WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 67 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.2 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Subscriber+ Arbitrary Activity Privacy Modification via IDOR < 4.7.12 Fixed in 4.7.12 CVE-2026-88912 WPScan
7.5 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Unauthenticated SQL Injection via 'compare' Parameter No login needed ≤ 4.7.11 CVE-2026-16482 Wordfence
4.3 Medium BuddyPress Plugin buddypress Broken Access Control Insecure Direct Object Reference to Notifications Deletion ≤ 14.3.3 CVE-2024-12145 Wordfence
5.4 Medium Push Notification for Post and BuddyPress Plugin push-notification-for-post-and-buddypress Broken Access Control ≤ 3.20 Fixed in 3.21 CVE-2026-81279 Patchstack
9.3 Critical rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection No login needed ≤ 4.7.11 Fixed in 4.7.12 CVE-2026-66592 Patchstack
5.4 Medium BuddyPress Plugin buddypress Information Disclosure Subscriber+ Private Messages Disclosure via IDOR < 14.5.0 Fixed in 14.5.0 CVE-2026-8155 WPScan
7.5 High BuddyPress Plugin buddypress PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data ≤ 14.5.0 CVE-2026-1360 Wordfence
8.5 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection ≤ 4.7.10 Fixed in 4.7.11 CVE-2026-59551 Patchstack
9.3 Critical rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection No login needed ≤ 4.7.10 Fixed in 4.7.11 CVE-2026-59549 Patchstack
6.5 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 4.6.18 CVE-2026-15287 Wordfence
6.4 Medium Block, Suspend, Report for BuddyPress Plugin bp-toolkit Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter ≤ 3.6.4 CVE-2026-4653 Wordfence
6.5 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control ≤ 4.7.9 Fixed in 4.7.10 CVE-2026-40773 Patchstack
4.3 Medium BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Friends List IDOR via REST API ≤ 14.4.0 CVE-2026-53675 VulnCheck
7.1 High BuddyPress Plugin buddypress Denial of Service BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution ≤ 14.4.0 CVE-2026-53674 VulnCheck
8.1 High BuddyPress Plugin buddypress Broken Access Control BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter ≤ 14.4.0 CVE-2026-53673 VulnCheck
6.4 Medium Buddypress Plugin buddypress Cross-Site Scripting WordPress Plugin Buddypress 6.2.0 Persistent Cross-Site Scripting 6.2.0 CVE-2020-37233 VulnCheck
8.8 High BuddyPress Groupblog Plugin bp-groupblog Privilege Escalation Authenticated (Subscriber+) Privilege Escalation to Administrator via Group Blog IDOR ≤ 1.9.3 CVE-2026-5144 Wordfence
5.3 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.8 Fixed in 4.7.9 CVE-2026-25325 Patchstack
7.3 High BuddyPress Plugin buddypress Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 14.3.3 CVE-2024-11976 Wordfence
8.8 High BuddyPress Xprofile Custom Field Types Plugin bp-xprofile-custom-field-types Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.2.8 CVE-2025-14997 Wordfence
6.5 Medium BuddyPress Activity Shortcode Plugin bp-activity-shortcode Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-62760 Patchstack
6.1 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Cross-Site Scripting Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.10.2 CVE-2025-14154 Wordfence
3.7 Low rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control Missing Authorization to Unauthenticated Information Disclosure via handle_rest_pre_dispatch Function No login needed 4.7.0 – 4.7.3 CVE-2025-9218 Wordfence
5.3 Medium Restrictions for BuddyPress Plugin bp-restrict Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 1.5.2 CVE-2025-12391 Wordfence
6.5 Medium Activity Plus Reloaded for BuddyPress Plugin bp-activity-plus-reloaded Cross-Site Scripting ≤ 1.1.2 CVE-2025-62949 Patchstack
7.5 High BuddyPress Plugin buddypress Broken Access Control No login needed ≤ 14.3.4 Fixed in 14.4.0 CVE-2025-62022 Patchstack
6.5 Medium BuddyPress Notification Widget Plugin buddypress-notifications-widget Cross-Site Scripting ≤ 1.3.3 CVE-2025-58263 Patchstack
8.6 High BuddyPress XProfile Custom Image Field Plugin buddypress-xprofile-image-field Arbitrary File Deletion No login needed ≤ 3.0.1 Fixed in 3.1.0 CVE-2025-48158 Patchstack
4.3 Medium BuddyPress Docs Plugin buddypress-docs Broken Access Control Subscriber+ Arbitrary Document Read/Update < 2.2.5 Fixed in 2.2.5 CVE-2025-5526 WPScan
5.4 Medium Activity Plus Reloaded for BuddyPress Plugin bp-activity-plus-reloaded Broken Access Control ≤ 1.1.2 CVE-2025-30957 Patchstack
9.8 Critical Push Notification for Post and BuddyPress Plugin push-notification-for-post-and-buddypress SQL Injection Multiple Unauthenticated SQLi No login needed < 1.9.4 Fixed in 1.9.4 CVE-2024-6159 WPScan
5.4 Medium Wbcom Designs - Activity Link Preview For BuddyPress Plugin activity-link-preview-for-buddypress Server-Side Request Forgery Activity Link Preview For BuddyPress plugin <= 1.4.4 - Server Side Request Forgery (SSRF) No login needed ≤ 1.4.4 Fixed in 1.6.0 CVE-2025-47548 Patchstack
4.2 Medium Buddypress Force Password Change Plugin buddy-press-force-password-change Privilege Escalation Authenticated (Subscriber+) Account Takeover via Password Update ≤ 0.1 CVE-2025-3793 Wordfence
7.1 High Activity Reactions For Buddypress Plugin activity-reactions-for-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.22 CVE-2025-31006 Patchstack
9.8 Critical Buddypress Humanity Plugin buddypress-humanity Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.2 CVE-2025-31033 Patchstack
6.5 Medium BuddyPress Members Only Plugin buddypress-members-only Cross-Site Scripting ≤ 3.5.3 Fixed in 3.6.3 CVE-2025-31812 Patchstack
4.8 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Server-Side Request Forgery Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links No login needed ≤ 2.7.4 CVE-2024-13697 Wordfence
7.5 High Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Information Disclosure Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.6.9 CVE-2024-13611 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update ≤ 3.4.25 CVE-2025-1780 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 3.4.24 CVE-2024-13358 Wordfence
6.5 Medium Push Notification for Post and BuddyPress Plugin push-notification-for-post-and-buddypress Broken Access Control Settings Change No login needed ≤ 2.11 Fixed in 2.12 CVE-2025-23771 Patchstack
6.5 Medium SocialV - Social Network and Community BuddyPress Theme Broken Access Control Social Network and Community BuddyPress Theme <= 2.0.15 - Missing Authorization to Arbitrary File Download ≤ 2.0.15 CVE-2024-13529 Wordfence
6.4 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Cross-Site Scripting Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.6.9 CVE-2024-13612 Wordfence
5.4 Medium BuddyPress Groups Extras Plugin buddypress-groups-extras Cross-Site Request Forgery No login needed ≤ 3.6.10 Fixed in 3.7.0 CVE-2025-24538 Patchstack
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license) ≤ 1.3.3 CVE-2024-13370 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 1.3.4 CVE-2024-13368 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
5.4 Medium Activity Plus Reloaded for BuddyPress Plugin bp-activity-plus-reloaded Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery ≤ 1.1.1 CVE-2024-11913 Wordfence
7.1 High Mass Messaging in BuddyPress Plugin mass-messaging-in-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.1 CVE-2025-23798 Patchstack
7.1 High Jet Skinner for BuddyPress Plugin jet-skinner-for-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2025-23706 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only