WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 66 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.9 Medium AI Chatbot for WordPress – Hyve Lite Plugin hyve-lite Broken Access Control Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-97305 Patchstack
5.4 Medium WPBot Plugin chatbot Broken Access Control Subscriber+ Claude AI Settings Update 8.7.2 – < 8.7.6 Fixed in 8.7.6 CVE-2026-87959 WPScan
5.3 Medium WPBot Plugin chatbot Broken Access Control Unauthenticated AI Provider API Abuse via Multiple AJAX Actions No login needed < 8.5.7 Fixed in 8.5.7 CVE-2026-87918 WPScan
5.3 Medium WPBot Plugin chatbot Information Disclosure Unauthenticated Chat Visitor PII Disclosure No login needed 8.4.9 – < 8.6.0 Fixed in 8.6.0 CVE-2026-87916 WPScan
4.8 Medium AI Engine Plugin ai-engine Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed < 3.6.4 Fixed in 3.6.4 CVE-2026-16953 WPScan
5.3 Medium WPBot Plugin chatbot Information Disclosure Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action No login needed ≤ 8.5.9 CVE-2026-16773 Wordfence
5.3 Medium WPBot Plugin chatbot Broken Access Control Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action No login needed ≤ 8.5.9 CVE-2026-16774 Wordfence
4.3 Medium WPBot AI ChatBot Plugin Broken Access Control Subscriber+ RAG Settings Update < 8.2.0 Fixed in 8.2.0 CVE-2026-14185 WPScan
4.3 Medium WPBot Plugin chatbot Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function ≤ 8.5.6 CVE-2026-15610 Wordfence
5.3 Medium WPBot Plugin chatbot Broken Access Control Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter No login needed ≤ 8.5.6 CVE-2026-15106 Wordfence
5.9 Medium AI Engine Plugin ai-engine Information Disclosure Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR < 3.5.5 Fixed in 3.5.5 CVE-2026-12510 WPScan
6.5 Medium ChatBot for eCommerce – WoowBot Plugin woowbot-woocommerce-chatbot Cross-Site Scripting WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) ≤ 4.6.1 Fixed in 4.7.0 CVE-2026-57414 Patchstack
5.3 Medium AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions No login needed ≤ 1.4.12 CVE-2026-6804 Wordfence
5.3 Medium AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Broken Access Control Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear' No login needed ≤ 1.4.12 CVE-2026-6803 Wordfence
4.4 Medium Chatra Live Chat + ChatBot + Cart Saver Plugin chatra-live-chat Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting ≤ 1.0.12 CVE-2026-12041 Wordfence
6.4 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes ≤ 2.3.0 CVE-2026-12731 Wordfence
6.4 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute ≤ 2.3.0 CVE-2026-12734 Wordfence
4.3 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action ≤ 2.3.0 CVE-2026-12729 Wordfence
6.5 Medium Elizaibots Plugin elizaibot-chatbots Cross-Site Scripting ≤ 1.0.2 CVE-2025-15659 Patchstack
6.4 Medium AI Chatbot & Workflow Automation by AIWU Plugin ai-copilot-content-generator Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header ≤ 1.4.14 CVE-2026-2955 Wordfence
4.4 Medium FastBots Plugin fastbots-ai-chatbots Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.0.12 CVE-2026-6800 Wordfence
5.3 Medium WP-Chatbot for Messenger Plugin wp-chatbot Broken Access Control Missing Authorization to Unauthenticated Chatbot Configuration Takeover No login needed ≤ 4.9 CVE-2026-3506 Wordfence
5.3 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Broken Access Control Missing Authorization to Unauthenticated API Key Modification No login needed ≤ 2.7.5 CVE-2026-1336 Wordfence
6.5 Medium Cliengo – Chatbot Plugin cliengo Broken Access Control Chatbot plugin <= 3.0.4 - Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-69388 Patchstack
5.3 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Broken Access Control No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2026-25338 Patchstack
6.4 Medium Smartsupp – live chat, AI shopping assistant and chatbots Plugin smartsupp-live-chat Cross-Site Scripting live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.9.1 CVE-2025-12448 Wordfence
6.4 Medium Chatbot for WordPress by Collect.chat ⚡️ Plugin collectchat Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field ≤ 2.4.8 CVE-2026-0736 Wordfence
5.3 Medium weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot Plugin wedocs Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 2.1.15 CVE-2025-14574 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed ≤ 2.5.5 CVE-2025-12585 Wordfence
5.3 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Broken Access Control Missing Authorization to Unauthenticated Media File Uploads No login needed ≤ 2.7.0 CVE-2025-13381 Wordfence
6.5 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter No login needed ≤ 2.7.0 CVE-2025-13378 Wordfence
5.3 Medium ChatBot Plugin chatbot Broken Access Control No login needed ≤ 7.3.9 Fixed in 7.4.0 CVE-2025-64277 Patchstack
4.3 Medium ChatBot Plugin chatbot Broken Access Control ≤ 7.7.3 Fixed in 7.7.4 CVE-2025-62952 Patchstack
4.3 Medium AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Plugin chatbot-ai-free-models Content Injection Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated CSV Injection No login needed ≤ 1.6.5 CVE-2025-11576 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Server-Side Request Forgery AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.4.6 CVE-2025-10705 Wordfence
5.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Unauthenticated Limited File Uploads and Conversation Erasing No login needed ≤ 2.3.5 CVE-2025-11256 Wordfence
5.4 Medium AI Engine Plugin ai-engine Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter ≤ 2.8.4 CVE-2025-5570 Wordfence
4.3 Medium ChatBot Plugin chatbot Broken Access Control ≤ 6.7.3 Fixed in 6.7.5 CVE-2025-53200 Patchstack
4.8 Medium AI ChatBot for WordPress – WPBot Plugin Cross-Site Scripting WPBot < 6.2.4 - Admin+ Stored XSS < 6.2.4 Fixed in 6.2.4 CVE-2025-0329 WPScan
5.4 Medium Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit Plugin Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions ≤ 2.3.6 CVE-2024-13816 Wordfence
5.9 Medium AI Chatbot for WordPress – Hyve Lite Plugin hyve-lite Cross-Site Scripting ≤ 1.2.2 Fixed in 1.2.3 CVE-2025-24666 Patchstack
4.3 Medium WPBot Pro Wordpress Chatbot Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation ≤ 13.5.5 CVE-2024-12879 Wordfence
6.5 Medium Conversational Forms for ChatBot Plugin conversational-forms Cross-Site Scripting ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-22813 Patchstack
5.4 Medium Chative Live chat and Chatbot Plugin chative-live-chat-and-chatbot Cross-Site Request Forgery Cross-Site Request Forgery via add_chative_widget_action Function No login needed ≤ 1.1 CVE-2024-12541 Wordfence
6.5 Medium Smartsupp – live chat, chatbots, AI and lead generation Plugin smartsupp-live-chat Cross-Site Request Forgery No login needed ≤ 3.6 Fixed in 3.7 CVE-2024-38790 Patchstack
4.3 Medium AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot Plugin ai-seo-translator Cross-Site Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-54306 Patchstack
5.4 Medium WP-Chatbot for Messenger Plugin wp-chatbot Broken Access Control ≤ 4.7 Fixed in 4.8 CVE-2023-32581 Patchstack
5.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Deletion No login needed ≤ 2.1.7 CVE-2024-10529 Wordfence
4.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification No login needed ≤ 2.1.8 CVE-2024-11143 Wordfence
6.1 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.7 CVE-2024-10684 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only