WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–47 of 47 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Wp Social Login and Register Social Counter Plugin wp-social Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write ≤ 3.2.1 CVE-2026-97344 Wordfence
6.1 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Cross-Site Scripting Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter No login needed ≤ 4.17.4 CVE-2026-92551 Wordfence
6.4 Medium User Profile Builder Plugin profile-builder Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Avatar Field ≤ 4.0.2 CVE-2026-93656 Wordfence
5.0 Medium Directorist Plugin directorist-wpml-integration Server-Side Request Forgery Subscriber+ SSRF via Avatar URL < 8.9.5 Fixed in 8.9.5 CVE-2026-84046 WPScan
4.1 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Server-Side Request Forgery Admin+ SSRF via bp_avatar < 2.4.5 Fixed in 2.4.5 CVE-2026-16542 WPScan
5.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via First Name / Last Name Profile Field ≤ 4.16.19 CVE-2026-18385 Wordfence
6.5 Medium WP Social Avatar Plugin wp-social-avatar Broken Access Control No login needed ≤ 1.5 CVE-2026-66454 Patchstack
4.3 Medium Simple User Avatar Plugin simple-user-avatar Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.9 Fixed in 5.0 CVE-2026-57676 Patchstack
6.5 Medium ProfilePress Plugin wp-user-avatar Cross-Site Scripting ≤ 4.16.13 Fixed in 4.16.14 CVE-2026-41556 Patchstack
4.3 Medium Charitable Plugin charitable Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter ≤ 1.8.11.1 CVE-2026-10038 Wordfence
5.3 Medium App Builder Plugin app-builder Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Avatar Modification via 'user_id' Parameter No login needed ≤ 5.6.0 CVE-2026-7638 Wordfence
4.4 Medium Buzz Comments Plugin buzz-comments Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Buzz Avatar' Setting ≤ 0.9.4 CVE-2026-6041 Wordfence
4.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Inactive Membership Plan Subscription ≤ 4.16.12 CVE-2026-4949 Wordfence
5.3 Medium Author Avatars List/Block Plugin author-avatars Broken Access Control No login needed ≤ 2.1.25 CVE-2026-39690 Patchstack
6.5 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution ProfilePress <= 4.16.11 - Unauthenticated Arbitrary Shortcode Execution via Checkout Billing Fields No login needed ≤ 4.16.11 CVE-2026-3309 Wordfence
4.3 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Broken Access Control Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.15.5 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Post Author Reassignment via Avatar Field ≤ 3.15.5 CVE-2026-3139 Wordfence
6.4 Medium wpForo Forum Plugin wpforo Cross-Site Scripting wpForo Forum 2.4.14 Stored XSS via SVG Avatar File Upload 2.4 – < 2.4.16 Fixed in 2.4.16 CVE-2026-28558 VulnCheck
6.5 Medium User Avatar - Reloaded Plugin user-avatar-reloaded Cross-Site Scripting Reloaded plugin <= 1.2.2 - Cross Site Scripting (XSS) ≤ 1.2.2 CVE-2025-68080 Patchstack
6.8 Medium WP User Manager Plugin wp-user-manager Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter ≤ 2.9.12 CVE-2025-13320 Wordfence
5.4 Medium ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 4.16.7 CVE-2025-13642 Wordfence
6.5 Medium WPAvatar Plugin wpavatar Cross-Site Scripting ≤ 1.9.4 CVE-2025-48312 Patchstack
6.5 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 4.16.4 CVE-2025-8878 Wordfence
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Broken Access Control Missing Authorization to Authenticated (Subscriber+) Avatar Migration ≤ 2.8.4 CVE-2025-8482 Wordfence
5.4 Medium wpForo Forum Plugin wpforo Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar ≤ 2.4.5 CVE-2025-4406 Wordfence
4.3 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Broken Access Control ≤ 1.0.6 CVE-2025-49980 Patchstack
4.3 Medium Avatar Plugin avatar Broken Access Control Insecure Direct Object References (IDOR) ≤ 0.1.4 CVE-2025-39434 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
4.3 Medium WP User Profile Avatar Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.5 CVE-2024-10789 Wordfence
6.5 Medium Author Avatars List/Block Plugin author-avatars Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.23 Fixed in 2.1.24 CVE-2025-22804 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.1 Fixed in 4.13.2 CVE-2023-41953 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.2 Fixed in 4.13.3 CVE-2023-50882 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 4.15.18 CVE-2024-11083 Wordfence
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Cache Clearing ≤ 2.7.11 CVE-2024-10786 Wordfence
6.5 Medium Author Avatars List/Block Plugin author-avatars Cross-Site Scripting ≤ 2.1.21 Fixed in 2.1.22 CVE-2024-47370 Patchstack
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Cross-Site Request Forgery No login needed ≤ 2.7.10 Fixed in 2.7.11 CVE-2024-43116 Patchstack
6.4 Medium ProfilePress Plugin wp-user-avatar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ProfilePress User Panel Widget ≤ 4.15.8 CVE-2024-2861 Wordfence
6.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Cross-Site Scripting ProfilePress <= 4.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.15.4 CVE-2024-2867 Wordfence
5.4 Medium WP User Profile Avatar Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.0.1 CVE-2023-6067 WPScan
6.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Cross-Site Scripting ProfilePress <= 4.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'reg-single-checkbox' ≤ 4.15.5 CVE-2024-3210 Wordfence
6.4 Medium ProfilePress Plugin wp-user-avatar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via profilepress-edit-profile Shortcode ≤ 4.15.1 CVE-2024-1806 Wordfence
6.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Cross-Site Scripting ProfilePress <= 4.15.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via [reg-select-role] Shortcode ≤ 4.15.0 CVE-2024-1409 Wordfence
6.4 Medium ProfilePress Plugin wp-user-avatar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.15.2 CVE-2024-1535 Wordfence
6.5 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Cross-Site Scripting ProfilePress <= 4.14.4 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.14.4 CVE-2024-1519 Wordfence
6.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Cross-Site Scripting ProfilePress <= 4.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.14.3 CVE-2024-1046 Wordfence
6.5 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Cross-Site Scripting WordPress WP User Profile Avatar Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0 Fixed in 1.0.1 CVE-2023-52118 Patchstack
4.3 Medium WP User Profile Avatar Plugin Broken Access Control Author+ Avatar Deletion/Update via IDOR < 1.0.1 Fixed in 1.0.1 CVE-2023-6384 WPScan
6.6 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar PHP Object Injection WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection ≤ 4.3.2 Fixed in 4.4.0 CVE-2022-45083 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only