WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–41 of 41 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment No login needed ≤ 5.3.5 CVE-2026-92977 Wordfence
7.2 High Complianz GDPR/CCPA Cookie Consent Banner Plugin complianz-gdpr Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Elementor Cookie Blocker Regex No login needed ≤ 7.5.4 CVE-2026-83561 Wordfence
8.8 High WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored XSS via Consent Logs No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85130 WPScan
6.5 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Arbitrary Post Deletion via CSRF No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85131 WPScan
5.4 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions < 4.4.2 Fixed in 4.4.2 CVE-2026-85133 WPScan
4.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Information Disclosure Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan 4.0.2 – < 4.4.2 Fixed in 4.4.2 CVE-2026-85132 WPScan
4.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Subscriber+ Banner Settings Overwrite and A/B Test Data Reset 3.6.5 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82185 WPScan
5.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Unauthenticated IAB TCF Consent Option Update No login needed 3.5.0 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82184 WPScan
7.2 High iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more Plugin iubenda-cookie-law-solution Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content No login needed ≤ 3.13.4 CVE-2026-77263 Wordfence
7.2 High iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more Plugin iubenda-cookie-law-solution Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite No login needed ≤ 3.13.4 CVE-2026-77233 Wordfence
4.1 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent SQL Injection Admin+ SQLi via 'offset' Parameter 3.0.0 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82186 WPScan
9.8 Critical WPLP Cookie Consent Plugin gdpr-cookie-consent Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint No login needed ≤ 4.4.1 CVE-2026-75865 Wordfence
4.3 Medium Cookie Consent Plugin Broken Access Control Subscriber+ MaxMind License Key Update 0.0.9 – < 0.0.10 Fixed in 0.0.10 CVE-2026-18046 WPScan
4.3 Medium Cookie Consent Plugin Information Disclosure Subscriber+ Consent Settings Update and Consent Log Disclosure < 0.0.10 Fixed in 0.0.10 CVE-2026-15388 WPScan
6.5 Medium WebToffee Cookie Consent Plugin Information Disclosure Consent Log Disclosure/Deletion, Page Creation & License Deactivation via Unprotected REST Routes No login needed < 3.5.3 Fixed in 3.5.3 CVE-2026-13389 WPScan
4.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed ≤ 4.3.7 CVE-2026-15136 Wordfence
6.4 Medium WP GDPR Cookie Consent Plugin wp-gdpr-cookie-consent Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions' AJAX Action ≤ 1.0.0 CVE-2026-8977 Wordfence
5.3 Medium Complianz – GDPR/CCPA Cookie Consent Plugin complianz-gdpr Broken Access Control GDPR/CCPA Cookie Consent <= 7.4.5 - Missing Authorization to Unauthenticated Private Post Content Disclosure via Consent Area REST Endpoint No login needed ≤ 7.4.5 CVE-2026-4019 Wordfence
4.9 Medium Complianz – GDPR/CCPA Cookie Consent Plugin complianz-gdpr Cross-Site Scripting GDPR/CCPA Cookie Consent <= 7.4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Content Filter ≤ 7.4.4.2 CVE-2026-2389 Wordfence
7.5 High Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Sensitive Information Exposure No login needed ≤ 4.1.2 CVE-2025-11754 Wordfence
6.4 Medium Complianz | GDPR/CCPA Cookie Consent Plugin complianz-gdpr Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 7.4.3 CVE-2025-11185 Wordfence
4.4 Medium Cookie consent for developers Plugin cookie-consent-for-developers Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Multiple Settings Fields ≤ 1.7.1 CVE-2026-1084 Wordfence
5.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 4.0.7 CVE-2025-14061 Wordfence
7.1 High WP GDPR Cookie Consent Plugin wp-gdpr-cookie-consent Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-53316 Patchstack
6.8 Medium Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery via scan-without-login Endpoint ≤ 5.2.4 CVE-2025-12136 Wordfence
6.5 Medium Termageddon: Cookie Consent & Privacy Compliance Plugin termageddon-usercentrics Cross-Site Scripting ≤ 1.8.1 Fixed in 1.8.2 CVE-2025-58026 Patchstack
7.1 High Beautiful Cookie Consent Banner Plugin beautiful-and-responsive-cookie-consent Cross-Site Scripting No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2025-49866 Patchstack
5.4 Medium GDPR Cookie Consent Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed < 2.6.1 Fixed in 2.6.1 CVE-2024-8397 WPScan
6.5 Medium GDPR Cookie Consent Plugin Cross-Site Request Forgery Bulk Delete via CSRF No login needed < 2.6.1 Fixed in 2.6.1 CVE-2024-8286 WPScan
5.9 Medium WP Cookie Consent Plugin wp-cookie-consent Cross-Site Scripting ≤ 1.0 CVE-2025-46525 Patchstack
7.1 High Implied Cookie Consent Plugin implied-cookie-consent Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-25113 Patchstack
4.3 Medium GDPR CCPA Compliance Support Plugin ninja-gdpr-compliance Broken Access Control ≤ 2.7.1 Fixed in 2.7.2 CVE-2025-24591 Patchstack
7.1 High Cookie Consent & Autoblock for GDPR/CCPA Plugin cookie-consent-autoblock Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23501 Patchstack
5.3 Medium Seers Plugin seers-cookie-consent-banner-privacy-policy Broken Access Control No login needed ≤ 8.1.1 Fixed in 8.1.2 CVE-2023-47515 Patchstack
4.3 Medium Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) Plugin gdpr-cookie-consent Broken Access Control Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script ≤ 3.6.5 CVE-2024-11724 Wordfence
7.2 High WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Client-IP header No login needed ≤ 3.2.0 CVE-2024-4869 Wordfence
5.3 Medium Cookie Consent Plugin uk-cookie-consent Broken Access Control No login needed ≤ 3.2 Fixed in 3.2.1 CVE-2024-35692 Patchstack
5.4 Medium GDPR CCPA Compliance & Cookie Consent Banner Plugin ninja-gdpr-compliance Broken Access Control Missing Authorization to Settings Update and Stored Cross-Site Scripting ≤ 2.7.0 CVE-2024-5607 Wordfence
5.3 Medium WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 3.0.2 CVE-2024-3599 Wordfence
4.3 Medium Complianz – GDPR/CCPA Cookie Consent Plugin Cross-Site Request Forgery GDPR/CCPA Cookie Consent <= 6.5.6 - Cross-Site Request Forgery to Data Request Deletion No login needed ≤ 6.5.6 CVE-2024-1592 Wordfence
4.4 Medium Complianz | GDPR/CCPA Cookie Consent Plugin Cross-Site Scripting Authenticated(Administrator+) Stored Cross-site Scripting via settings ≤ 6.5.5 CVE-2023-6498 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only