WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–50 of 66 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.9 Medium | AI Chatbot for WordPress – Hyve Lite | Broken Access Control Hyve Lite plugin <= 2.0.2 - Insecure Direct Object References (IDOR) No login needed |
≤ 2.0.2 Fixed in 2.0.3 |
CVE-2026-97305 |
Patchstack | |
| 5.4 Medium | WPBot | Broken Access Control Subscriber+ Claude AI Settings Update |
8.7.2 – < 8.7.6 Fixed in 8.7.6 |
CVE-2026-87959 |
WPScan | |
| 5.3 Medium | WPBot | Broken Access Control Unauthenticated AI Provider API Abuse via Multiple AJAX Actions No login needed |
< 8.5.7 Fixed in 8.5.7 |
CVE-2026-87918 |
WPScan | |
| 5.3 Medium | WPBot | Information Disclosure Unauthenticated Chat Visitor PII Disclosure No login needed |
8.4.9 – < 8.6.0 Fixed in 8.6.0 |
CVE-2026-87916 |
WPScan | |
| 4.8 Medium | AI Engine | Arbitrary File Deletion Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie No login needed |
< 3.6.4 Fixed in 3.6.4 |
CVE-2026-16953 |
WPScan | |
| 5.3 Medium | WPBot | Information Disclosure Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action No login needed |
≤ 8.5.9 |
CVE-2026-16773 |
Wordfence | |
| 5.3 Medium | WPBot | Broken Access Control Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action No login needed |
≤ 8.5.9 |
CVE-2026-16774 |
Wordfence | |
| 4.3 Medium | WPBot AI ChatBot | Broken Access Control Subscriber+ RAG Settings Update |
< 8.2.0 Fixed in 8.2.0 |
CVE-2026-14185 |
WPScan | |
| 4.3 Medium | WPBot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function |
≤ 8.5.6 |
CVE-2026-15610 |
Wordfence | |
| 5.3 Medium | WPBot | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter No login needed |
≤ 8.5.6 |
CVE-2026-15106 |
Wordfence | |
| 5.9 Medium | AI Engine | Information Disclosure Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR |
< 3.5.5 Fixed in 3.5.5 |
CVE-2026-12510 |
WPScan | |
| 6.5 Medium | ChatBot for eCommerce – WoowBot | Cross-Site Scripting WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) |
≤ 4.6.1 Fixed in 4.7.0 |
CVE-2026-57414 |
Patchstack | |
| 5.3 Medium | AI Chatbot & Workflow Automation by AIWU | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions No login needed |
≤ 1.4.12 |
CVE-2026-6804 |
Wordfence | |
| 5.3 Medium | AI Chatbot & Workflow Automation by AIWU | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear' No login needed |
≤ 1.4.12 |
CVE-2026-6803 |
Wordfence | |
| 4.4 Medium | Chatra Live Chat + ChatBot + Cart Saver | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting |
≤ 1.0.12 |
CVE-2026-12041 |
Wordfence | |
| 6.4 Medium | weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'sectionTitleTag' and 'articleTitleTag' Block Attributes |
≤ 2.3.0 |
CVE-2026-12731 |
Wordfence | |
| 6.4 Medium | weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'connectorWidth' Block Attribute |
≤ 2.3.0 |
CVE-2026-12734 |
Wordfence | |
| 4.3 Medium | weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Migration via wedocs_migrate_betterdocs_to_wedocs AJAX Action |
≤ 2.3.0 |
CVE-2026-12729 |
Wordfence | |
| 6.5 Medium | Elizaibots | Cross-Site Scripting |
≤ 1.0.2 |
CVE-2025-15659 |
Patchstack | |
| 6.4 Medium | AI Chatbot & Workflow Automation by AIWU | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' Header |
≤ 1.4.14 |
CVE-2026-2955 |
Wordfence | |
| 4.4 Medium | FastBots | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
≤ 1.0.12 |
CVE-2026-6800 |
Wordfence | |
| 5.3 Medium | WP-Chatbot for Messenger | Broken Access Control Missing Authorization to Unauthenticated Chatbot Configuration Takeover No login needed |
≤ 4.9 |
CVE-2026-3506 |
Wordfence | |
| 5.3 Medium | AI ChatBot with ChatGPT and Content Generator by AYS | Broken Access Control Missing Authorization to Unauthenticated API Key Modification No login needed |
≤ 2.7.5 |
CVE-2026-1336 |
Wordfence | |
| 6.5 Medium | Cliengo – Chatbot | Broken Access Control Chatbot plugin <= 3.0.4 - Broken Access Control |
≤ 3.0.4 Fixed in 3.0.5 |
CVE-2025-69388 |
Patchstack | |
| 5.3 Medium | AI ChatBot with ChatGPT and Content Generator by AYS | Broken Access Control No login needed |
≤ 2.7.4 Fixed in 2.7.5 |
CVE-2026-25338 |
Patchstack | |
| 6.4 Medium | Smartsupp – live chat, AI shopping assistant and chatbots | Cross-Site Scripting live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.9.1 |
CVE-2025-12448 |
Wordfence | |
| 6.4 Medium | Chatbot for WordPress by Collect.chat ⚡️ | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Field |
≤ 2.4.8 |
CVE-2026-0736 |
Wordfence | |
| 5.3 Medium | weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 2.1.15 |
CVE-2025-14574 |
Wordfence | |
| 5.3 Medium | MxChat – AI Chatbot | Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed |
≤ 2.5.5 |
CVE-2025-12585 |
Wordfence | |
| 5.3 Medium | AI ChatBot with ChatGPT and Content Generator by AYS | Broken Access Control Missing Authorization to Unauthenticated Media File Uploads No login needed |
≤ 2.7.0 |
CVE-2025-13381 |
Wordfence | |
| 6.5 Medium | AI ChatBot with ChatGPT and Content Generator by AYS | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter No login needed |
≤ 2.7.0 |
CVE-2025-13378 |
Wordfence | |
| 5.3 Medium | ChatBot | Broken Access Control No login needed |
≤ 7.3.9 Fixed in 7.4.0 |
CVE-2025-64277 |
Patchstack | |
| 4.3 Medium | ChatBot | Broken Access Control |
≤ 7.7.3 Fixed in 7.7.4 |
CVE-2025-62952 |
Patchstack | |
| 4.3 Medium | AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant | Content Injection Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated CSV Injection No login needed |
≤ 1.6.5 |
CVE-2025-11576 |
Wordfence | |
| 5.3 Medium | MxChat – AI Chatbot | Server-Side Request Forgery AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 2.4.6 |
CVE-2025-10705 |
Wordfence | |
| 5.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Unauthenticated Limited File Uploads and Conversation Erasing No login needed |
≤ 2.3.5 |
CVE-2025-11256 |
Wordfence | |
| 5.4 Medium | AI Engine | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter |
≤ 2.8.4 |
CVE-2025-5570 |
Wordfence | |
| 4.3 Medium | ChatBot | Broken Access Control |
≤ 6.7.3 Fixed in 6.7.5 |
CVE-2025-53200 |
Patchstack | |
| 4.8 Medium | AI ChatBot for WordPress – WPBot | Cross-Site Scripting WPBot < 6.2.4 - Admin+ Stored XSS |
< 6.2.4 Fixed in 6.2.4 |
CVE-2025-0329 |
WPScan | |
| 5.4 Medium | Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit | Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions |
≤ 2.3.6 |
CVE-2024-13816 |
Wordfence | |
| 5.9 Medium | AI Chatbot for WordPress – Hyve Lite | Cross-Site Scripting |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2025-24666 |
Patchstack | |
| 4.3 Medium | WPBot Pro Wordpress Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation |
≤ 13.5.5 |
CVE-2024-12879 |
Wordfence | |
| 6.5 Medium | Conversational Forms for ChatBot | Cross-Site Scripting |
≤ 1.4.2 Fixed in 1.4.3 |
CVE-2025-22813 |
Patchstack | |
| 5.4 Medium | Chative Live chat and Chatbot | Cross-Site Request Forgery Cross-Site Request Forgery via add_chative_widget_action Function No login needed |
≤ 1.1 |
CVE-2024-12541 |
Wordfence | |
| 6.5 Medium | Smartsupp – live chat, chatbots, AI and lead generation | Cross-Site Request Forgery No login needed |
≤ 3.6 Fixed in 3.7 |
CVE-2024-38790 |
Patchstack | |
| 4.3 Medium | AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot | Cross-Site Request Forgery No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2024-54306 |
Patchstack | |
| 5.4 Medium | WP-Chatbot for Messenger | Broken Access Control |
≤ 4.7 Fixed in 4.8 |
CVE-2023-32581 |
Patchstack | |
| 5.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Deletion No login needed |
≤ 2.1.7 |
CVE-2024-10529 |
Wordfence | |
| 4.3 Medium | Kognetiks Chatbot | Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification No login needed |
≤ 2.1.8 |
CVE-2024-11143 |
Wordfence | |
| 6.1 Medium | Kognetiks Chatbot | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.7 |
CVE-2024-10684 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.