WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–50 of 90 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Autoship Cloud for WooCommerce Subscription Products | Broken Access Control No login needed |
≤ 2.17.1 |
CVE-2026-39762 |
Patchstack | |
| 6.5 Medium | App for Cloudflare® | Broken Access Control |
≤ 1.10.1 |
CVE-2026-39749 |
Patchstack | |
| 8.8 High | WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import |
2.0 – 3.8.3 |
CVE-2026-93031 |
Wordfence | |
| 8.6 High | Yogeta WP Cloud | Path Traversal Unauthenticated Arbitrary File Download No login needed |
≤ 1.0 |
CVE-2026-80494 |
WPScan | |
| 6.5 Medium | Simple CAPTCHA with Cloudflare Turnstile | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation No login needed |
1.2.2 – < 1.42.3 Fixed in 1.42.3 |
CVE-2026-85116 |
WPScan | |
| 5.6 Medium | Simple Cloudflare Turnstile | Authentication Bypass Captcha Bypass No login needed |
≤ 1.42.1 Fixed in 1.42.3 |
CVE-2026-66674 |
Patchstack | |
| 6.5 Medium | Simple Cloudflare Turnstile | Content Injection No login needed |
≤ 1.42.1 Fixed in 1.42.3 |
CVE-2026-66632 |
Patchstack | |
| 8.8 High | Templately | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch |
≤ 3.7.1 |
CVE-2026-18438 |
Wordfence | |
| 5.3 Medium | Simple CAPTCHA with Cloudflare Turnstile | Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed |
< 1.42.0 Fixed in 1.42.0 |
CVE-2026-15239 |
WPScan | |
| 6.5 Medium | Templately | Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2026-15359 |
WPScan | |
| 6.5 Medium | pCloud WP Backup | Broken Access Control Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read |
≤ 2.0.3 |
CVE-2026-14503 |
Wordfence | |
| 7.1 High | tagDiv Cloud Library | Cross-Site Scripting No login needed |
≤ 3.9.4 |
CVE-2026-57733 |
Patchstack | |
| 5.3 Medium | Sendcloud Shipping | Broken Access Control No login needed |
≤ 1.0.29 |
CVE-2026-57760 |
Patchstack | |
| 7.1 High | pCloud WP Backup | Cross-Site Request Forgery No login needed |
≤ 2.0.2 |
CVE-2026-57757 |
Patchstack | |
| 8.8 High | Offload, AI & Optimize with Cloudflare Images | Remote Code Execution Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action |
≤ 1.10.2 |
CVE-2026-9860 |
Wordfence | |
| 8.1 High | CloudSecure WP Security | Authentication Bypass Broken Authentication No login needed |
≤ 1.4.7 Fixed in 1.4.8 |
CVE-2026-42411 |
Patchstack | |
| 5.8 Medium | Simple Cloudflare Turnstile | Authentication Bypass Broken Authentication No login needed |
≤ 1.38.0 Fixed in 1.38.1 |
CVE-2026-40799 |
Patchstack | |
| 4.3 Medium | SEO Plugin by Squirrly SEO | Broken Access Control Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations |
≤ 12.4.16 |
CVE-2026-7624 |
Wordfence | |
| 7.2 High | LiteSpeed Cache | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints No login needed |
≤ 7.7 |
CVE-2026-3375 |
Wordfence | |
| 4.3 Medium | Autoship Cloud for WooCommerce Subscription Products | Broken Access Control |
≤ 2.14.0 |
CVE-2026-24527 |
Patchstack | |
| 5.3 Medium | Mailercloud – Integrate webforms and synchronize website contacts | Broken Access Control Integrate webforms and synchronize website contacts plugin <= 1.0.7 - Broken Access Control No login needed |
≤ 1.0.7 |
CVE-2026-39713 |
Patchstack | |
| 8.1 High | CloudMe | Local File Inclusion No login needed |
≤ 1.2.2 |
CVE-2026-22433 |
Patchstack | |
| 6.5 Medium | Cool Tag Cloud | Cross-Site Scripting |
≤ 2.29 |
CVE-2025-69011 |
Patchstack | |
| 4.3 Medium | SEO Plugin by Squirrly SEO | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection |
≤ 12.4.14 |
CVE-2025-14342 |
Wordfence | |
| 7.2 High | Super Page Cache | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Activity Log No login needed |
≤ 5.2.2 |
CVE-2026-1843 |
Wordfence | |
| 4.3 Medium | Code Snippets | Cross-Site Request Forgery Cross-Site Request Forgery to Cloud Snippet Download/Update Actions No login needed |
≤ 3.9.4 |
CVE-2026-1785 |
Wordfence | |
| 5.4 Medium | Cloudinary | Broken Access Control |
≤ 3.3.2 |
CVE-2026-24560 |
Patchstack | |
| 6.5 Medium | TaxCloud for WooCommerce | Broken Access Control No login needed |
≤ 8.3.8 Fixed in 8.4.0 |
CVE-2025-67958 |
Patchstack | |
| 7.1 High | SensitiveTagCloud | Cross-Site Request Forgery No login needed |
≤ 1.4.1 |
CVE-2025-49344 |
Patchstack | |
| 6.5 Medium | BizPrint | Broken Access Control |
≤ 4.6.7 Fixed in 4.7.1 |
CVE-2025-69024 |
Patchstack | |
| 6.5 Medium | Offload, AI & Optimize with Cloudflare Images | Broken Access Control |
≤ 1.9.5 Fixed in 1.9.6 |
CVE-2025-66104 |
Patchstack | |
| 8.1 High | Cool Tag Cloud | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.29 |
CVE-2025-13614 |
Wordfence | |
| 5.3 Medium | Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning | Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed |
≤ 2.3.8 |
CVE-2025-10304 |
Wordfence | |
| 6.5 Medium | tagDiv Cloud Library | Cross-Site Scripting |
≤ 3.9.2 Fixed in 3.9.2 |
CVE-2025-62032 |
Patchstack | |
| 7.1 High | CloudSearch | Cross-Site Request Forgery No login needed |
≤ 3.0.0 |
CVE-2025-62962 |
Patchstack | |
| 6.4 Medium | Listeo | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode |
≤ 2.0.8 |
CVE-2025-8413 |
Wordfence | |
| 4.3 Medium | WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder | Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function |
≤ 1.2.16 |
CVE-2025-9029 |
Wordfence | |
| 7.1 High | W3SCloud Contact Form 7 to Zoho CRM | Cross-Site Request Forgery No login needed |
≤ 3.2 |
CVE-2025-60169 |
Patchstack | |
| 6.5 Medium | Cloud SAML SSO | Broken Access Control Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action No login needed |
≤ 1.0.19 |
CVE-2025-7045 |
Wordfence | |
| 8.2 High | Cloud SAML SSO | Broken Access Control Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action No login needed |
≤ 1.0.19 |
CVE-2025-7040 |
Wordfence | |
| 5.9 Medium | Search Cloud One | Cross-Site Scripting |
≤ 2.2.5 |
CVE-2025-58883 |
Patchstack | |
| 6.5 Medium | Donation Forms WP by Givecloud | Cross-Site Scripting |
≤ 1.0.9 Fixed in 1.0.10 |
CVE-2025-58842 |
Patchstack | |
| 9.8 Critical | Cloudflare Image Resizing | Remote Code Execution Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook No login needed |
≤ 1.5.6 |
CVE-2025-8723 |
Wordfence | |
| 7.5 High | Cloud SAML SSO - Single Sign On Login | Local File Inclusion Single Sign On Login <= 1.0.18 - Local File Inclusion No login needed |
≤ 1.0.18 Fixed in 1.0.19 |
CVE-2025-49264 |
Patchstack | |
| 6.4 Medium | Custom Word Cloud | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via angle Parameter |
≤ 0.3 |
CVE-2025-8317 |
Wordfence | |
| 6.4 Medium | Mine CloudVod | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via audio Parameter |
≤ 2.1.10 |
CVE-2025-8071 |
Wordfence | |
| 6.4 Medium | Media Library Assistant | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes |
≤ 3.26 |
CVE-2025-7035 |
Wordfence | |
| 6.5 Medium | CryptoCloud - Crypto Payment Gateway | Broken Access Control Crypto Payment Gateway plugin <= 2.1.2 - Broken Access Control No login needed |
≤ 2.1.2 Fixed in 2.3.2 |
CVE-2025-48147 |
Patchstack | |
| 4.3 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation |
≤ 4.17.5 |
CVE-2025-4683 |
Wordfence | |
| 6.5 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Privilege Escalation Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation No login needed |
≤ 4.17.4 |
CVE-2025-3438 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.