WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–50 of 67 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | WPCafe | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Email Notification Flow Read/Create/Update/Delete No login needed |
≤ 3.0.19 |
CVE-2026-11601 |
Wordfence | |
| 4.3 Medium | Datalogics Ecommerce Delivery | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions (datalogics_create_shipping / datalogics_cancel_shipping) |
≤ 2.6.65 |
CVE-2026-9613 |
Wordfence | |
| 6.5 Medium | Create | SQL Injection Authenticated (Author+) SQL Injection via 'order' Parameter |
≤ 2.5.3 |
CVE-2026-13200 |
Wordfence | |
| 6.5 Medium | Create | SQL Injection Authenticated (Author+) SQL Injection via 'order_by' Parameter |
≤ 2.5.3 |
CVE-2026-13191 |
Wordfence | |
| 4.3 Medium | PDF Builder for WooCommerce. Create invoices,packing slips and more | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Invoice Data Disclosure via GetInvoiceDetail AJAX Handler |
≤ 2.0.11 |
CVE-2026-11899 |
Wordfence | |
| 4.3 Medium | BetterLinks | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Short URL Creation via create_fbs_link AJAX Action |
≤ 3.1.0 |
CVE-2026-19801 |
Wordfence | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-18037 |
WPScan | |
| 6.5 Medium | Create by Mediavine | Information Disclosure Unauthenticated Unpublished Content Disclosure and Publication No login needed |
< 2.5.4 Fixed in 2.5.4 |
CVE-2026-16992 |
WPScan | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-13110 |
Wordfence | |
| 5.3 Medium | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action No login needed |
≤ 2.1.0 |
CVE-2026-15411 |
Wordfence | |
| 5.3 Medium | Create | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.6.0 Fixed in 2.6.1 |
CVE-2026-65490 |
Patchstack | |
| 4.3 Medium | DHL eCommerce (Benelux) for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions |
≤ 2.2.3 |
CVE-2026-9235 |
Wordfence | |
| 4.3 Medium | LearnPress – WordPress LMS Plugin for Create and Sell Online Courses | Price Manipulation WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter |
≤ 4.3.5 |
CVE-2026-7648 |
Wordfence | |
| 6.4 Medium | Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'chartid' Shortcode Attribute |
≤ 2.1.0 |
CVE-2026-4730 |
Wordfence | |
| 6.5 Medium | App Builder – Create Native Android & iOS Apps On The Flight | Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.5.10 - Unauthenticated Privilege Escalation via 'role' Parameter No login needed |
≤ 5.5.10 |
CVE-2026-2375 |
Wordfence | |
| 5.3 Medium | Popup Builder - Create highly converting, mobile friendly marketing popups. | Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed |
≤ 4.4.2 |
CVE-2025-13079 |
Wordfence | |
| 6.4 Medium | Popup Box – Easily Create WordPress Popups | Cross-Site Scripting Easily Create WordPress Popups <= 3.2.12 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.2.12 |
CVE-2025-12122 |
Wordfence | |
| 6.4 Medium | Interactions – Create Interactive Experiences in the Block Editor | Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-12709 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed |
≤ 2.5.2 |
CVE-2025-13205 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed |
≤ 2.5.2 |
CVE-2025-13194 |
Wordfence | |
| 6.4 Medium | Popup Builder – Create highly converting, mobile friendly marketing popups. | Cross-Site Scripting Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.4.1 |
CVE-2025-9856 |
Wordfence | |
| 5.3 Medium | User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | Broken Access Control Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure No login needed |
≤ 1.8.0 |
CVE-2025-10694 |
Wordfence | |
| 4.3 Medium | MPWizard – Create Mercado Pago Payment Links | Cross-Site Request Forgery Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion No login needed |
≤ 1.2.1 |
CVE-2025-9885 |
Wordfence | |
| 4.3 Medium | Real Estate Property 2024 Create Your Own Fields and Search Bar WP | Broken Access Control |
≤ 4.48 Fixed in 4.49 |
CVE-2025-48150 |
Patchstack | |
| 4.3 Medium | Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes | Broken Access Control |
≤ 1.0.10 |
CVE-2025-49973 |
Patchstack | |
| 4.3 Medium | Atelier Create CV | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.1.5 |
CVE-2025-49439 |
Patchstack | |
| 4.3 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation |
≤ 4.17.5 |
CVE-2025-4683 |
Wordfence | |
| 5.4 Medium | EKC Tournament Manager | Cross-Site Request Forgery Create Tournaments/Teams via CSRF |
< 2.2.2 Fixed in 2.2.2 |
CVE-2024-9709 |
WPScan | |
| 6.5 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Privilege Escalation Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation No login needed |
≤ 4.17.4 |
CVE-2025-3438 |
Wordfence | |
| 4.3 Medium | Simple Sitemap – Create a Responsive HTML Sitemap | Broken Access Control Create a Responsive HTML Sitemap plugin <= 3.6.0 - Broken Access Control |
≤ 3.6.0 Fixed in 3.6.1 |
CVE-2025-39413 |
Patchstack | |
| 5.3 Medium | Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More | Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 2.5.0 |
CVE-2024-11153 |
Wordfence | |
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update |
≤ 3.4.25 |
CVE-2025-1780 |
Wordfence | |
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update |
≤ 3.4.24 |
CVE-2024-13358 |
Wordfence | |
| 6.1 Medium | Active Products Tables for WooCommerce. Use constructor to create tables | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.6.6 |
CVE-2025-0864 |
Wordfence | |
| 4.3 Medium | Print Barcode Labels for your WooCommerce products/orders | Broken Access Control |
≤ 3.4.10 Fixed in 3.4.11 |
CVE-2025-24603 |
Patchstack | |
| 6.5 Medium | Create with Code | Cross-Site Scripting |
≤ 1.4 Fixed in 1.5 |
CVE-2025-24638 |
Patchstack | |
| 6.4 Medium | Quill Forms | Conversational Multi Step Forms, Surveys & quizzes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.10.0 |
CVE-2024-11826 |
Wordfence | |
| 5.4 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) |
≤ 4.16.4 |
CVE-2024-12042 |
Wordfence | |
| 6.4 Medium | FAQ And Answers – Create Frequently Asked Questions Area on WP Sites | Cross-Site Scripting Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2024-11882 |
Wordfence | |
| 6.1 Medium | PDF Builder for WooCommerce. Create invoices,packing slips and more | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2.136 |
CVE-2024-11276 |
Wordfence | |
| 6.5 Medium | Custom Dashboard Widget | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.0 |
CVE-2024-51860 |
Patchstack | |
| 5.3 Medium | Popup Box – Create Countdown, Coupon, Video, Contact Form Popups | Broken Access Control Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update No login needed |
≤ 4.9.7 |
CVE-2024-10861 |
Wordfence | |
| 4.3 Medium | Content Slider Block – Create fully functional slider with Gutenberg block | Information Disclosure Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure |
≤ 3.1.5 |
CVE-2024-10667 |
Wordfence | |
| 6.4 Medium | Active Products Tables for WooCommerce. Use constructor to create tables | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode |
≤ 1.0.6.4 |
CVE-2024-10168 |
Wordfence | |
| 6.5 Medium | Print Barcode Labels for your WooCommerce products/orders | Broken Access Control |
≤ 3.4.9 Fixed in 3.4.10 |
CVE-2024-43310 |
Patchstack | |
| 4.7 Medium | Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons | Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed |
≤ 2.6.5 |
CVE-2024-8541 |
Wordfence | |
| 5.1 Medium | Create | Cross-Site Scripting |
≤ 2.9.1 Fixed in 2.9.2 |
CVE-2024-47356 |
Patchstack | |
| 4.3 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload |
≤ 4.15.3 |
CVE-2024-8242 |
Wordfence | |
| 5.3 Medium | Create by Mediavine | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.9.8 Fixed in 1.9.9 |
CVE-2024-43264 |
Patchstack | |
| 5.6 Medium | App Builder – Create Native Android & iOS Apps On The Flight | SQL Injection Create Native Android & iOS Apps On The Flight <= 4.3.3 - Unauthenticated Limited SQL Injection via app-builder-search No login needed |
≤ 4.3.3 |
CVE-2024-7651 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.