WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–38 of 38 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.71 CVE-2026-94405 Patchstack
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name ≤ 3.3.70 CVE-2026-97338 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Author+ Stored XSS via Package Icon < 3.3.71 Fixed in 3.3.71 CVE-2026-86610 WPScan
6.5 Medium Download Manager Plugin download-manager Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter ≤ 3.3.68 CVE-2026-92714 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute ≤ 3.3.66 CVE-2026-16685 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes ≤ 3.3.61 CVE-2026-14343 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute ≤ 3.3.60 CVE-2026-13733 Wordfence
4.3 Medium Download Manager Plugin download-manager Broken Access Control Missing Authorization to Authenticated (Contributor+) Media File Protection Removal ≤ 3.3.51 CVE-2026-4057 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 3.3.52 CVE-2026-5357 Wordfence
5.3 Medium Download Manager Plugin download-manager Broken Access Control No login needed ≤ 3.3.52 Fixed in 3.3.53 CVE-2026-39676 Patchstack
5.9 Medium Download Manager Plugin download-manager Cross-Site Scripting ≤ 3.3.53 CVE-2026-39615 Patchstack
4.3 Medium Download Manager Plugin download-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter ≤ 3.3.49 CVE-2026-2571 Wordfence
6.1 Medium Download Manager Plugin download-manager Cross-Site Scripting Reflected Cross-Site Scripting via 'redirect_to' Parameter No login needed ≤ 3.3.46 CVE-2026-1666 Wordfence
4.3 Medium Download Manager Plugin download-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure ≤ 3.3.32 CVE-2025-13498 Wordfence
4.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure ≤ 3.3.32 Fixed in 3.3.33 CVE-2025-63070 Patchstack
5.3 Medium Download Manager Plugin download-manager Broken Access Control Unauthenticated Cron Trigger due to Hardcoded Cron Key No login needed ≤ 3.3.30 CVE-2025-12177 Wordfence
4.3 Medium Download Manager Plugin download-manager Cross-Site Request Forgery No login needed ≤ 3.3.24 Fixed in 3.3.25 CVE-2025-60093 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.25 Fixed in 3.3.26 CVE-2025-60092 Patchstack
6.1 Medium Download Manager Plugin download-manager Cross-Site Scripting Reflected Cross-Site Scripting via `user_ids` Parameter No login needed ≤ 3.3.23 CVE-2025-10146 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode ≤ 3.3.18 CVE-2025-4367 Wordfence
4.8 Medium Download Manager Plugin download-manager Cross-Site Scripting Admin+ Stored XSS < 3.2.99 Fixed in 3.2.99 CVE-2024-8284 WPScan
5.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 3.3.12 CVE-2025-3056 Wordfence
4.6 Medium Download Manager Plugin download-manager Information Disclosure Unauthenticated Data Exposure < 3.3.07 Fixed in 3.3.07 CVE-2024-13126 WPScan
5.4 Medium Download Manager Plugin download-manager Path Traversal Authenticated (Author+) Path Traversal to Limited File Overwrite ≤ 3.3.08 CVE-2025-1785 Wordfence
4.3 Medium Download Manager Plugin download-manager Broken Access Control ≤ 3.3.03 Fixed in 3.3.04 CVE-2024-56217 Patchstack
4.8 Medium Download Manager Plugin download-manager Cross-Site Scripting Admin+ Stored XSS < 3.3.03 Fixed in 3.3.03 CVE-2024-10706 WPScan
5.3 Medium Download manager Plugin download-manager Broken Access Control Improper Authorization to Unauthenticated Download of Password-Protected Files No login needed ≤ 3.3.03 CVE-2024-11768 Wordfence
5.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Contributor+ Stored XSS < 3.3.00 Fixed in 3.3.00 CVE-2024-8444 WPScan
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.97 CVE-2024-6208 Wordfence
4.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting ≤ 3.2.86 CVE-2024-1766 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 3.2.92 CVE-2024-5266 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode ≤ 3.2.93 CVE-2024-4001 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode ≤ 3.2.90 CVE-2024-4160 Wordfence
5.3 Medium Download Manager Plugin download-manager Information Disclosure File Password Lock Bypass No login needed ≤ 3.2.82 Fixed in 3.2.83 CVE-2024-32131 Patchstack
4.8 Medium CM Download Manager Plugin cm-download-manager Cross-Site Request Forgery Download Deletion via CSRF < 2.9.0 Fixed in 2.9.0 CVE-2024-1232 WPScan
6.5 Medium Download Manager Plugin download-manager Cross-Site Scripting ≤ 3.2.84 Fixed in 3.2.85 CVE-2024-29114 Patchstack
5.3 Medium Download Manager Plugin download-manager Broken Access Control Missing Authorization No login needed ≤ 3.2.84 CVE-2023-6785 Wordfence
6.4 Medium Download Manager Plugin download-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.85 CVE-2023-6954 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only