WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 90 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Broken Access Control No login needed ≤ 2.17.1 CVE-2026-39762 Patchstack
6.5 Medium App for Cloudflare® Plugin app-for-cf Broken Access Control ≤ 1.10.1 CVE-2026-39749 Patchstack
8.8 High WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import 2.0 – 3.8.3 CVE-2026-93031 Wordfence
8.6 High Yogeta WP Cloud Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.0 CVE-2026-80494 WPScan
6.5 Medium Simple CAPTCHA with Cloudflare Turnstile Plugin simple-cloudflare-turnstile Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation No login needed 1.2.2 – < 1.42.3 Fixed in 1.42.3 CVE-2026-85116 WPScan
5.6 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Authentication Bypass Captcha Bypass No login needed ≤ 1.42.1 Fixed in 1.42.3 CVE-2026-66674 Patchstack
6.5 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Content Injection No login needed ≤ 1.42.1 Fixed in 1.42.3 CVE-2026-66632 Patchstack
8.8 High Templately Plugin templately Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch ≤ 3.7.1 CVE-2026-18438 Wordfence
5.3 Medium Simple CAPTCHA with Cloudflare Turnstile Plugin simple-cloudflare-turnstile Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed < 1.42.0 Fixed in 1.42.0 CVE-2026-15239 WPScan
6.5 Medium Templately Plugin templately Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed < 3.7.1 Fixed in 3.7.1 CVE-2026-15359 WPScan
6.5 Medium pCloud WP Backup Plugin pcloud-wp-backup Broken Access Control Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read ≤ 2.0.3 CVE-2026-14503 Wordfence
7.1 High tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2026-57733 Patchstack
5.3 Medium Sendcloud Shipping Plugin sendcloud-connected-shipping Broken Access Control No login needed ≤ 1.0.29 CVE-2026-57760 Patchstack
7.1 High pCloud WP Backup Plugin pcloud-wp-backup Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2026-57757 Patchstack
8.8 High Offload, AI & Optimize with Cloudflare Images Plugin cf-images Remote Code Execution Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action ≤ 1.10.2 CVE-2026-9860 Wordfence
8.1 High CloudSecure WP Security Plugin cloudsecure-wp-security Authentication Bypass Broken Authentication No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2026-42411 Patchstack
5.8 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Authentication Bypass Broken Authentication No login needed ≤ 1.38.0 Fixed in 1.38.1 CVE-2026-40799 Patchstack
4.3 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo Broken Access Control Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations ≤ 12.4.16 CVE-2026-7624 Wordfence
7.2 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints No login needed ≤ 7.7 CVE-2026-3375 Wordfence
4.3 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Broken Access Control ≤ 2.14.0 CVE-2026-24527 Patchstack
5.3 Medium Mailercloud – Integrate webforms and synchronize website contacts Plugin mailercloud-integrate-webforms-synchronize-contacts Broken Access Control Integrate webforms and synchronize website contacts plugin <= 1.0.7 - Broken Access Control No login needed ≤ 1.0.7 CVE-2026-39713 Patchstack
8.1 High CloudMe Theme cloudme Local File Inclusion No login needed ≤ 1.2.2 CVE-2026-22433 Patchstack
6.5 Medium Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting ≤ 2.29 CVE-2025-69011 Patchstack
4.3 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection ≤ 12.4.14 CVE-2025-14342 Wordfence
7.2 High Super Page Cache Plugin wp-cloudflare-page-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Activity Log No login needed ≤ 5.2.2 CVE-2026-1843 Wordfence
4.3 Medium Code Snippets Plugin code-snippets Cross-Site Request Forgery Cross-Site Request Forgery to Cloud Snippet Download/Update Actions No login needed ≤ 3.9.4 CVE-2026-1785 Wordfence
5.4 Medium Cloudinary Plugin cloudinary-image-management-and-manipulation-in-the-cloud-cdn Broken Access Control ≤ 3.3.2 CVE-2026-24560 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
7.1 High SensitiveTagCloud Plugin sensitive-tag-cloud Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-49344 Patchstack
6.5 Medium BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control ≤ 4.6.7 Fixed in 4.7.1 CVE-2025-69024 Patchstack
6.5 Medium Offload, AI & Optimize with Cloudflare Images Plugin cf-images Broken Access Control ≤ 1.9.5 Fixed in 1.9.6 CVE-2025-66104 Patchstack
8.1 High Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.29 CVE-2025-13614 Wordfence
5.3 Medium Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed ≤ 2.3.8 CVE-2025-10304 Wordfence
6.5 Medium tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.2 CVE-2025-62032 Patchstack
7.1 High CloudSearch Plugin cloud-search Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2025-62962 Patchstack
6.4 Medium Listeo Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode ≤ 2.0.8 CVE-2025-8413 Wordfence
4.3 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin wdesignkit Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function ≤ 1.2.16 CVE-2025-9029 Wordfence
7.1 High W3SCloud Contact Form 7 to Zoho CRM Plugin w3s-cf7-zoho Cross-Site Request Forgery No login needed ≤ 3.2 CVE-2025-60169 Patchstack
6.5 Medium Cloud SAML SSO Plugin cloud-sso-single-sign-on Broken Access Control Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action No login needed ≤ 1.0.19 CVE-2025-7045 Wordfence
8.2 High Cloud SAML SSO Plugin cloud-sso-single-sign-on Broken Access Control Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action No login needed ≤ 1.0.19 CVE-2025-7040 Wordfence
5.9 Medium Search Cloud One Plugin search-cloud-one Cross-Site Scripting ≤ 2.2.5 CVE-2025-58883 Patchstack
6.5 Medium Donation Forms WP by Givecloud Plugin donation-forms-by-givecloud Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-58842 Patchstack
9.8 Critical Cloudflare Image Resizing Plugin cf-image-resizing Remote Code Execution Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook No login needed ≤ 1.5.6 CVE-2025-8723 Wordfence
7.5 High Cloud SAML SSO - Single Sign On Login Plugin cloud-sso-single-sign-on Local File Inclusion Single Sign On Login <= 1.0.18 - Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-49264 Patchstack
6.4 Medium Custom Word Cloud Plugin custom-word-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via angle Parameter ≤ 0.3 CVE-2025-8317 Wordfence
6.4 Medium Mine CloudVod Plugin mine-cloudvod Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via audio Parameter ≤ 2.1.10 CVE-2025-8071 Wordfence
6.4 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes ≤ 3.26 CVE-2025-7035 Wordfence
6.5 Medium CryptoCloud - Crypto Payment Gateway Plugin cryptocloud-crypto-payment-gateway Broken Access Control Crypto Payment Gateway plugin <= 2.1.2 - Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.3.2 CVE-2025-48147 Patchstack
4.3 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation ≤ 4.17.5 CVE-2025-4683 Wordfence
6.5 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Privilege Escalation Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation No login needed ≤ 4.17.4 CVE-2025-3438 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only