WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 72 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.5 Low Simple Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Cross-Site Scripting Admin+ Stored XSS via PayPal API Credentials < 5.2.6 Fixed in 5.2.6 CVE-2026-104119 WPScan
3.7 Low Booking Calendar Plugin booking Other Race Condition No login needed ≤ 11.8.4 Fixed in 11.9 CVE-2026-39601 Patchstack
2.7 Low Astra Theme astra Content Injection ≤ 4.13.12 Fixed in 4.14.0 CVE-2026-27085 Patchstack
2.7 Low MCP Server Plugin Information Disclosure Contributor+ Arbitrary Post Title Disclosure via workflows/run REST Route < 1.8.2 Fixed in 1.8.2 CVE-2026-96526 WPScan
2.7 Low MCP Server Plugin Broken Access Control Contributor+ Workflow Modification and Deletion via Missing Ownership Check < 1.8.2 Fixed in 1.8.2 CVE-2026-96525 WPScan
3.7 Low MonsterInsights Plugin google-analytics-for-wordpress Authentication Bypass Unauthenticated Measurement Protocol Secret Update via Empty-Key HMAC Bypass No login needed < 11.1.0 Fixed in 11.1.0 CVE-2026-11366 WPScan
3.7 Low Builderall Plugin Broken Access Control Unauthenticated OAuth Access Token Poisoning via Public REST Routes No login needed < 3.0.2 Fixed in 3.0.2 CVE-2026-11882 WPScan
2.7 Low User Profile Picture Plugin metronet-profile-picture Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.6.3 Fixed in 2.6.4 CVE-2026-61971 Patchstack
2.7 Low Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.6.11 Fixed in 3.6.12 CVE-2026-39510 Patchstack
2.7 Low Elementor Website Builder Plugin elementor Broken Access Control ≤ 3.35.5 Fixed in 3.35.6 CVE-2026-32445 Patchstack
3.8 Low Real 3D FlipBook Plugin real3d-flipbook-lite Broken Access Control ≤ 4.19.1 Fixed in 4.19.2 CVE-2026-25423 Patchstack
3.8 Low Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-47555 Patchstack
3.8 Low Crowdsignal Forms Plugin crowdsignal-forms Broken Access Control ≤ 1.7.2 Fixed in 1.8.0 CVE-2025-69015 Patchstack
2.7 Low WP Document Revisions Plugin wp-document-revisions Broken Access Control ≤ 3.7.2 Fixed in 3.8.0 CVE-2025-68585 Patchstack
2.7 Low WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce plugin <= 6.7.24 - Broken Access Control ≤ 6.7.24 Fixed in 6.7.25 CVE-2025-54004 Patchstack
2.7 Low Traveler Option Tree Plugin custom-option-tree Information Disclosure Sensitive Data Exposure ≤ 2.8 CVE-2025-49300 Patchstack
3.7 Low rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function No login needed 4.7.0 – 4.7.3 CVE-2025-9218 Wordfence
2.7 Low Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Broken Access Control ≤ 8.0.8 Fixed in 8.1.0 CVE-2025-64255 Patchstack
2.7 Low Photo Block Plugin photo-block Broken Access Control ≤ 1.5.1 Fixed in 1.6.0 CVE-2025-64254 Patchstack
3.4 Low WP YouTube Lyte Plugin wp-youtube-lyte Open Redirect No login needed ≤ 1.7.28 Fixed in 1.7.29 CVE-2025-66062 Patchstack
2.7 Low Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control ≤ 6.2.4 Fixed in 6.3.0 CVE-2025-64352 Patchstack
3.8 Low Rank Math SEO Plugin seo-by-rank-math Broken Access Control ≤ 1.0.252.1 Fixed in 1.0.253 CVE-2025-64350 Patchstack
3.8 Low CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control ≤ 1.4.35 CVE-2025-58009 Patchstack
3.8 Low Content Mask Plugin content-mask Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.8.5.3 CVE-2025-58012 Patchstack
2.7 Low Site Info Plugin site-info-dashboard-widget Information Disclosure Sensitive Data Exposure ≤ 1.1 CVE-2025-58866 Patchstack
3.8 Low Job Board Manager Plugin job-board-manager Content Injection ≤ 2.1.61 CVE-2025-58827 Patchstack
3.5 Low Product Carousel Slider for Elementor Plugin ecommerce-product-carousel-slider-for-elementor Broken Access Control ≤ 2.1.3 CVE-2025-58816 Patchstack
3.4 Low Advanced Custom Fields Plugin Content Injection An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page… prior to 6.4.3 CVE-2025-54940 jpcert
2.7 Low Piotnet Forms Plugin piotnetforms Path Traversal ≤ 1.0.30 CVE-2025-32205 Patchstack
2.7 Low Squeeze Plugin squeeze Information Disclosure Full Path Disclosure (FPD) ≤ 1.6 Fixed in 1.6.1 CVE-2025-31003 Patchstack
2.7 Low Quiz Cat Plugin quiz-cat Broken Access Control ≤ 3.0.8 Fixed in 3.0.9 CVE-2025-30877 Patchstack
3.8 Low Filebird Plugin filebird Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.4.2.1 Fixed in 6.4.6 CVE-2025-26977 Patchstack
3.5 Low Analytify Plugin wp-analytify Broken Access Control ≤ 5.1.0 Fixed in 5.1.1 CVE-2023-41695 Patchstack
3.5 Low Popup Maker Plugin popup-maker Broken Access Control ≤ 1.17.1 Fixed in 1.18.0 CVE-2022-45819 Patchstack
3.7 Low AR Plugin ar-for-wordpress Broken Access Control Missing Authorization to Unauthenticated Limited File Upload No login needed ≤ 7.3 CVE-2024-12300 Wordfence
3.8 Low CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control ≤ 1.4.13 Fixed in 1.4.15 CVE-2023-23814 Patchstack
3.1 Low Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Import_WPforms ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23825 Patchstack
3.5 Low WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin miniorange-login-openid Broken Access Control ≤ 7.5.14 Fixed in 7.6.0 CVE-2023-24375 Patchstack
3.7 Low WordPress Console Plugin wordpress-console Broken Access Control No login needed ≤ 0.3.9 CVE-2023-28168 Patchstack
2.7 Low Otter - Gutenberg Block Plugin otter-blocks Broken Access Control ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-51671 Patchstack
3.8 Low CM Table Of Contents – WordPress TOC Plugin Cross-Site Request Forgery WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF < 1.2.3 Fixed in 1.2.3 CVE-2024-5030 WPScan
3.7 Low Maintenance Redirect Plugin jf3-maintenance-mode Authentication Bypass IP Bypass No login needed ≤ 2.0.1 Fixed in 2.1.0 CVE-2024-45453 Patchstack
3.7 Low Maintenance & Coming Soon Redirect Animation Plugin maintenance-coming-soon-redirect-animation Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3.3 CVE-2024-43944 Patchstack
3.8 Low Photo Gallery by Ays Plugin gallery-photo-gallery Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection < 5.7.1 Fixed in 5.7.1 CVE-2024-37442 Patchstack
2.7 Low WP Directory Kit Plugin wpdirectorykit Content Injection HTML Injection ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-37253 Patchstack
3.5 Low WooCommerce Plugin woocommerce Content Injection ≤ 8.9.2 Fixed in 9.0.0 CVE-2024-35777 Patchstack
3.5 Low Academy LMS Plugin academy Open Redirect ≤ 2.0.4 CVE-2024-37234 Patchstack
3.7 Low Solid Security Plugin better-wp-security Denial of Service IP Spoofing Leading to Denial of Service No login needed ≤ 9.3.1 Fixed in 9.3.2 CVE-2022-44593 Patchstack
3.7 Low Under Construction / Maintenance Mode from Acurax Plugin coming-soon-maintenance-mode-from-acurax Authentication Bypass IP Bypass No login needed ≤ 2.6 CVE-2024-35749 Patchstack
3.7 Low weForms Plugin weforms Broken Access Control No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-30512 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only