WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 55 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Broken Access Control No login needed ≤ 2.17.1 CVE-2026-39762 Patchstack
6.5 Medium App for Cloudflare® Plugin app-for-cf Broken Access Control ≤ 1.10.1 CVE-2026-39749 Patchstack
6.5 Medium Simple CAPTCHA with Cloudflare Turnstile Plugin simple-cloudflare-turnstile Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Contact Form 7 Field Repopulation No login needed 1.2.2 – < 1.42.3 Fixed in 1.42.3 CVE-2026-85116 WPScan
5.6 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Authentication Bypass Captcha Bypass No login needed ≤ 1.42.1 Fixed in 1.42.3 CVE-2026-66674 Patchstack
6.5 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Content Injection No login needed ≤ 1.42.1 Fixed in 1.42.3 CVE-2026-66632 Patchstack
5.3 Medium Simple CAPTCHA with Cloudflare Turnstile Plugin simple-cloudflare-turnstile Other Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key No login needed < 1.42.0 Fixed in 1.42.0 CVE-2026-15239 WPScan
6.5 Medium Templately Plugin templately Broken Access Control Unauthenticated Administrator Templately Cloud Connection Overwrite No login needed < 3.7.1 Fixed in 3.7.1 CVE-2026-15359 WPScan
6.5 Medium pCloud WP Backup Plugin pcloud-wp-backup Broken Access Control Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read ≤ 2.0.3 CVE-2026-14503 Wordfence
5.3 Medium Sendcloud Shipping Plugin sendcloud-connected-shipping Broken Access Control No login needed ≤ 1.0.29 CVE-2026-57760 Patchstack
5.8 Medium Simple Cloudflare Turnstile Plugin simple-cloudflare-turnstile Authentication Bypass Broken Authentication No login needed ≤ 1.38.0 Fixed in 1.38.1 CVE-2026-40799 Patchstack
4.3 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo Broken Access Control Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations ≤ 12.4.16 CVE-2026-7624 Wordfence
4.3 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Broken Access Control ≤ 2.14.0 CVE-2026-24527 Patchstack
5.3 Medium Mailercloud – Integrate webforms and synchronize website contacts Plugin mailercloud-integrate-webforms-synchronize-contacts Broken Access Control Integrate webforms and synchronize website contacts plugin <= 1.0.7 - Broken Access Control No login needed ≤ 1.0.7 CVE-2026-39713 Patchstack
6.5 Medium Cool Tag Cloud Plugin cool-tag-cloud Cross-Site Scripting ≤ 2.29 CVE-2025-69011 Patchstack
4.3 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection ≤ 12.4.14 CVE-2025-14342 Wordfence
4.3 Medium Code Snippets Plugin code-snippets Cross-Site Request Forgery Cross-Site Request Forgery to Cloud Snippet Download/Update Actions No login needed ≤ 3.9.4 CVE-2026-1785 Wordfence
5.4 Medium Cloudinary Plugin cloudinary-image-management-and-manipulation-in-the-cloud-cdn Broken Access Control ≤ 3.3.2 CVE-2026-24560 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
6.5 Medium BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control ≤ 4.6.7 Fixed in 4.7.1 CVE-2025-69024 Patchstack
6.5 Medium Offload, AI & Optimize with Cloudflare Images Plugin cf-images Broken Access Control ≤ 1.9.5 Fixed in 1.9.6 CVE-2025-66104 Patchstack
5.3 Medium Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed ≤ 2.3.8 CVE-2025-10304 Wordfence
6.5 Medium tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.2 CVE-2025-62032 Patchstack
6.4 Medium Listeo Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode ≤ 2.0.8 CVE-2025-8413 Wordfence
4.3 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin wdesignkit Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function ≤ 1.2.16 CVE-2025-9029 Wordfence
6.5 Medium Cloud SAML SSO Plugin cloud-sso-single-sign-on Broken Access Control Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action No login needed ≤ 1.0.19 CVE-2025-7045 Wordfence
5.9 Medium Search Cloud One Plugin search-cloud-one Cross-Site Scripting ≤ 2.2.5 CVE-2025-58883 Patchstack
6.5 Medium Donation Forms WP by Givecloud Plugin donation-forms-by-givecloud Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-58842 Patchstack
6.4 Medium Custom Word Cloud Plugin custom-word-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via angle Parameter ≤ 0.3 CVE-2025-8317 Wordfence
6.4 Medium Mine CloudVod Plugin mine-cloudvod Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via audio Parameter ≤ 2.1.10 CVE-2025-8071 Wordfence
6.4 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes ≤ 3.26 CVE-2025-7035 Wordfence
6.5 Medium CryptoCloud - Crypto Payment Gateway Plugin cryptocloud-crypto-payment-gateway Broken Access Control Crypto Payment Gateway plugin <= 2.1.2 - Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.3.2 CVE-2025-48147 Patchstack
4.3 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation ≤ 4.17.5 CVE-2025-4683 Wordfence
6.5 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Privilege Escalation Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation No login needed ≤ 4.17.4 CVE-2025-3438 Wordfence
6.5 Medium Mixcloud Embed Plugin mixcloud-embed Cross-Site Scripting ≤ 2.2.0 CVE-2025-46501 Patchstack
4.3 Medium Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Order Information Disclosure ≤ 4.1 CVE-2025-1284 Wordfence
5.3 Medium Cart66 Cloud Plugin cart66-cloud Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.3.7 CVE-2025-2841 Wordfence
4.3 Medium Printus Plugin printus-cloud-printing-for-woocommerce Broken Access Control ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-31830 Patchstack
4.3 Medium pCloud Backup Plugin pcloud-backup Broken Access Control ≤ 1.0.1 CVE-2025-31755 Patchstack
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
4.3 Medium SoundCloud Ultimate Plugin soundcloud-ultimate Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30542 Patchstack
6.5 Medium List Mixcloud Plugin list-mixcloud Cross-Site Scripting ≤ 1.4 CVE-2025-28930 Patchstack
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting ≤ 2.8.0.1 Fixed in 2.8.1 CVE-2025-26878 Patchstack
6.4 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.0 CVE-2024-13461 Wordfence
4.3 Medium Soundcloud Is Gold Plugin soundcloud-is-gold Broken Access Control ≤ 2.5.1 CVE-2023-32586 Patchstack
5.4 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) ≤ 4.16.4 CVE-2024-12042 Wordfence
4.3 Medium Child Theme Creator by Orbisius Plugin orbisius-child-theme-creator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Snippet Update/Delete ≤ 1.5.5 CVE-2024-12263 Wordfence
5.4 Medium tencentcloud-cos Plugin tencentcloud-cos Broken Access Control ≤ 1.0.7 CVE-2023-29433 Patchstack
4.3 Medium Dollie Hub – Build Your Own WordPress Cloud Platform Plugin Information Disclosure Build Your Own WordPress Cloud Platform <= 6.2.0 - Authenticated (Contributor+) Post Disclosure ≤ 6.2.0 CVE-2024-12099 Wordfence
6.4 Medium LegalWeb Cloud Plugin legalweb-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.2 CVE-2024-11761 Wordfence
6.1 Medium 2D Tag Cloud Plugin 2d-tag-cloud-widget-by-sujin Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 6.0.2 CVE-2024-9670 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only