WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–18 of 18 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WP Edit Password Protected Plugin Broken Access Control Unauthenticated Site-Wide Access Mode Bypass via REST API No login needed 2.0.0 – < 2.0.7 Fixed in 2.0.7 CVE-2026-90952 WPScan
5.3 Medium Wp Edit Password Protected Plugin Broken Access Control Protection Bypass via REST API No login needed < 1.3.5 Fixed in 1.3.5 CVE-2025-8945 WPScan
4.3 Medium Gutentor Plugin gutentor Information Disclosure Subscriber+ Password Protected Post Password Disclosure via REST API < 4.0.6 Fixed in 4.0.6 CVE-2026-16983 WPScan
4.3 Medium Password Protect WordPress Lite Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Password Protected Post Password Update ≤ 1.9.20 CVE-2025-10005 Wordfence
7.5 High Password Protected Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via REST API No login needed 2.6.8 – < 2.8.4 Fixed in 2.8.4 CVE-2026-14943 WPScan
3.7 Low Password Protected Plugin password-protected Broken Access Control Unauthenticated Authorization Bypass via IP Address Spoofing No login needed ≤ 2.7.11 CVE-2025-11244 Wordfence
5.3 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Broken Access Control Missing Authorization to Password Protected Post Disclosure No login needed ≤ 5.2.7 CVE-2025-9984 Wordfence
6.1 Medium Wp Edit Password Protected Plugin Open Redirect No login needed < 1.3.5 Fixed in 1.3.5 CVE-2025-9034 WPScan
5.3 Medium Rehub Theme Information Disclosure Unauthenticated Password Protected Post Disclosure No login needed ≤ 19.9.7 CVE-2025-7368 Wordfence
5.3 Medium Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products Plugin password-protected Information Disclosure Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.7.7 CVE-2025-3453 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Information Disclosure Unauthenticated Password Protected Event Disclosure No login needed < 6.8.2.1 Fixed in 6.8.2.1 CVE-2024-5333 WPScan
7.5 High Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Authentication Bypass Password Protected View Bypass Vulnerability No login needed ≤ 5.7.1 Fixed in 5.8.0 CVE-2023-46630 Patchstack
4.3 Medium Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease Plugin Broken Access Control Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure ≤ 2.6.6 CVE-2024-0437 Wordfence
5.4 Medium Combo Blocks Plugin Broken Access Control Unauthenticated Password Protected Posts Access < 2.2.76 Fixed in 2.2.76 CVE-2024-0881 WPScan
4.3 Medium Inline Related Posts Plugin intelly-related-posts Broken Access Control Subscriber+ Password Protected Post Read < 3.6.0 Fixed in 3.6.0 CVE-2023-6257 WPScan
5.3 Medium Hubbub Lite Plugin social-pug Authentication Bypass Unauthenticated Password Protected Posts Access No login needed < 1.33.1 Fixed in 1.33.1 CVE-2024-1526 WPScan
5.3 Medium Password Protected Store for WooCommerce Plugin password-protected-woo-store Information Disclosure Information Exposure via REST API No login needed ≤ 2.2 CVE-2024-1088 Wordfence
4.4 Medium Password Protected Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.6.6 CVE-2024-0656 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only