WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–38 of 38 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.2 High Divi Dash Plugin Denial of Service Unauthenticated Denial of Service via IP Address Spoofing No login needed < 1.0.7 Fixed in 1.0.7 CVE-2026-14321 WPScan
7.5 High LearnDash LMS Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler ≤ 5.1.5 CVE-2026-12483 Wordfence
7.1 High Ultimate Dashboard Pro Plugin ultimate-dashboard-pro Cross-Site Scripting No login needed ≤ 3.11.2 CVE-2026-66621 Patchstack
7.1 High SureDash Plugin suredash Cross-Site Scripting No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2026-66698 Patchstack
8.1 High WPMU DEV Dashboard Plugin Authentication Bypass Authentication Bypass to Arbitrary Plugin Installation (Remote Code Execution) via Forged WDP_AUTH HMAC on ?wpmudev-hub= Endpoint No login needed ≤ 5.0.0 CVE-2026-15459 Wordfence
7.3 High Material Dashboard Plugin material-dashboard Broken Access Control Missing Authorization to Unauthenticated Task Enumeration, Execution, and Deletion No login needed ≤ 1.4.10 CVE-2026-6079 Wordfence
8.8 High FleekDash V2 Plugin fleekdash Broken Access Control Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover via /users/{id} REST Endpoint ≤ 2.6.2.2 CVE-2026-14356 Wordfence
8.5 High SureDash Plugin suredash SQL Injection ≤ 1.8.0 Fixed in 1.8.1 CVE-2026-54813 Patchstack
7.2 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process ≤ 9.1.2 CVE-2026-5464 Wordfence
8.8 High ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation 8.0.0 – 9.0.2 CVE-2026-1992 Wordfence
8.8 High ExactMetrics Plugin google-analytics-dashboard-for-wp Privilege Escalation Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update 7.1.0 – 9.0.2 CVE-2026-1993 Wordfence
7.1 High DASHBOARD BUILDER Plugin dashboard-builder Cross-Site Request Forgery Cross-Site Request Forgery to SQL Injection No login needed ≤ 1.5.7 CVE-2025-14615 Wordfence
7.1 High WSAnalytics Plugin wsanalytics-google-analytics-and-dashboards Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-48097 Patchstack
8.8 High SureDash Plugin suredash Privilege Escalation ≤ 1.0.3 Fixed in 1.1.0 CVE-2025-48164 Patchstack
7.5 High wp-dashboard-notes Plugin Broken Access Control Contributor+ Arbitrary Private Notes Update via IDOR No login needed < 1.0.11 Fixed in 1.0.11 CVE-2023-7239 WPScan
8.8 High UiPress lite | Effortless custom dashboards, admin themes and pages Plugin uipress-lite Remote Code Execution Authenticated (Subscriber+) Remote Code Execution ≤ 3.5.07 CVE-2025-3053 Wordfence
8.8 High Frontend Dashboard Plugin frontend-dashboard Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via fed_admin_setting_form_function Function 1.0 – 2.2.7 CVE-2025-4474 Wordfence
8.8 High Frontend Dashboard Plugin frontend-dashboard Broken Access Control Missing Authorization to Authenticated (Subscriber+) Account Takeover/Privilege Escalation via ajax_request Function 1.5.10 – 2.2.7 CVE-2025-4473 Wordfence
7.1 High Dashboard Notepads Plugin dashboard-notepads Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.1 CVE-2025-39441 Patchstack
7.5 High Material Dashboard Plugin material-dashboard Local File Inclusion ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31014 Patchstack
8.1 High Material Dashboard Plugin material-dashboard Local File Inclusion No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31097 Patchstack
8.8 High UiPress lite | Effortless custom dashboards, admin themes and pages Plugin uipress-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.5.04 CVE-2025-1309 Wordfence
7.1 High Fast Flow Plugin fast-flow-dashboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.16 Fixed in 1.2.18 CVE-2025-26868 Patchstack
7.1 High Data Dash Plugin data-dash Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-23751 Patchstack
7.1 High Kv Compose Email From Dashboard Plugin kv-send-email-from-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23525 Patchstack
7.1 High Live Dashboard Plugin live-dashboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.3 CVE-2025-23474 Patchstack
7.1 High Custom Links On Admin Dashboard Toolbar Plugin customize-wpadmin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3 CVE-2025-25135 Patchstack
7.1 High FLX Dashboard Groups Plugin flx-dashboard-groups Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.7 CVE-2025-23730 Patchstack
7.1 High Custom Dashboard Widget Plugin create-custom-dashboard-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-56024 Patchstack
7.1 High Dashing Memberships Plugin dashing-memberships Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51760 Patchstack
7.2 High MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin Cross-Site Scripting The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting No login needed < 3.1.3 Fixed in 3.1.3 CVE-2016-15041 Wordfence
7.2 High Uncanny Groups for LearnDash Plugin Privilege Escalation Authenticated (Group Leader+) Privilege Escalation ≤ 6.1.0.1 CVE-2024-8349 Wordfence
8.8 High Frontend Dashboard Plugin frontend-dashboard Broken Access Control Authenticated (Subscriber+) Arbitrary Function Call ≤ 2.2.4 CVE-2024-8268 Wordfence
7.1 High Tin Canny Reporting for LearnDash Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.0.7 Fixed in 4.3.0.8 CVE-2024-39656 Patchstack
7.1 High Uncanny Toolkit Pro for LearnDash Plugin uncanny-toolkit-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 4.1.4.1 Fixed in 4.1.4.1 CVE-2024-37436 Patchstack
7.5 High Frontend Dashboard Plugin frontend-dashboard Information Disclosure Sensitive Data Exposure on PII No login needed ≤ 2.2.2 Fixed in 2.2.4 CVE-2024-32726 Patchstack
7.1 High Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Scripting Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51488 Patchstack
7.1 High Custom Dashboard Widgets Plugin custom-dashboard-widgets Cross-Site Request Forgery WordPress Custom Dashboard Widgets Plugin <= 1.3.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.3.1 CVE-2024-22290 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only