WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–24 of 24 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter No login needed ≤ 1.57.2 CVE-2026-92144 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field No login needed ≤ 1.57.2 CVE-2026-85235 Wordfence
8.5 High Forminator Forms Plugin forminator Remote Code Execution Authenticated RCE via XML-RPC PHP Object Injection 1.57.0.7 – < 1.57.2.1 Fixed in 1.57.2.1 CVE-2026-87067 WPScan
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field No login needed ≤ 1.57.0.1 CVE-2026-18324 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter No login needed ≤ 1.57.0 CVE-2026-18328 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) No login needed ≤ 1.57.0.2 CVE-2026-18323 Wordfence
7.2 High Forminator Forms Plugin forminator Remote Code Execution Admin+ Network-Wide RCE via Hub Connector API Key on Multisite 1.40.0 – < 1.57.0.5 Fixed in 1.57.0.5 CVE-2026-19221 WPScan
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.56.0 Fixed in 1.56.1 CVE-2026-28143 Patchstack
8.8 High Forminator Plugin forminator Privilege Escalation ≤ 1.56.0 Fixed in 1.56.0.1 CVE-2026-28111 Patchstack
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Forged Upload Record via Select Field No login needed ≤ 1.56.1 CVE-2026-18325 Wordfence
8.1 High Uncanny Automator Plugin uncanny-automator PHP Object Injection Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token No login needed ≤ 7.3.1.4 CVE-2026-15008 Wordfence
7.5 High Forminator Plugin forminator Path Traversal Arbitrary File Download No login needed ≤ 1.55.0.2 Fixed in 1.55.1 CVE-2026-57815 Patchstack
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.55.0.1 Fixed in 1.55.0.2 CVE-2026-57814 Patchstack
7.1 High Forminator Plugin forminator Cross-Site Scripting No login needed ≤ 1.53.1 Fixed in 1.53.2 CVE-2026-56071 Patchstack
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Path Traversal Contact Form, Payment Form & Custom Form Builder <= 1.52.1 - Unauthenticated Arbitrary File Read via 'upload-1[file][file_path]' No login needed ≤ 1.52.1 CVE-2026-5192 Wordfence
8.8 High Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent Plugin tablesome Broken Access Control Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent 0.5.4 - 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure and Privilege Escalation 0.5.4 – 1.2.1 CVE-2025-12845 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator PHP Object Injection Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated PHP Object Injection (PHAR) Triggered via Administrator Form Submission Deletion No login needed ≤ 1.44.2 CVE-2025-6464 Wordfence
8.8 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Arbitrary File Deletion Contact Form, Payment Form & Custom Form Builder <= 1.44.2 - Unauthenticated Arbitrary File Deletion Triggered via Administrator Form Submission Deletion No login needed ≤ 1.44.2 CVE-2025-6463 Wordfence
7.1 High GSheetConnector for Forminator Forms Plugin gsheetconnector-forminator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.12 Fixed in 1.0.13 CVE-2025-22752 Patchstack
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation ≤ 1.35.1 CVE-2024-10402 Wordfence
7.5 High Forminator Plugin forminator Information Disclosure HubSpot Developer API Key Sensitive Information Exposure No login needed ≤ 1.29.1 CVE-2024-7389 Wordfence
7.2 High Forminator Plugin forminator SQL Injection Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain… prior to 1.29.3 CVE-2024-31077 jpcert
7.2 High Forminator Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via File Upload No login needed ≤ 1.29.0 CVE-2024-1794 Wordfence
7.1 High Forminator Plugin forminator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.29.0 Fixed in 1.29.1 CVE-2024-29777 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only