WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–50 of 55 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Autoship Cloud for WooCommerce Subscription Products | Broken Access Control No login needed |
≤ 2.17.1 |
CVE-2026-39762 |
Patchstack | |
| 6.5 Medium | App for Cloudflare® | Broken Access Control |
≤ 1.10.1 |
CVE-2026-39749 |
Patchstack | |
| 6.5 Medium | Simple CAPTCHA with Cloudflare Turnstile | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation No login needed |
1.2.2 – < 1.42.3 Fixed in 1.42.3 |
CVE-2026-85116 |
WPScan | |
| 5.6 Medium | Simple Cloudflare Turnstile | Authentication Bypass Captcha Bypass No login needed |
≤ 1.42.1 Fixed in 1.42.3 |
CVE-2026-66674 |
Patchstack | |
| 6.5 Medium | Simple Cloudflare Turnstile | Content Injection No login needed |
≤ 1.42.1 Fixed in 1.42.3 |
CVE-2026-66632 |
Patchstack | |
| 5.3 Medium | Simple CAPTCHA with Cloudflare Turnstile | Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed |
< 1.42.0 Fixed in 1.42.0 |
CVE-2026-15239 |
WPScan | |
| 6.5 Medium | Templately | Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed |
< 3.7.1 Fixed in 3.7.1 |
CVE-2026-15359 |
WPScan | |
| 6.5 Medium | pCloud WP Backup | Broken Access Control Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read |
≤ 2.0.3 |
CVE-2026-14503 |
Wordfence | |
| 5.3 Medium | Sendcloud Shipping | Broken Access Control No login needed |
≤ 1.0.29 |
CVE-2026-57760 |
Patchstack | |
| 5.8 Medium | Simple Cloudflare Turnstile | Authentication Bypass Broken Authentication No login needed |
≤ 1.38.0 Fixed in 1.38.1 |
CVE-2026-40799 |
Patchstack | |
| 4.3 Medium | SEO Plugin by Squirrly SEO | Broken Access Control Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations |
≤ 12.4.16 |
CVE-2026-7624 |
Wordfence | |
| 4.3 Medium | Autoship Cloud for WooCommerce Subscription Products | Broken Access Control |
≤ 2.14.0 |
CVE-2026-24527 |
Patchstack | |
| 5.3 Medium | Mailercloud – Integrate webforms and synchronize website contacts | Broken Access Control Integrate webforms and synchronize website contacts plugin <= 1.0.7 - Broken Access Control No login needed |
≤ 1.0.7 |
CVE-2026-39713 |
Patchstack | |
| 6.5 Medium | Cool Tag Cloud | Cross-Site Scripting |
≤ 2.29 |
CVE-2025-69011 |
Patchstack | |
| 4.3 Medium | SEO Plugin by Squirrly SEO | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection |
≤ 12.4.14 |
CVE-2025-14342 |
Wordfence | |
| 4.3 Medium | Code Snippets | Cross-Site Request Forgery Cross-Site Request Forgery to Cloud Snippet Download/Update Actions No login needed |
≤ 3.9.4 |
CVE-2026-1785 |
Wordfence | |
| 5.4 Medium | Cloudinary | Broken Access Control |
≤ 3.3.2 |
CVE-2026-24560 |
Patchstack | |
| 6.5 Medium | TaxCloud for WooCommerce | Broken Access Control No login needed |
≤ 8.3.8 Fixed in 8.4.0 |
CVE-2025-67958 |
Patchstack | |
| 6.5 Medium | BizPrint | Broken Access Control |
≤ 4.6.7 Fixed in 4.7.1 |
CVE-2025-69024 |
Patchstack | |
| 6.5 Medium | Offload, AI & Optimize with Cloudflare Images | Broken Access Control |
≤ 1.9.5 Fixed in 1.9.6 |
CVE-2025-66104 |
Patchstack | |
| 5.3 Medium | Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning | Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed |
≤ 2.3.8 |
CVE-2025-10304 |
Wordfence | |
| 6.5 Medium | tagDiv Cloud Library | Cross-Site Scripting |
≤ 3.9.2 Fixed in 3.9.2 |
CVE-2025-62032 |
Patchstack | |
| 6.4 Medium | Listeo | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode |
≤ 2.0.8 |
CVE-2025-8413 |
Wordfence | |
| 4.3 Medium | WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder | Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function |
≤ 1.2.16 |
CVE-2025-9029 |
Wordfence | |
| 6.5 Medium | Cloud SAML SSO | Broken Access Control Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action No login needed |
≤ 1.0.19 |
CVE-2025-7045 |
Wordfence | |
| 5.9 Medium | Search Cloud One | Cross-Site Scripting |
≤ 2.2.5 |
CVE-2025-58883 |
Patchstack | |
| 6.5 Medium | Donation Forms WP by Givecloud | Cross-Site Scripting |
≤ 1.0.9 Fixed in 1.0.10 |
CVE-2025-58842 |
Patchstack | |
| 6.4 Medium | Custom Word Cloud | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via angle Parameter |
≤ 0.3 |
CVE-2025-8317 |
Wordfence | |
| 6.4 Medium | Mine CloudVod | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via audio Parameter |
≤ 2.1.10 |
CVE-2025-8071 |
Wordfence | |
| 6.4 Medium | Media Library Assistant | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes |
≤ 3.26 |
CVE-2025-7035 |
Wordfence | |
| 6.5 Medium | CryptoCloud - Crypto Payment Gateway | Broken Access Control Crypto Payment Gateway plugin <= 2.1.2 - Broken Access Control No login needed |
≤ 2.1.2 Fixed in 2.3.2 |
CVE-2025-48147 |
Patchstack | |
| 4.3 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation |
≤ 4.17.5 |
CVE-2025-4683 |
Wordfence | |
| 6.5 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Privilege Escalation Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation No login needed |
≤ 4.17.4 |
CVE-2025-3438 |
Wordfence | |
| 6.5 Medium | Mixcloud Embed | Cross-Site Scripting |
≤ 2.2.0 |
CVE-2025-46501 |
Patchstack | |
| 4.3 Medium | Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Order Information Disclosure |
≤ 4.1 |
CVE-2025-1284 |
Wordfence | |
| 5.3 Medium | Cart66 Cloud | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 2.3.7 |
CVE-2025-2841 |
Wordfence | |
| 4.3 Medium | Printus | Broken Access Control |
≤ 1.2.6 Fixed in 1.2.7 |
CVE-2025-31830 |
Patchstack | |
| 4.3 Medium | pCloud Backup | Broken Access Control |
≤ 1.0.1 |
CVE-2025-31755 |
Patchstack | |
| 6.4 Medium | WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder | Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.3 |
CVE-2024-12189 |
Wordfence | |
| 4.3 Medium | SoundCloud Ultimate | Cross-Site Request Forgery No login needed |
≤ 1.5 |
CVE-2025-30542 |
Patchstack | |
| 6.5 Medium | List Mixcloud | Cross-Site Scripting |
≤ 1.4 |
CVE-2025-28930 |
Patchstack | |
| 6.5 Medium | Autoship Cloud for WooCommerce Subscription Products | Cross-Site Scripting |
≤ 2.8.0.1 Fixed in 2.8.1 |
CVE-2025-26878 |
Patchstack | |
| 6.4 Medium | Autoship Cloud for WooCommerce Subscription Products | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.8.0 |
CVE-2024-13461 |
Wordfence | |
| 4.3 Medium | Soundcloud Is Gold | Broken Access Control |
≤ 2.5.1 |
CVE-2023-32586 |
Patchstack | |
| 5.4 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) |
≤ 4.16.4 |
CVE-2024-12042 |
Wordfence | |
| 4.3 Medium | Child Theme Creator by Orbisius | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Snippet Update/Delete |
≤ 1.5.5 |
CVE-2024-12263 |
Wordfence | |
| 5.4 Medium | tencentcloud-cos | Broken Access Control |
≤ 1.0.7 |
CVE-2023-29433 |
Patchstack | |
| 4.3 Medium | Dollie Hub – Build Your Own WordPress Cloud Platform | Information Disclosure Build Your Own WordPress Cloud Platform <= 6.2.0 - Authenticated (Contributor+) Post Disclosure |
≤ 6.2.0 |
CVE-2024-12099 |
Wordfence | |
| 6.4 Medium | LegalWeb Cloud | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.2 |
CVE-2024-11761 |
Wordfence | |
| 6.1 Medium | 2D Tag Cloud | Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed |
≤ 6.0.2 |
CVE-2024-9670 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.