WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–17 of 17 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical BackupSheep Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key No login needed ≤ 1.8 CVE-2026-101148 WPScan
9.6 Critical WebTotem Backups Plugin wt-backups Arbitrary File Deletion Subscriber+ Arbitrary File Deletion via Path Traversal < 1.1.0 Fixed in 1.1.0 CVE-2026-77006 WPScan
9.1 Critical WPvivid Backup & Migration Plugin Path Traversal Unauthenticated Path Traversal via send_to_site_connect No login needed < 0.9.131 Fixed in 0.9.131 CVE-2026-19725 WPScan
9.3 Critical Everest Backup Plugin everest-backup SQL Injection No login needed ≤ 2.3.12 CVE-2026-66472 Patchstack
9.8 Critical Migration, Backup, Staging Plugin wpvivid-backuprestore Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 0.9.123 CVE-2026-1357 Wordfence
9.8 Critical Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App Plugin post-smtp Broken Access Control Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.0 - Missing Authorization to Account Takeover via Unauthenticated Email Log Disclosure No login needed ≤ 3.6.0 CVE-2025-11833 Wordfence
9.8 Critical WP Database Backup Plugin wp-database-backup Remote Code Execution Unauthenticated OS Command Injection No login needed < 5.2 Fixed in 5.2 CVE-2019-25224 Wordfence
9.8 Critical Bears Backup Plugin Remote Code Execution Unauthenticated Remote Code Execution No login needed ≤ 2.0.0 CVE-2025-5396 Wordfence
10.0 Critical WP SuperBackup Plugin indeed-wp-superbackup Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.3.3 Fixed in 2.4 CVE-2024-56064 Patchstack
9.8 Critical Super Backup & Clone - Migrate Plugin Arbitrary File Upload Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload No login needed ≤ 2.3.3 CVE-2024-9290 Wordfence
9.8 Critical WP Umbrella: Update Backup Restore & Monitoring Plugin wp-health Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.17.0 CVE-2024-12209 Wordfence
9.8 Critical Backup and Staging by WP Time Capsule Plugin wp-time-capsule Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.22.21 CVE-2024-8856 Wordfence
9.1 Critical Backuply – Backup, Restore, Migrate and Clone Plugin backuply SQL Injection Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection ≤ 1.3.4 CVE-2024-8669 Wordfence
9.8 Critical Backup and Staging by WP Time Capsule Plugin wp-time-capsule Authentication Bypass Authentication Bypass and Privilege Escalation No login needed ≤ 1.22.20 Fixed in 1.22.21 CVE-2024-38770 Patchstack
9.8 Critical WishList Member X Plugin Information Disclosure Unauthenticated Database Backup Download No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37113 Patchstack
9.1 Critical WP STAGING WordPress Backup Plugin – Migration Backup Restore Plugin wp-staging Arbitrary File Upload Migration Backup Restore <= 3.4.3 - Authenticated (Admin+) Arbitrary File Upload ≤ 3.4.3 CVE-2024-3412 Wordfence
9.8 Critical Migration, Backup, Staging – WPvivid Plugin wpvivid-backuprestore SQL Injection WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the… No login needed 0.9.68 CVE-2024-1981 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only