WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 101 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WPCafe Plugin wp-cafe Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete No login needed ≤ 3.0.19 CVE-2026-11601 Wordfence
4.3 Medium Datalogics Ecommerce Delivery Plugin datalogics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping) ≤ 2.6.65 CVE-2026-9613 Wordfence
6.5 Medium Create Plugin mediavine-create SQL Injection Authenticated (Author+) SQL Injection via 'order' Parameter ≤ 2.5.3 CVE-2026-13200 Wordfence
6.5 Medium Create Plugin mediavine-create SQL Injection Authenticated (Author+) SQL Injection via 'order_by' Parameter ≤ 2.5.3 CVE-2026-13191 Wordfence
4.3 Medium PDF Builder for WooCommerce. Create invoices,packing slips and more Plugin woo-pdf-invoice-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler ≤ 2.0.11 CVE-2026-11899 Wordfence
8.8 High Save as PDF Plugin by PDFCrowd Plugin save-as-pdf-by-pdfcrowd Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute ≤ 4.6.1 CVE-2026-92807 Wordfence
4.3 Medium BetterLinks Plugin betterlinks Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action ≤ 3.1.0 CVE-2026-19801 Wordfence
2.7 Low Content Mask Plugin content-mask Privilege Escalation Contributor Publish Capability Bypass via create_new_content_mask 1.8.0 – < 1.8.5.5 Fixed in 1.8.5.5 CVE-2026-77003 WPScan
6.5 Medium Create by Mediavine Plugin Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed < 2.5.4 Fixed in 2.5.4 CVE-2026-18037 WPScan
6.5 Medium Create by Mediavine Plugin Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed < 2.5.4 Fixed in 2.5.4 CVE-2026-16992 WPScan
8.0 High Create Block Plugin Remote Code Execution Admin+ PHP Code Injection via Pattern Save (Multisite) < 2.10.0 Fixed in 2.10.0 CVE-2026-16623 WPScan
5.3 Medium StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action No login needed ≤ 2.1.0 CVE-2026-13110 Wordfence
5.3 Medium StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action No login needed ≤ 2.1.0 CVE-2026-15411 Wordfence
5.3 Medium Create Plugin mediavine-create Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-65490 Patchstack
8.5 High Create Plugin mediavine-create SQL Injection ≤ 2.5.3 Fixed in 2.5.4 CVE-2026-24552 Patchstack
4.3 Medium DHL eCommerce (Benelux) for WooCommerce Plugin dhlpwc Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions ≤ 2.2.3 CVE-2026-9235 Wordfence
7.5 High LatePoint Plugin latepoint Privilege Escalation Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset ≤ 5.5.1 CVE-2026-8176 Wordfence
4.3 Medium LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Plugin learnpress Price Manipulation WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter ≤ 4.3.5 CVE-2026-7648 Wordfence
6.4 Medium Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website Plugin charts-ninja-graphs-and-charts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'chartid' Shortcode Attribute ≤ 2.1.0 CVE-2026-4730 Wordfence
9.1 Critical Create DB Tables Plugin create-db-tables Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php No login needed ≤ 1.2.1 CVE-2026-4119 Wordfence
6.5 Medium App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter No login needed ≤ 5.5.10 CVE-2026-2375 Wordfence
7.5 High The Events Calendar Plugin the-events-calendar Path Traversal Authenticated (Author+) Arbitrary File Read via ajax_create_import No login needed ≤ 6.15.17 CVE-2026-3585 Wordfence
8.8 High WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation Plugin optin Broken Access Control Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.4.24 CVE-2026-1720 Wordfence
5.3 Medium Popup Builder - Create highly converting, mobile friendly marketing popups. Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed ≤ 4.4.2 CVE-2025-13079 Wordfence
6.4 Medium Popup Box – Easily Create WordPress Popups Plugin popup-box Cross-Site Scripting Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.12 CVE-2025-12122 Wordfence
9.8 Critical JAY Login & Register Plugin jay-login-register Privilege Escalation Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user No login needed ≤ 2.6.03 CVE-2025-15027 Wordfence
6.4 Medium Interactions – Create Interactive Experiences in the Block Editor Plugin Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-12709 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed ≤ 2.5.2 CVE-2025-13205 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
9.8 Critical Fox LMS – WordPress LMS Plugin fox-lms Privilege Escalation WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder' No login needed 1.0.4.7 – 1.0.5.1 CVE-2025-14156 Wordfence
6.4 Medium Popup Builder – Create highly converting, mobile friendly marketing popups. Plugin popup-builder Cross-Site Scripting Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.4.1 CVE-2025-9856 Wordfence
7.1 High Create Posts & Terms Plugin create-posts-terms Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-49351 Patchstack
7.1 High Image Gallery block – Create and display photo gallery/photo album. Plugin 3d-image-gallery Authentication Bypass Create and display photo gallery/photo album. plugin <= 1.0.7 - Broken Authentication ≤ 1.0.7 Fixed in 2.0.0 CVE-2025-49394 Patchstack
5.3 Medium User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Plugin userfeedback-lite Broken Access Control Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure No login needed ≤ 1.8.0 CVE-2025-10694 Wordfence
8.8 High WPBifröst – Instant Passwordless Temporary Login Links Plugin create-temporary-login Broken Access Control Instant Passwordless Temporary Login Links <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.7 CVE-2025-10299 Wordfence
4.3 Medium MPWizard – Create Mercado Pago Payment Links Plugin mpwizard Cross-Site Request Forgery Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2025-9885 Wordfence
9.8 Critical Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition Plugin webinar-ignition Authentication Bypass Unauthenticated Login Token Generation to Authentication Bypass No login needed ≤ 4.03.32 CVE-2025-6441 Wordfence
4.3 Medium Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now Broken Access Control ≤ 4.48 Fixed in 4.49 CVE-2025-48150 Patchstack
8.8 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin Cross-Site Request Forgery Multi-Purpose WordPress Advertising Manager <= 4.89 - Cross-Site Request Forgery to PHP Code Injection in bsaCreateAdTemplate No login needed ≤ 4.89 CVE-2025-6459 Wordfence
4.3 Medium Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes Plugin image-sizes-controller Broken Access Control ≤ 1.0.10 CVE-2025-49973 Patchstack
4.3 Medium Atelier Create CV Plugin atelier-create-cv Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.5 CVE-2025-49439 Patchstack
4.3 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation ≤ 4.17.5 CVE-2025-4683 Wordfence
5.4 Medium EKC Tournament Manager Plugin ekc-tournament-manager Cross-Site Request Forgery Create Tournaments/Teams via CSRF < 2.2.2 Fixed in 2.2.2 CVE-2024-9709 WPScan
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Privilege Escalation WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function ≤ 3.8.1 CVE-2025-3876 Wordfence
6.5 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Privilege Escalation Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation No login needed ≤ 4.17.4 CVE-2025-3438 Wordfence
4.3 Medium Simple Sitemap – Create a Responsive HTML Sitemap Plugin simple-sitemap Broken Access Control Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Control ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-39413 Patchstack
7.3 High Create custom forms for WordPress with a smart form plugin for smart businesses Plugin abcsubmit Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.4 CVE-2025-2801 Wordfence
7.5 High Greek Multi Tool – Fix peralinks, accents, auto create menus and more Plugin greek-multi-tool Broken Access Control Fix peralinks, accents, auto create menus and more plugin <= 2.3.1 - Broken Access Control No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-30797 Patchstack
5.3 Medium Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More Plugin content-control Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.5.0 CVE-2024-11153 Wordfence
8.8 High SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile ≤ 1.12.17 CVE-2024-12544 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only