WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–41 of 41 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting No login needed ≤ 11.2.6 Fixed in 11.2.7 CVE-2026-97289 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 11.2.5 Fixed in 11.2.6 CVE-2026-62140 Patchstack
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-79615 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14826 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14825 WPScan
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option ≤ 11.2.1 CVE-2026-15963 Wordfence
6.4 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter ≤ 11.2.1 CVE-2026-11780 Wordfence
4.8 Medium Quiz And Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS via Polar Question < 11.2.2 Fixed in 11.2.2 CVE-2026-14824 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Template Deletion < 11.1.5 Fixed in 11.1.5 CVE-2026-14821 WPScan
5.3 Medium Quiz And Survey Master Plugin Information Disclosure Unauthenticated User Enumeration and Password Oracle via Quiz Login No login needed < 11.1.3 Fixed in 11.1.3 CVE-2026-14820 WPScan
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 11.2.0 Fixed in 11.2.1 CVE-2026-65454 Patchstack
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Custom+) SQL Injection via 'pages' Parameter ≤ 11.2.0 CVE-2026-13767 Wordfence
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure ≤ 11.1.4 CVE-2026-9230 Wordfence
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action ≤ 11.1.4 CVE-2026-9233 Wordfence
7.1 High Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting No login needed ≤ 11.1.2 Fixed in 11.1.3 CVE-2026-48867 Patchstack
7.1 High Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting No login needed ≤ 11.0.0 Fixed in 11.1.0 CVE-2026-40787 Patchstack
4.9 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters ≤ 11.1.2 CVE-2026-6448 Wordfence
5.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Content Injection Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields No login needed ≤ 10.1.0 CVE-2026-5797 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter ≤ 10.3.5 CVE-2026-2412 Wordfence
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 10.3.1 Fixed in 10.3.2 CVE-2025-67987 Patchstack
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 10.3.4 Fixed in 10.3.5 CVE-2026-25329 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 10.3.4 Fixed in 10.3.5 CVE-2026-25324 Patchstack
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 10.3.3 Fixed in 10.3.4 CVE-2026-24358 Patchstack
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter ≤ 10.3.1 CVE-2025-9318 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads No login needed ≤ 10.3.1 CVE-2025-9637 Wordfence
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion ≤ 10.3.1 CVE-2025-9294 Wordfence
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control No login needed ≤ 10.3.2 Fixed in 10.3.3 CVE-2025-63054 Patchstack
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 10.2.4 Fixed in 10.2.5 CVE-2025-55708 Patchstack
6.1 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Author+ Stored XSS No login needed < 9.2.1 Fixed in 9.2.1 CVE-2024-10679 WPScan
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 8.1.10 Fixed in 8.1.11 CVE-2023-37984 Patchstack
4.8 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Author+ Stored XSS < 9.1.3 Fixed in 9.1.3 CVE-2024-8758 WPScan
4.7 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Contributor+ Stored XSS No login needed < 9.1.1 Fixed in 9.1.1 CVE-2024-6879 WPScan
5.9 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Contributor+ Stored XSS < 9.1.0 Fixed in 9.1.0 CVE-2024-6390 WPScan
6.5 Medium Quiz and Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS < 9.0.5 Fixed in 9.0.5 CVE-2024-6025 WPScan
8.8 High Quiz And Survey Master Plugin SQL Injection Contributor+ SQLi < 9.0.2 Fixed in 9.0.2 CVE-2024-5606 WPScan
5.5 Medium Quiz And Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS < 9.0.2 Fixed in 9.0.2 CVE-2024-4934 WPScan
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control No login needed ≤ 8.1.16 Fixed in 8.1.17 CVE-2023-51507 Patchstack
9.9 Critical Quiz And Survey Master – Best Quiz, Exam and Survey Plugin quiz-master-next SQL Injection Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection ≤ 9.0.1 CVE-2024-3592 Wordfence
9.3 Critical Quiz And Survey Master Plugin quiz-master-next SQL Injection Unauthenticated SQL Injection No login needed ≤ 8.1.4 Fixed in 8.1.5 CVE-2023-28787 Patchstack
5.9 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting ≤ 8.2.2 Fixed in 8.2.3 CVE-2024-27966 Patchstack
5.4 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Request Forgery No login needed ≤ 8.1.18 Fixed in 8.1.19 CVE-2023-51521 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only