WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–14 of 14 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Plugin Cross-Site Scripting Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.8.1 CVE-2026-15016 Wordfence
6.5 Medium Paid Memberships Pro - Member Directory Add On Plugin Information Disclosure Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi < 1.2.6 Fixed in 1.2.6 CVE-2024-1287 WPScan
4.9 Medium Paid Memberships Pro - Membership Maps Add On Plugin Information Disclosure Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosure < 0.7 Fixed in 0.7 CVE-2024-1286 WPScan
5.4 Medium Paid Memberships Pro Plugin Broken Access Control ≤ 1.2.3 Fixed in 1.2.4 CVE-2023-39990 Patchstack
5.4 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery Cross-Site Request Forgery to Membership Modification No login needed ≤ 2.12.10 CVE-2024-1407 Wordfence
5.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 3.0.1 CVE-2024-3215 Wordfence
5.4 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 2.12.10 Fixed in 3.0 CVE-2024-32793 Patchstack
4.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 2.12.10 Fixed in 3.0 CVE-2024-32794 Patchstack
4.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 2.12.10 CVE-2024-0588 Wordfence
5.3 Medium Paid Memberships Pro – Mailchimp Add On Plugin pmpro-mailchimp Information Disclosure Mailchimp Add On plugin <= 2.3.4 - Sensitive Data Exposure No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-30523 Patchstack
5.3 Medium Paid Memberships Pro – Payfast Gateway Add On Plugin pmpro-payfast Information Disclosure Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-30514 Patchstack
4.3 Medium Paid Memberships Pro Plugin Information Disclosure Contributor+ Arbitrary User Custom Field Disclosure < 2.12.9 Fixed in 2.12.9 CVE-2024-1279 WPScan
5.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery Cross-Site Request Forgery to Level Orders Update No login needed ≤ 2.12.7 CVE-2024-0624 Wordfence
5.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Broken Access Control Missing Authorization via API No login needed ≤ 2.12.5 CVE-2023-6855 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only