WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–39 of 39 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Magic Tooltips For Contact Form 7 Plugin magic-tooltips-for-contact-form-7 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'esc_html' Filter Override via Comment Author No login needed ≤ 1.0.34 CVE-2026-101928 Wordfence
7.2 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 PHP Object Injection ≤ 3.5.51 Fixed in 3.5.52 CVE-2026-96833 Patchstack
7.1 High Calculation For Contact Form 7 Plugin calculation-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0 Fixed in 1.1 CVE-2026-81300 Patchstack
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated RCE via Control Character Filename Bypass No login needed < 1.3.9.9 Fixed in 1.3.9.9 CVE-2026-18781 WPScan
7.5 High Track Geolocation Of Users Using Contact Form 7 Plugin track-geolocation-of-users-using-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.2 CVE-2026-73386 Patchstack
7.5 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.4 CVE-2026-73384 Patchstack
7.1 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting No login needed ≤ 3.5.45 Fixed in 3.5.46 CVE-2026-65439 Patchstack
7.5 High Post My CF7 Form Plugin post-my-contact-form-7 Broken Access Control No login needed ≤ 6.2.0 Fixed in 7.0.0 CVE-2026-59534 Patchstack
7.2 High Connect Contact Form 7 and Mailchimp Plugin contact-form-7-mailchimp-extension Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values No login needed ≤ 0.9.78.06 CVE-2026-15000 Wordfence
7.1 High Drag and Drop Multiple File Upload – Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Contact Form 7 plugin <= 1.3.9.7 - Cross Site Scripting (XSS) No login needed ≤ 1.3.9.7 Fixed in 1.3.9.8 CVE-2026-49055 Patchstack
8.1 High WP Contact Form 7 DB Handler Plugin wp-contact-form-7-db-handler Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion via 'contact_form' Parameter No login needed ≤ 3.0 CVE-2026-6455 Wordfence
8.1 High Drag and Drop File Upload for Contact Form 7 Plugin drag-and-drop-file-upload-for-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via sanitize_file_name Bypass No login needed ≤ 1.1.3 CVE-2026-5364 Wordfence
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via Non-ASCII Filename Blacklist Bypass No login needed ≤ 1.3.9.7 CVE-2026-5718 Wordfence
7.5 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Limited Arbitrary File Read via mfile Field No login needed ≤ 1.3.9.6 CVE-2026-5710 Wordfence
7.2 High Spam Protect for Contact Form 7 Plugin wp-contact-form-7-spam-blocker Remote Code Execution Editor+ Remote Code Execution < 1.2.10 Fixed in 1.2.10 CVE-2026-1540 WPScan
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.3.9.5 CVE-2026-3459 Wordfence
8.8 High PDF for Contact Form 7 Plugin pdf-for-contact-form-7 PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60081 Patchstack
7.1 High Billplz Addon for Contact Form 7 Plugin billplz-for-contact-form-7 Cross-Site Scripting No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-31007 Patchstack
7.1 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2025-52777 Patchstack
8.2 High Abandoned Contact Form 7 Plugin abandoned-contact-form-7 Broken Access Control No login needed ≤ 2.2 CVE-2025-52817 Patchstack
7.2 High Ultra Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Database module No login needed 3.5.11 – 3.5.19 CVE-2025-6212 Wordfence
7.2 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload via 'save_options' ≤ 3.5.12 CVE-2025-6220 Wordfence
8.1 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Upload via Insufficient Blacklist Checks No login needed ≤ 1.3.8.9 CVE-2025-3515 Wordfence
7.6 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 SQL Injection ≤ 1.0.4 CVE-2025-32126 Patchstack
7.5 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated PHP Object Injection via PHAR to Arbitrary File Deletion No login needed ≤ 1.3.8.8 CVE-2025-2485 Wordfence
8.8 High Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Arbitrary File Upload Unauthenticated Arbitrary File Deletion No login needed ≤ 1.3.8.7 CVE-2025-2328 Wordfence
7.1 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-23812 Patchstack
7.6 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution SQL Injection ≤ 1.2.1 CVE-2025-23784 Patchstack
7.5 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Broken Access Control No login needed ≤ 3.2.6 Fixed in 3.2.7 CVE-2023-47693 Patchstack
7.1 High Connect Contact Form 7 to Constant Contact Plugin connect-contact-form-7-to-constant-contact-v3 Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 Fixed in 1.5 CVE-2024-54343 Patchstack
7.3 High WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Plugin wpb-popup-for-contact-form-7 Arbitrary Shortcode Execution Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form No login needed ≤ 1.7.5 CVE-2024-11038 Wordfence
7.1 High Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 Fixed in 2.3.1 CVE-2024-48021 Patchstack
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 4.1.2 CVE-2024-6317 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 4.1.2 CVE-2024-6316 Wordfence
7.2 High Frontend Registration – Contact Form 7 Plugin frontend-registration-contact-form-7 Privilege Escalation Contact Form 7 <= 5.1 - Authenticated (Editor+) Privilege Escalation ≤ 5.1 CVE-2024-4870 Wordfence
7.1 High Contact Form 7 Newsletter Plugin contact-form-7-newsletter Cross-Site Scripting No login needed ≤ 2.2 CVE-2024-31110 Patchstack
7.1 High Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 Fixed in 2.1 CVE-2024-29130 Patchstack
7.1 High Sitepact Plugin sitepact-klaviyo-contact-form-7 SQL Injection WordPress Sitepact's Contact Form 7 Extension For Klaviyo Plugin <= 1.0.5 is vulnerable to SQL Injection No login needed ≤ 1.0.5 Fixed in 3.0.0 CVE-2024-25928 Patchstack
7.2 High Admin side data storage for Contact Form 7 Plugin admin-side-data-storage-for-contact-form-7 SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.1.1 CVE-2024-1776 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only