WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–50 of 101 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | WPCafe | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete No login needed |
≤ 3.0.19 |
CVE-2026-11601 |
Wordfence | |
| 4.3 Medium | Datalogics Ecommerce Delivery | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping) |
≤ 2.6.65 |
CVE-2026-9613 |
Wordfence | |
| 6.5 Medium | Create | SQL Injection Authenticated (Author+) SQL Injection via 'order' Parameter |
≤ 2.5.3 |
CVE-2026-13200 |
Wordfence | |
| 6.5 Medium | Create | SQL Injection Authenticated (Author+) SQL Injection via 'order_by' Parameter |
≤ 2.5.3 |
CVE-2026-13191 |
Wordfence | |
| 4.3 Medium | PDF Builder for WooCommerce. Create invoices,packing slips and more | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler |
≤ 2.0.11 |
CVE-2026-11899 |
Wordfence | |
| 8.8 High | Save as PDF Plugin by PDFCrowd | Remote Code Execution Authenticated (Contributor+) Arbitrary Function Invocation / Code Injection via 'pdf_created_callback' Shortcode Attribute |
≤ 4.6.1 |
CVE-2026-92807 |
Wordfence | |
| 4.3 Medium | BetterLinks | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action |
≤ 3.1.0 |
CVE-2026-19801 |
Wordfence | |
| 2.7 Low | Content Mask | Privilege Escalation Contributor Publish Capability Bypass via create_new_content_mask |
1.8.0 – < 1.8.5.5 Fixed in 1.8.5.5 |
CVE-2026-77003 |
WPScan | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-18037 |
WPScan | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-16992 |
WPScan | |
| 8.0 High | Create Block | Remote Code Execution Admin+ PHP Code Injection via Pattern Save (Multisite) |
< 2.10.0 Fixed in 2.10.0 |
CVE-2026-16623 |
WPScan | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-13110 |
Wordfence | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-15411 |
Wordfence | |
| 5.3 Medium | Create | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.6.0 Fixed in 2.6.1 |
CVE-2026-65490 |
Patchstack | |
| 8.5 High | Create | SQL Injection |
≤ 2.5.3 Fixed in 2.5.4 |
CVE-2026-24552 |
Patchstack | |
| 4.3 Medium | DHL eCommerce (Benelux) for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions |
≤ 2.2.3 |
CVE-2026-9235 |
Wordfence | |
| 7.5 High | LatePoint | Privilege Escalation Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset |
≤ 5.5.1 |
CVE-2026-8176 |
Wordfence | |
| 4.3 Medium | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Price Manipulation WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter |
≤ 4.3.5 |
CVE-2026-7648 |
Wordfence | |
| 6.4 Medium | Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'chartid' Shortcode Attribute |
≤ 2.1.0 |
CVE-2026-4730 |
Wordfence | |
| 9.1 Critical | Create DB Tables | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Table Creation/Deletion via admin-post.php No login needed |
≤ 1.2.1 |
CVE-2026-4119 |
Wordfence | |
| 6.5 Medium | App Builder – Create Native Android & iOS Apps On The Flight | Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter No login needed |
≤ 5.5.10 |
CVE-2026-2375 |
Wordfence | |
| 7.5 High | The Events Calendar | Path Traversal Authenticated (Author+) Arbitrary File Read via ajax_create_import No login needed |
≤ 6.15.17 |
CVE-2026-3585 |
Wordfence | |
| 8.8 High | WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation | Broken Access Control Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation |
≤ 1.4.24 |
CVE-2026-1720 |
Wordfence | |
| 5.3 Medium | Popup Builder - Create highly converting, mobile friendly marketing popups. | Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed |
≤ 4.4.2 |
CVE-2025-13079 |
Wordfence | |
| 6.4 Medium | Popup Box – Easily Create WordPress Popups | Cross-Site Scripting Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.2.12 |
CVE-2025-12122 |
Wordfence | |
| 9.8 Critical | JAY Login & Register | Privilege Escalation Unauthenticated Privilege Escalation via jay_login_register_ajax_create_final_user No login needed |
≤ 2.6.03 |
CVE-2025-15027 |
Wordfence | |
| 6.4 Medium | Interactions – Create Interactive Experiences in the Block Editor | Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-12709 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed |
≤ 2.5.2 |
CVE-2025-13205 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed |
≤ 2.5.2 |
CVE-2025-13194 |
Wordfence | |
| 9.8 Critical | Fox LMS – WordPress LMS | Privilege Escalation WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder' No login needed |
1.0.4.7 – 1.0.5.1 |
CVE-2025-14156 |
Wordfence | |
| 6.4 Medium | Popup Builder – Create highly converting, mobile friendly marketing popups. | Cross-Site Scripting Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.4.1 |
CVE-2025-9856 |
Wordfence | |
| 7.1 High | Create Posts & Terms | Cross-Site Request Forgery No login needed |
≤ 1.3.1 |
CVE-2025-49351 |
Patchstack | |
| 7.1 High | Image Gallery block – Create and display photo gallery/photo album. | Authentication Bypass Create and display photo gallery/photo album. plugin <= 1.0.7 - Broken Authentication |
≤ 1.0.7 Fixed in 2.0.0 |
CVE-2025-49394 |
Patchstack | |
| 5.3 Medium | User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | Broken Access Control Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure No login needed |
≤ 1.8.0 |
CVE-2025-10694 |
Wordfence | |
| 8.8 High | WPBifröst – Instant Passwordless Temporary Login Links | Broken Access Control Instant Passwordless Temporary Login Links <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation |
≤ 1.0.7 |
CVE-2025-10299 |
Wordfence | |
| 4.3 Medium | MPWizard – Create Mercado Pago Payment Links | Cross-Site Request Forgery Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion No login needed |
≤ 1.2.1 |
CVE-2025-9885 |
Wordfence | |
| 9.8 Critical | Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition | Authentication Bypass Unauthenticated Login Token Generation to Authentication Bypass No login needed |
≤ 4.03.32 |
CVE-2025-6441 |
Wordfence | |
| 4.3 Medium | Real Estate Property 2024 Create Your Own Fields and Search Bar WP | Broken Access Control |
≤ 4.48 Fixed in 4.49 |
CVE-2025-48150 |
Patchstack | |
| 8.8 High | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager | Cross-Site Request Forgery Multi-Purpose WordPress Advertising Manager <= 4.89 - Cross-Site Request Forgery to PHP Code Injection in bsaCreateAdTemplate No login needed |
≤ 4.89 |
CVE-2025-6459 |
Wordfence | |
| 4.3 Medium | Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes | Broken Access Control |
≤ 1.0.10 |
CVE-2025-49973 |
Patchstack | |
| 4.3 Medium | Atelier Create CV | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.1.5 |
CVE-2025-49439 |
Patchstack | |
| 4.3 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation |
≤ 4.17.5 |
CVE-2025-4683 |
Wordfence | |
| 5.4 Medium | EKC Tournament Manager | Cross-Site Request Forgery Create Tournaments/Teams via CSRF |
< 2.2.2 Fixed in 2.2.2 |
CVE-2024-9709 |
WPScan | |
| 8.8 High | SMS Alert Order Notifications – WooCommerce | Privilege Escalation WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function |
≤ 3.8.1 |
CVE-2025-3876 |
Wordfence | |
| 6.5 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Privilege Escalation Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation No login needed |
≤ 4.17.4 |
CVE-2025-3438 |
Wordfence | |
| 4.3 Medium | Simple Sitemap – Create a Responsive HTML Sitemap | Broken Access Control Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Control |
≤ 3.6.0 Fixed in 3.6.1 |
CVE-2025-39413 |
Patchstack | |
| 7.3 High | Create custom forms for WordPress with a smart form plugin for smart businesses | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.4 |
CVE-2025-2801 |
Wordfence | |
| 7.5 High | Greek Multi Tool – Fix peralinks, accents, auto create menus and more | Broken Access Control Fix peralinks, accents, auto create menus and more plugin <= 2.3.1 - Broken Access Control No login needed |
≤ 2.3.1 Fixed in 2.3.2 |
CVE-2025-30797 |
Patchstack | |
| 5.3 Medium | Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More | Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 2.5.0 |
CVE-2024-11153 |
Wordfence | |
| 8.8 High | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile |
≤ 1.12.17 |
CVE-2024-12544 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.