WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–48 of 48 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.5 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via 'page_url' Parameter ≤ 1.4.0.5 CVE-2026-12037 Wordfence
6.5 Medium 10Web Booster Plugin tenweb-speed-optimizer Information Disclosure Unauthenticated Connection Secret Disclosure and Deletion No login needed < 2.34.0 Fixed in 2.34.0 CVE-2026-82195 WPScan
5.3 Medium Sale Booster Plugin Information Disclosure Unauthenticated Non-Public Product Disclosure No login needed 7.0.0 – < 7.5.2 Fixed in 7.5.2 CVE-2026-88929 WPScan
4.3 Medium SEO Booster Plugin seo-booster Broken Access Control Authenticated (Subscriber+) Missing Authorization to Arbitrary Options Modification via handle_oauth_callback() ≤ 7.4.7 CVE-2026-15660 Wordfence
5.4 Medium Gravity Booster – Styles & Layouts for Gravity Forms Plugin styles-and-layouts-for-gravity-forms Broken Access Control Styles & Layouts for Gravity Forms plugin <= 6.0 - Broken Access Control ≤ 6.0 CVE-2026-74004 Patchstack
4.4 Medium Gravity Booster Plugin styles-and-layouts-for-gravity-forms Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'stylerSettings' Parameter ≤ 5.26 CVE-2026-12477 Wordfence
5.3 Medium StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action No login needed ≤ 2.1.0 CVE-2026-13110 Wordfence
5.3 Medium StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action No login needed ≤ 2.1.0 CVE-2026-15411 Wordfence
4.9 Medium SEO Booster Plugin seo-booster SQL Injection Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter ≤ 7.3.1 CVE-2026-15458 Wordfence
4.9 Medium SEO Booster Plugin seo-booster SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 7.3.1 CVE-2026-15445 Wordfence
5.3 Medium WCBoost – Products Compare Plugin wcboost-products-compare Information Disclosure Products Compare plugin <= 1.1.0 - Sensitive Data Exposure No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2026-57633 Patchstack
4.9 Medium WS Optimize – All-in-One Speed Booster & Cache Tools Plugin lws-optimize Path Traversal All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read ≤ 3.3.19 CVE-2026-12089 Wordfence
5.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control No login needed ≤ 1.4.0.3 Fixed in 1.4.0.4 CVE-2026-45212 Patchstack
5.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control No login needed ≤ 7.11.3 Fixed in 7.11.3 CVE-2026-32586 Patchstack
6.5 Medium SEO Booster Plugin seo-booster Broken Access Control No login needed ≤ 6.1.8 CVE-2025-68019 Patchstack
4.3 Medium All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Plugin all-in-one-seo-pack Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure ≤ 4.9.2 CVE-2025-14384 Wordfence
5.4 Medium Core Web Vitals & PageSpeed Booster Plugin core-web-vitals-pagespeed-booster Broken Access Control ≤ 1.0.28 CVE-2025-62144 Patchstack
4.3 Medium WP DB Booster Plugin wp-db-booster Cross-Site Request Forgery Cross-Site Request Forgery to Database Cleanup No login needed ≤ 1.0.1 CVE-2025-14168 Wordfence
4.3 Medium All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Plugin all-in-one-seo-pack Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion ≤ 4.8.9 CVE-2025-12847 Wordfence
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting ≤ 7.3.2 Fixed in 7.4.0 CVE-2025-64380 Patchstack
4.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control ≤ 7.4.0 Fixed in 7.5.0 CVE-2025-64379 Patchstack
4.3 Medium WP Blast | SEO & Performance Booster Plugin wpblast Cross-Site Request Forgery Cross-Site Request Forgery to Cache Clearing No login needed ≤ 1.8.6 CVE-2025-9622 Wordfence
5.4 Medium WP DB Booster Plugin wp-db-booster Broken Access Control ≤ 1.0.1 CVE-2025-53318 Patchstack
5.9 Medium Jetpack Plugin jetpack Cross-Site Scripting Contributor+ Stored XSS < 13.8, < 3.4.8 Fixed in 13.8 CVE-2024-10076 WPScan
6.5 Medium WP Social SEO Booster – Knowledge Graph Social Signals SEO Plugin wp-social-seo-booster Cross-Site Scripting ≤ 1.2.0 CVE-2025-27348 Patchstack
5.3 Medium Booster Elementor Addons Plugin booster-for-elementor Broken Access Control No login needed ≤ 1.4.9 CVE-2023-38480 Patchstack
5.4 Medium Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder Plugin Cross-Site Scripting Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.20.2 CVE-2024-10583 Wordfence
4.4 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery ≤ 1.3.9.8 Fixed in 1.3.9.9 CVE-2024-53738 Patchstack
5.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode ≤ 7.2.3 CVE-2024-9170 Wordfence
6.1 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.2.3 CVE-2024-9239 Wordfence
4.3 Medium Boostify Header Footer Builder for Elementor Plugin boostify-header-footer-builder Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.3.6 CVE-2024-10794 Wordfence
4.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control ≤ 1.3.9.3 Fixed in 1.3.9.4 CVE-2024-43314 Patchstack
6.5 Medium Blockbooster Theme blockbooster Broken Access Control No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2024-43979 Patchstack
6.4 Medium Marketing and SEO Booster Plugin marketing-and-seo-booster Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.9.10 CVE-2024-9066 Wordfence
6.5 Medium Booster Plus for WooCommerce Plugin Information Disclosure Authenticated Arbitrary WordPress Option Disclosure < 7.1.3 Fixed in 7.1.3 CVE-2023-52230 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Broken Access Control Authenticated Arbitrary Post/Page Deletion < 7.1.2 Fixed in 7.1.2 CVE-2023-52232 Patchstack
4.3 Medium Boostify Header Footer Builder for Elementor Plugin boostify-header-footer-builder Broken Access Control Missing Authorization to Page/Post Creation ≤ 1.3.5 CVE-2024-4788 Wordfence
6.4 Medium Boostify Header Footer Builder for Elementor Plugin boostify-header-footer-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via size Parameter ≤ 1.3.2 CVE-2024-5006 Wordfence
6.5 Medium Booster Elite for WooCommerce Plugin Authentication Bypass Authenticated Production Creation/Modification < 7.1.3 Fixed in 7.1.3 CVE-2023-51511 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Authentication Bypass Authenticated Production Creation/Modification ≤ 7.1.2 Fixed in 7.1.3 CVE-2023-48747 Patchstack
5.3 Medium Booster Extension Plugin booster-extension Information Disclosure Basic Information Exposure via booster_extension_authorbox_shortcode_display No login needed ≤ 1.2.0 CVE-2024-2109 Wordfence
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.8 CVE-2024-3957 Wordfence
4.3 Medium SEO Booster Plugin seo-booster Cross-Site Request Forgery No login needed ≤ 3.8.9 Fixed in 3.8.10 CVE-2024-32438 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Information Disclosure Auth. Sensitive Data Exposure < 7.1.2 Fixed in 7.1.2 CVE-2023-52231 Patchstack
6.5 Medium Booster Elite for WooCommerce Plugin Information Disclosure Auth. Sensitive Data Exposure < 7.1.2 Fixed in 7.1.2 CVE-2023-52234 Patchstack
6.4 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde ≤ 7.1.7 CVE-2024-1534 Wordfence
5.3 Medium Build & Control Block Patterns – Boost up Gutenberg Editor Plugin control-block-patterns Broken Access Control Boost up Gutenberg Editor <= 1.3.5.4 - Missing Authorization No login needed ≤ 1.3.5.4 CVE-2024-1095 Wordfence
6.4 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 7.1.6 CVE-2024-1054 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only