WordPress Plugin CVE Trends 2026

Open dataset of high-severity vulnerabilities (CVSS ≥ 7.0) in popular WordPress plugins. Sourced from NIST NVD, refreshed every 30 minutes.

5
CVEs tracked
5
unique plugins
8.74
avg CVSS
9.8
max CVSS
1
CRITICAL
4
HIGH

Download

📊 CSV (0.9 KB) 📦 JSON

License: CC-BY-4.0 · Last updated: 2026-05-03 08:23 UTC · Citation: GuardLabs (2026). WordPress Plugin CVE Trends 2026. https://guardlabs.online/datasets/cve-trends-2026/

Schema

FieldTypeDescription
cve_idstringCVE identifier, e.g. CVE-2026-2892
pluginstringAffected WordPress plugin name
cvssfloatCVSS v3 base score (0.0–10.0)
severitystringHIGH or CRITICAL
publishedISO 8601Date CVE published in NVD
modifiedISO 8601Date CVE record last modified
report_urlURLPlain-language analysis on guardlabs.online (en/ru/es)

Sample (top 10 by CVSS)

CVEPluginCVSSSeverityReport
CVE-2026-7567Temporary Login9.8CRITICALen · ru · es
CVE-2026-3772WP Editor8.8HIGHen · ru · es
CVE-2026-6741Calendar Booking Plugin for Appointments and Events8.8HIGHen · ru · es
CVE-2026-7106Highland Software Custom Role Manager8.8HIGHen · ru · es
CVE-2026-2892Otter Blocks7.5HIGHen · ru · es

For the full 5 records, download the CSV/JSON above.

Source & Methodology

Use Cases

Need automated patching for these CVEs on your WordPress site?
GuardLabs Website Care · Annual applies patches the same day they drop. $240/year. Free audit first →