WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–31 of 31 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Post SMTP Plugin post-smtp Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via 'user_email' Parameter (Multisite Registration → Failed Email Log) No login needed ≤ 4.0.1 CVE-2026-75962 Wordfence
7.2 High Visitor Traffic Real Time Statistics Plugin visitors-traffic-real-time-statistics Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header No login needed ≤ 8.16 CVE-2026-97341 Wordfence
7.2 High Appointment Hour Booking Plugin appointment-hour-booking Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via Booking Form Single-Line Field via Schedule Calendar List Renderer No login needed ≤ 1.5.97 CVE-2026-96573 Wordfence
7.2 High Frontend Post Submission Manager Lite Plugin frontend-post-submission-manager-lite Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) No login needed ≤ 1.3.4 CVE-2026-96649 Wordfence
7.5 High Multiple elFinder Plugins Plugin Cross-Site Scripting DOM-based XSS via postMessage Origin Bypass No login needed < 8.0.5, < 1.2.1, < 2.1.3 Fixed in 8.0.5 CVE-2026-85081 WPScan
7.2 High HT Contact Form Plugin ht-contactform Cross-Site Scripting Unauthenticated Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume No login needed ≤ 2.10.1 CVE-2026-93303 Wordfence
8.0 High Unbounce Landing Pages Plugin unbounce Broken Access Control Subscriber+ Reverse-Proxy Target Hijack via set_unbounce_domains 1.1.1 – < 1.1.5 Fixed in 1.1.5 CVE-2026-85574 WPScan
8.6 High Domain For Sale Plugin domain-for-sale Broken Access Control ThemeAtelier Domain For Sale < 3.5.2 Missing Authorization via REST API No login needed < 3.5.2 Fixed in 3.5.2 CVE-2026-89023 VulnCheck
7.2 High Listdom: AI-powered Business Directory with Classifieds Ads Listings Plugin listdom Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter No login needed ≤ 5.8.1 CVE-2026-19796 Wordfence
7.2 High Forminator Forms Plugin forminator Cross-Site Scripting Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter No login needed ≤ 1.57.0 CVE-2026-18328 Wordfence
8.8 High DoLogin Security Plugin dologin Authentication Bypass Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token ≤ 4.3 CVE-2026-14495 Wordfence
8.1 High Dom Theme dom Local File Inclusion No login needed ≤ 1.24 CVE-2025-69146 Patchstack
7.3 High Listdom Plugin listdom Privilege Escalation No login needed ≤ 5.5.0 Fixed in 5.6.0 CVE-2026-49063 Patchstack
7.2 High NotificationX Plugin notificationx Cross-Site Scripting Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview' No login needed ≤ 3.2.0 CVE-2025-15380 Wordfence
8.1 High Domnoo Plugin domnoo Local File Inclusion No login needed ≤ 1.49 Fixed in 1.52.1 CVE-2025-52812 Patchstack
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-31903 Patchstack
7.1 High Random Quotes Plugin random-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-27267 Patchstack
7.1 High Random Image Selector Plugin random-image-selector Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-26548 Patchstack
7.1 High Random Posts, Mp3 Player + ShareButton Plugin random-posts-mp3-player-sharebutton Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23744 Patchstack
7.1 High Domain Plugin domain-theme Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-28897 Patchstack
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting Reflected XSS No login needed ≤ 1.40 CVE-2024-13574 WPScan
7.1 High Stray Random Quotes Plugin stray-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.9 CVE-2025-23883 Patchstack
7.5 High LTL Freight Quotes – Old Dominion Edition Plugin SQL Injection Old Dominion Edition <= 4.2.10 - Unauthenticated SQL Injection No login needed ≤ 4.2.10 CVE-2024-13489 Wordfence
7.1 High WP24 Domain Check Plugin wp24-domain-check Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.10.14 Fixed in 1.10.15 CVE-2025-24602 Patchstack
7.1 High Mind3doM RyeBread Widgets Plugin mind3dom-ryebread-widgets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23722 Patchstack
7.1 High Domain Sharding Plugin domain-sharding Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-50533 Patchstack
7.1 High Random Featured Post Plugin random-featured-post-plugin Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2024-51650 Patchstack
7.5 High SB Random Posts Widget Plugin sb-random-posts-widget Local File Inclusion ≤ 1.0 Fixed in 1.1 CVE-2024-48029 Patchstack
7.2 High Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math PHP Object Injection AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection ≤ 1.0.228 CVE-2024-9314 Wordfence
8.1 High Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Authentication Bypass Email Verification and Authentication Bypass due to Insufficient Randomness No login needed ≤ 2.7.4 CVE-2024-4185 Wordfence
8.5 High Randomize Plugin randomize SQL Injection WordPress Randomize Plugin <= 1.4.3 is vulnerable to SQL Injection ≤ 1.4.3 CVE-2023-52204 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only