WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 62 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Wp Social Login and Register Social Counter Plugin wp-social Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write ≤ 3.2.1 CVE-2026-97344 Wordfence
6.1 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Cross-Site Scripting Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter No login needed ≤ 4.17.4 CVE-2026-92551 Wordfence
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Information Disclosure Authenticated (Subscriber+) Sensitive Information Exposure via Shortcode Injection via Nickname and Biographical Info Profile Fields ≤ 4.17.4 CVE-2026-92536 Wordfence
7.2 High User Profile Builder Plugin profile-builder Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Avatar Field No login needed ≤ 4.0.2 CVE-2026-95866 Wordfence
6.4 Medium User Profile Builder Plugin profile-builder Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Field ≤ 4.0.2 CVE-2026-93656 Wordfence
5.0 Medium Directorist Plugin directorist-wpml-integration Server-Side Request Forgery Subscriber+ SSRF via Avatar URL < 8.9.5 Fixed in 8.9.5 CVE-2026-84046 WPScan
4.1 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Server-Side Request Forgery Admin+ SSRF via bp_avatar < 2.4.5 Fixed in 2.4.5 CVE-2026-16542 WPScan
8.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via 'eup_bio' Biography Field (Entity-Encoded Shortcode Bracket) ≤ 4.17.2 CVE-2026-85658 Wordfence
8.1 High ProfilePress Plugin wp-user-avatar Remote Code Execution ProfilePress WordPress Plugin < 4.17.2 Unauthenticated Arbitrary Plugin Installation RCE No login needed < 4.17.2 Fixed in 4.17.2 CVE-2026-66047 VulnCheck
7.5 High One User Avatar | User Profile Picture Plugin one-user-avatar Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter ≤ 2.5.4 CVE-2026-18983 Wordfence
5.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field ≤ 4.16.19 CVE-2026-18385 Wordfence
6.5 Medium WP Social Avatar Plugin wp-social-avatar Broken Access Control No login needed ≤ 1.5 CVE-2026-66454 Patchstack
8.8 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary File Upload Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion ≤ 4.16.18 CVE-2026-13352 Wordfence
4.3 Medium Simple User Avatar Plugin simple-user-avatar Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.9 Fixed in 5.0 CVE-2026-57676 Patchstack
2.7 Low UsersWP Plugin userswp Broken Access Control Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter ≤ 1.2.63 CVE-2026-12102 Wordfence
6.5 Medium ProfilePress Plugin wp-user-avatar Cross-Site Scripting ≤ 4.16.13 Fixed in 4.16.14 CVE-2026-41556 Patchstack
4.3 Medium Charitable Plugin charitable Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter ≤ 1.8.11.1 CVE-2026-10038 Wordfence
5.3 Medium App Builder Plugin app-builder Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter No login needed ≤ 5.6.0 CVE-2026-7638 Wordfence
9.8 Critical Breeze Cache Plugin breeze Arbitrary File Upload Unauthenticated Arbitrary File Upload via fetch_gravatar_from_remote No login needed ≤ 2.4.4 CVE-2026-3844 Wordfence
4.4 Medium Buzz Comments Plugin buzz-comments Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Buzz Avatar' Setting ≤ 0.9.4 CVE-2026-6041 Wordfence
4.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription ≤ 4.16.12 CVE-2026-4949 Wordfence
5.3 Medium Author Avatars List/Block Plugin author-avatars Broken Access Control No login needed ≤ 2.1.25 CVE-2026-39690 Patchstack
6.5 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields No login needed ≤ 4.16.11 CVE-2026-3309 Wordfence
7.1 High Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Broken Access Control ProfilePress <= 4.16.11 - Missing Authorization to Authenticated (Subscriber+) Membership Payment Bypass ≤ 4.16.11 CVE-2026-3445 Wordfence
4.3 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Broken Access Control Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field ≤ 3.15.5 CVE-2026-3139 Wordfence
8.1 High ProfilePress Plugin wp-user-avatar Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Subscription Cancellation/Expiration ≤ 4.16.11 CVE-2026-3453 Wordfence
6.4 Medium wpForo Forum Plugin wpforo Cross-Site Scripting wpForo Forum 2.4.14 Stored XSS via SVG Avatar File Upload 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28558 VulnCheck
6.5 Medium User Avatar - Reloaded Plugin user-avatar-reloaded Cross-Site Scripting Reloaded plugin <= 1.2.2 - Cross Site Scripting (XSS) ≤ 1.2.2 CVE-2025-68080 Patchstack
6.8 Medium WP User Manager Plugin wp-user-manager Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter ≤ 2.9.12 CVE-2025-13320 Wordfence
5.4 Medium ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 4.16.7 CVE-2025-13642 Wordfence
6.5 Medium WPAvatar Plugin wpavatar Cross-Site Scripting ≤ 1.9.4 CVE-2025-48312 Patchstack
6.5 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 4.16.4 CVE-2025-8878 Wordfence
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Broken Access Control Missing Authorization to Authenticated (Subscriber+) Avatar Migration ≤ 2.8.4 CVE-2025-8482 Wordfence
5.4 Medium wpForo Forum Plugin wpforo Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar ≤ 2.4.5 CVE-2025-4406 Wordfence
4.3 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Broken Access Control ≤ 1.0.6 CVE-2025-49980 Patchstack
8.1 High Avatar Plugin avatar Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 0.1.4 CVE-2025-3520 Wordfence
4.3 Medium Avatar Plugin avatar Broken Access Control Insecure Direct Object References (IDOR) ≤ 0.1.4 CVE-2025-39434 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
7.1 High GravatarLocalCache Plugin gravatarlocalcache Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.2 CVE-2025-23901 Patchstack
4.3 Medium WP User Profile Avatar Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.5 CVE-2024-10789 Wordfence
6.5 Medium Author Avatars List/Block Plugin author-avatars Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.23 Fixed in 2.1.24 CVE-2025-22804 Patchstack
7.1 High 3D Avatar User Profile Plugin 3d-avatar-user-profile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-54358 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.1 Fixed in 4.13.2 CVE-2023-41953 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.2 Fixed in 4.13.3 CVE-2023-50882 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 4.15.18 CVE-2024-11083 Wordfence
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Cache Clearing ≤ 2.7.11 CVE-2024-10786 Wordfence
6.5 Medium Author Avatars List/Block Plugin author-avatars Cross-Site Scripting ≤ 2.1.21 Fixed in 2.1.22 CVE-2024-47370 Patchstack
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Cross-Site Request Forgery No login needed ≤ 2.7.10 Fixed in 2.7.11 CVE-2024-43116 Patchstack
6.4 Medium ProfilePress Plugin wp-user-avatar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget ≤ 4.15.8 CVE-2024-2861 Wordfence
8.6 High ProfilePress Plugin wp-user-avatar Privilege Escalation Unauthenticated Limited Privilege Escalation No login needed ≤ 4.13.1 Fixed in 4.13.2 CVE-2023-41954 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only