WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–26 of 26 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Advanced Custom Fields: Extended Plugin acf-extended Privilege Escalation Unauthenticated Privilege Escalation via Front-End User Insert Action No login needed 0.9.2.2 – < 0.9.2.7 Fixed in 0.9.2.7 CVE-2026-80467 WPScan
8.1 High Advanced Custom Fields: Extended Plugin acf-extended Privilege Escalation Unauthenticated Administrator Account Takeover via Front-End User Update Action No login needed < 0.9.2.7 Fixed in 0.9.2.7 CVE-2026-12526 WPScan
4.3 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Broken Access Control ≤ 6.1.1 CVE-2026-66678 Patchstack
5.3 Medium Advanced Custom Fields (ACF®) Plugin advanced-custom-fields Broken Access Control Unauthenticated Arbitrary Post Modification via Front-End Form '_post_title' and '_post_content' Parameters No login needed ≤ 6.8.1 CVE-2026-8382 Wordfence
9.8 Critical Advanced Custom Fields: Extended Plugin acf-extended Privilege Escalation Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter No login needed ≤ 0.9.2.5 CVE-2026-8809 Wordfence
6.5 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Cross-Site Scripting ≤ 5.0.2 CVE-2026-49044 Patchstack
6.4 Medium Advanced Custom Fields: Font Awesome Field Plugin advanced-custom-fields-font-awesome Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via JSON Field ≤ 5.0.2 CVE-2026-6415 Wordfence
6.5 Medium Advanced Custom Fields: Extended Plugin acf-extended Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.9.2.3 CVE-2025-15463 Wordfence
5.3 Medium Advanced Custom Fields (ACF®) Plugin advanced-custom-fields Broken Access Control Unauthenticated Missing Authorization to Arbitrary Post/Page Disclosure via AJAX Field Query Parameters No login needed ≤ 6.7.0 CVE-2026-4812 Wordfence
6.4 Medium Advanced Custom Fields: Font Awesome Plugin advanced-custom-fields-font-awesome Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.0.1 CVE-2025-14983 Wordfence
9.8 Critical Advanced Custom Fields: Extended Plugin acf-extended Privilege Escalation Unauthenticated Privilege Escalation via Insert User Form Action No login needed ≤ 0.9.2.1 CVE-2025-14533 Wordfence
9.8 Critical Advanced Custom Fields: Extended Plugin acf-extended Remote Code Execution Unauthenticated Remote Code Execution in prepare_form No login needed 0.9.0.5 – 0.9.1.1 CVE-2025-13486 Wordfence
8.8 High Advanced Custom Fields : CPT Options Pages Plugin acf-cpt-options-pages Cross-Site Request Forgery No login needed ≤ 2.0.9 CVE-2025-60208 Patchstack
3.4 Low Advanced Custom Fields Plugin Content Injection An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page… prior to 6.4.3 CVE-2025-54940 jpcert
10.0 Critical WordPress Plugin advanced-custom-fields Local File Inclusion WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion No login needed ≤ 3.5.1 CVE-2012-10025 VulnCheck
7.1 High Advanced Custom Fields: Link Picker Field Plugin acf-link-picker-field Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2025-26746 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Cross-Site Request Forgery No login needed < 6.3.2 Fixed in 6.3.2 CVE-2024-37251 Patchstack
5.4 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Broken Access Control Subscriber+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37250 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin Broken Access Control Contributor+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37249 Patchstack
5.3 Medium advanced-custom-fields Plugin advanced-custom-fields Cross-Site Scripting In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can r… No login needed Not stated CVE-2024-49593 mitre
6.1 Medium Advanced Custom Fields Plugin advanced-custom-fields Cross-Site Scripting Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the '… No login needed 6.3.5 and earlier CVE-2024-45429 jpcert
7.5 High Advanced Custom Fields Plugin Broken Access Control Contributor+ Custom Field Access No login needed < 6.3 Fixed in 6.3 CVE-2024-4565 WPScan
9.9 Critical Advanced Custom Fields PRO Plugin Local File Inclusion Contributor+ Local File Inclusion < 6.2.10 Fixed in 6.2.10 CVE-2024-34762 Patchstack
8.5 High Advanced Custom Fields PRO Plugin Remote Code Execution Contributor+ Arbitrary Function Execution < 6.2.10 Fixed in 6.2.10 CVE-2024-34761 Patchstack
6.4 Medium Advanced Custom Fields Plugin advanced-custom-fields Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field ≤ 6.2.4 CVE-2023-6701 Wordfence
3.7 Low Advanced Custom Fields (ACF) Plugin advanced-custom-fields Information Disclosure WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposure No login needed 3.1.1 – 6.0.2 Fixed in 6.0.3 CVE-2022-40696 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only