WordPress Security Tracker
Counting vulnerabilities so you don't have to.
10,831
Vulnerabilities in 2025
6,242
2026 (so far)
945
Last 30 days
Last 30 Days Breakdown
- 909 plugin vulnerabilities
- 27 theme vulnerabilities
- 9 core vulnerabilities
Recent Critical & High Severity
- critical Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.8.5 - Unauthenticated PHP Object Injection CVSS 9.8 · Contact Form, Survey, Quiz & Popup Form Builder – ARForms
- high Infility Global <= 2.15.21 - Unauthenticated Stored Cross-Site Scripting via /cf7_record Log Endpoint CVSS 7.2 · Infility Global
- high Online Scheduling and Appointment Booking System <= 27.7 - Unauthenticated Stored Cross-Site Scripting via bookly_speed_up_update_addons AJAX action CVSS 7.2 · Online Scheduling and Appointment Booking System – Bookly
- high Gallery by BestWebSoft <= 4.7.9 - Authenticated (Editor+) SQL Injection via Gallery Image Order Array Keys CVSS 7.2 · Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress
- high WP Travel Engine <= 6.8.4 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'booking_id' Parameter CVSS 7.5 · WP Travel Engine – Tour Booking Plugin – Tour Operator Software
- high WCPOS <= 1.9.14 - Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine CVSS 7.2 · WCPOS – Point of Sale (POS) plugin for WooCommerce
- high Royal Addons for Elementor <= 1.7.1064 - Authenticated (Contributor+) Server-Side Request Forgery via Form Builder Widget 'webhook_url' Setting CVSS 8.8 · Royal Addons for Elementor – Addons and Templates Kit for Elementor
- high Query Wrangler <= 1.5.57 - Authenticated (Subscriber+) Remote Code Execution via 'options' Parameter CVSS 8.8 · Query Wrangler
- critical ProSolution WP Client <= 2.0.10 - Unauthenticated Arbitrary File Upload via Content-Disposition Header Filename Override CVSS 9.8 · ProSolution WP Client
- critical ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters CVSS 9.1 · ProSolution WP Client
Last updated: Aug 17, 2026, 06:51 AM
Why This Matters