WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 76 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium FundEngine Plugin wp-fundraising-donation Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_featured_video_url' Parameter ≤ 1.8.1 CVE-2026-76063 Wordfence
4.3 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification via 'campaign_post' Parameter ≤ 1.8.1 CVE-2026-75930 Wordfence
5.3 Medium Charitable Plugin charitable Other Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature Bypass No login needed < 1.8.12 Fixed in 1.8.12 CVE-2026-16650 WPScan
6.8 Medium GiveWP Plugin give Cross-Site Scripting GiveWP Worker+ Stored XSS via Donation Form Template Settings < 4.16.3 Fixed in 4.16.3 CVE-2026-14318 WPScan
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control ≤ 1.7.8 Fixed in 1.7.9 CVE-2026-59560 Patchstack
6.5 Medium Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2026-65518 Patchstack
6.5 Medium FundEngine Plugin wp-fundraising-donation Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2026-57406 Patchstack
6.5 Medium Better Payment – Instant Payments, Donations, Fundraising with Subscriptions & More Plugin better-payment Other Instant Payments, Donations, Fundraising with Subscriptions & More plugin <= 2.2.0 - Other Vulnerability Type No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-57364 Patchstack
5.3 Medium Donation Thermometer Plugin donation-thermometer Broken Access Control No login needed ≤ 2.2.7 CVE-2025-64636 Patchstack
5.3 Medium FundPress Plugin fundpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Donation Status Modification via donate_action_status AJAX Handler No login needed ≤ 2.0.8 CVE-2026-4650 Wordfence
5.3 Medium Cryptocurrency Donation Box – Bitcoin & Crypto Donations Plugin cryptocurrency-donation-box Broken Access Control Bitcoin & Crypto Donations plugin <= 2.2.13 - Broken Access Control No login needed ≤ 2.2.13 CVE-2026-39691 Patchstack
5.3 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable Other Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.9.7 - Insufficient Verification of Data Authenticity to Unauthenticated Donation Status Forgery via Stripe Webhook No login needed ≤ 1.8.9.7 CVE-2026-3177 Wordfence
6.4 Medium WordPress PayPal Donation Plugin wordpress-paypal-donation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'amount' Shortcode Attribute ≤ 1.01 CVE-2026-4072 Wordfence
4.7 Medium Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Open Redirect No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-68602 Patchstack
4.3 Medium WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.25 CVE-2025-58999 Patchstack
6.5 Medium Donation Thermometer Plugin donation-thermometer Cross-Site Scripting ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-67550 Patchstack
6.1 Medium WP-SOS-Donate Donation Sidebar Plugin wp-sos-donate Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 0.9.2 CVE-2025-13625 Wordfence
4.1 Medium Donation Plugin SQL Injection Admin+ SQLi ≤ 1.0 CVE-2025-13001 WPScan
5.3 Medium IDonate – Blood Donation, Request And Donor Management System Plugin idonate Broken Access Control Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 2.1.14 CVE-2025-12877 Wordfence
6.4 Medium Paypal Donation Shortcode Plugin paypal-donation-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2025-11859 Wordfence
4.9 Medium Double the Donation Plugin double-the-donation Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.0.0 CVE-2025-12020 Wordfence
6.5 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable SQL Injection Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated (Subscriber+) SQL Injection ≤ 1.8.8.4 CVE-2025-11893 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association No login needed ≤ 4.10.0 CVE-2025-11228 Wordfence
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure No login needed ≤ 4.10.0 CVE-2025-11227 Wordfence
5.9 Medium Double the Donation Plugin double-the-donation Cross-Site Scripting ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57929 Patchstack
4.3 Medium Double the Donation Plugin double-the-donation Cross-Site Request Forgery No login needed ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57930 Patchstack
6.5 Medium Donation Forms WP by Givecloud Plugin donation-forms-by-givecloud Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-58842 Patchstack
5.9 Medium Recurring PayPal Donations Plugin recurring-donation Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-57891 Patchstack
4.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update ≤ 4.5.0 CVE-2025-7221 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Information Disclosure Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure No login needed ≤ 4.6.0 CVE-2025-8620 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 4.5.0 - Authenticated (GiveWP worker+) Stored Cross-Site Scripting ≤ 4.5.0 CVE-2025-7205 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.3.0 - Missing Authorization To Authenticated (Contributor+) Campaign Data View And Modification ≤ 4.3.0 CVE-2025-4571 Wordfence
6.4 Medium Raisely Donation Form Plugin raisely-donation-form Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via raisely_donation_form Shortcode ≤ 1.1 CVE-2025-3781 Wordfence
4.3 Medium FundEngine Plugin wp-fundraising-donation Cross-Site Request Forgery No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-47459 Patchstack
4.3 Medium WP Church Donation Plugin wp-church-donation Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31410 Patchstack
5.9 Medium Paytm Payment Donation Plugin paytm-donation Cross-Site Scripting ≤ 2.3.3 CVE-2025-22640 Patchstack
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Information Disclosure Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure No login needed ≤ 3.22.1 CVE-2025-2331 Wordfence
5.8 Medium Give – Divi Donation Modules Plugin give-donation-modules-for-divi Information Disclosure Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-22633 Patchstack
6.1 Medium Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.4 CVE-2024-13728 Wordfence
6.4 Medium CanadaHelps Embedded Donation Plugin embedded-cdn Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.1 CVE-2024-11778 Wordfence
6.4 Medium Philantro – Donations and Donor Management Plugin philantro Cross-Site Scripting Donations and Donor Management <= 5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via donate Shortcode ≤ 5.3 CVE-2024-13527 Wordfence
6.5 Medium Charity-thermometer Plugin charitydonation-thermometer Cross-Site Scripting ≤ 1.1.2 CVE-2025-23860 Patchstack
6.5 Medium Donation Block For PayPal Plugin donations-block Cross-Site Scripting ≤ 2.2.0 Fixed in 2.3.1 CVE-2025-22525 Patchstack
6.4 Medium Quill Forms | Conversational Multi Step Forms, Surveys & quizzes Plugin quillforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.10.0 CVE-2024-11826 Wordfence
6.1 Medium GTPayment Donations Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2024-11607 WPScan
6.4 Medium Philantro – Donations and Donor Management Plugin philantro Cross-Site Scripting Donations and Donor Management <= 5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2 CVE-2024-12500 Wordfence
4.3 Medium Donations Made Easy – Smart Donations Plugin smart-donations Broken Access Control Smart Donations plugin <= 4.0.12 - Broken Access Control ≤ 4.0.12 CVE-2023-38475 Patchstack
6.5 Medium Stripe Donation Plugin bin-stripe-donation Cross-Site Scripting ≤ 1.2.5 CVE-2024-53752 Patchstack
6.1 Medium Kudos Donations – Easy donations and payments with Mollie Plugin kudos-donations Cross-Site Scripting Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting No login needed ≤ 3.2.9 CVE-2024-11684 Wordfence
6.1 Medium Kudos Donations – Easy donations and payments with Mollie Plugin kudos-donations Cross-Site Scripting Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting via 'add_query_arg' No login needed ≤ 3.2.9 CVE-2024-11685 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only