LR August 21, 2026
TrueBooker – Appointment Booking and Scheduler System < 1.2.7 - Missing Authorization CVE-2026-18777 5.3 Mokksh Parekh August 21, 2026
SmartCrawl SEO checker, analyzer & optimizer < 3.16.3 - Missing Authorization CVE-2026-16979 4.3 Ezekiel Victor August 21, 2026
Membership For WooCommerce < 3.1.2 - Unauthenticated Information Exposure CVE-2026-19709 5.3 Shikhali Jamalzade August 21, 2026
Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content < 0.8.6 - Reflected Cross-Site Scripting CVE-2026-77115 6.1 Huseyin Mertoglu August 21, 2026

Researcher Hall of Fame (Past 30 days)

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation