WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–22 of 22 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Bricksforge Plugin bricksforge Privilege Escalation No login needed ≤ 3.1.8.8 Fixed in 3.1.8.9 CVE-2026-84814 Patchstack
8.1 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary Password Reset via Pro Forms No login needed < 3.1.8.8 Fixed in 3.1.8.8 CVE-2026-18030 WPScan
9.8 Critical Bricksforge Plugin Privilege Escalation Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter No login needed ≤ 3.1.8.6 CVE-2026-14956 Wordfence
5.9 Medium Bricksable for Bricks Builder Plugin bricksable Cross-Site Scripting ≤ 1.6.83 Fixed in 1.6.84 CVE-2026-56009 Patchstack
4.3 Medium Bricks Builder Theme bricks Broken Access Control ≤ 2.1.4 Fixed in 2.2 CVE-2026-40723 Patchstack
7.5 High Bricksforge Plugin bricksforge Information Disclosure Sensitive Data Exposure No login needed ≤ 3.1.8.4 Fixed in 3.1.8.5 CVE-2026-34888 Patchstack
7.1 High Bricks Builder Theme bricks Cross-Site Scripting No login needed 1.9.2 – 2.2 Fixed in 2.3 CVE-2026-41554 Patchstack
7.5 High Bricks Builder Theme SQL Injection Unauthenticated SQL Injection via `p` Parameter No login needed ≤ 1.12.4 CVE-2025-6495 Wordfence
7.1 High Bricksbuilder Theme Privilege Escalation Authenticated (Contributor+) Privilege Escalation via create_autosave ≤ 1.9.6.1 CVE-2024-2297 Wordfence
5.9 Medium Bricksable for Bricks Builder Plugin bricksable Cross-Site Scripting ≤ 1.6.59 Fixed in 1.6.60 CVE-2024-51663 Patchstack
6.5 Medium Web Bricks Addons for Elementor Plugin webbricks-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-49665 Patchstack
5.4 Medium Bricks Theme Cross-Site Scripting Authenticated (Bricks Page Builder Access+) Stored Cross-Site Scripting ≤ 1.10.1 CVE-2023-3410 Wordfence
7.1 High Brickscore Plugin Cross-Site Scripting No login needed ≤ 1.4.2.5 CVE-2024-43950 Patchstack
4.3 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via save_settings No login needed ≤ 1.8.1 CVE-2023-3408 Wordfence
5.4 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via reset_settings No login needed ≤ 1.8.1 CVE-2023-3409 Wordfence
4.3 Medium Bricks Builder Plugin Broken Access Control Insecure Direct Object Reference ≤ 1.9.8 CVE-2024-4874 Wordfence
9.8 Critical Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31244 Patchstack
7.5 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Setting Deletion No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31243 Patchstack
10.0 Critical Bricks Builder Theme Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.9.6 Fixed in 1.9.6.1 CVE-2024-25600 Patchstack
7.1 High Max Addons Pro for Bricks Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32952 Patchstack
6.5 Medium Max Addons Pro for Bricks Plugin Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32951 Patchstack
5.3 Medium Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary Email Sending No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31242 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only