WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–31 of 31 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Media Import 2.0 – 3.8.3 CVE-2026-93031 Wordfence
8.6 High Yogeta WP Cloud Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.0 CVE-2026-80494 WPScan
8.8 High Templately Plugin templately Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload to Remote Code Execution via Gutenberg Cloud Import Attachment Filename Mismatch ≤ 3.7.1 CVE-2026-18438 Wordfence
7.1 High tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2026-57733 Patchstack
7.1 High pCloud WP Backup Plugin pcloud-wp-backup Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2026-57757 Patchstack
8.8 High Offload, AI & Optimize with Cloudflare Images Plugin cf-images Remote Code Execution Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action ≤ 1.10.2 CVE-2026-9860 Wordfence
8.1 High CloudSecure WP Security Plugin cloudsecure-wp-security Authentication Bypass Broken Authentication No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2026-42411 Patchstack
7.2 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via QUIC.cloud CCSS/UCSS REST API Endpoints No login needed ≤ 7.7 CVE-2026-3375 Wordfence
8.1 High CloudMe Theme cloudme Local File Inclusion No login needed ≤ 1.2.2 CVE-2026-22433 Patchstack
7.2 High Super Page Cache Plugin wp-cloudflare-page-cache Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Activity Log No login needed ≤ 5.2.2 CVE-2026-1843 Wordfence
7.1 High SensitiveTagCloud Plugin sensitive-tag-cloud Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-49344 Patchstack
8.1 High Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.29 CVE-2025-13614 Wordfence
7.1 High CloudSearch Plugin cloud-search Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2025-62962 Patchstack
7.1 High W3SCloud Contact Form 7 to Zoho CRM Plugin w3s-cf7-zoho Cross-Site Request Forgery No login needed ≤ 3.2 CVE-2025-60169 Patchstack
8.2 High Cloud SAML SSO Plugin cloud-sso-single-sign-on Broken Access Control Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action No login needed ≤ 1.0.19 CVE-2025-7040 Wordfence
7.5 High Cloud SAML SSO - Single Sign On Login Plugin cloud-sso-single-sign-on Local File Inclusion Single Sign On Login <= 1.0.18 - Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-49264 Patchstack
7.1 High Cart66 Cloud Plugin cart66-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.7 CVE-2025-32653 Patchstack
7.1 High WooCommerce Fattureincloud Plugin woo-fattureincloud Cross-Site Scripting No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-30837 Patchstack
7.1 High WP Colorful Tag Cloud Plugin wp-colorful-tag-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-28865 Patchstack
7.5 High WP Cloud Plugin cloud Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-23819 Patchstack
7.1 High CloudFlare(R) Cache Purge Plugin cloudflare-cache-purge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-22332 Patchstack
7.1 High WordPress Tag Cloud Plugin – Tag Groups Plugin tag-groups Cross-Site Scripting Tag Groups plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-22735 Patchstack
7.5 High Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin everest-backup Information Disclosure WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive Invormation Disclosure via procstat Log No login needed ≤ 2.2.13 CVE-2024-10028 Wordfence
7.3 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration No login needed ≤ 4.15.3 CVE-2024-8269 Wordfence
8.1 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover No login needed ≤ 4.15.2 CVE-2024-7628 Wordfence
7.5 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control No login needed ≤ 4.3.39 Fixed in 4.5.4 CVE-2024-32777 Patchstack
7.1 High WP-Stateless – Google Cloud Storage Plugin wp-stateless Broken Access Control Google Cloud Storage <= 3.4.0 - Missing Authorization to Limited Arbitrary Options Update ≤ 3.4.0 CVE-2024-1385 Wordfence
7.1 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.5.5 Fixed in 4.5.6 CVE-2024-29773 Patchstack
7.1 High Super Page Cache for Cloudflare Plugin wp-cloudflare-page-cache Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-27968 Patchstack
8.1 High Cloudflare Plugin cloudflare Information Disclosure Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users) ≤ 4.12.2 Fixed in 4.12.3 CVE-2024-0212 cloudflare
7.1 High 3D Tag Cloud Plugin cardoza-3d-tag-cloud Cross-Site Request Forgery WordPress 3D Tag Cloud Plugin <= 3.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.8 CVE-2022-41990 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only