WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–38 of 38 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Download Manager | Information Disclosure Sensitive Data Exposure No login needed |
≤ 3.3.71 |
CVE-2026-94405 |
Patchstack | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Display Name |
≤ 3.3.70 |
CVE-2026-97338 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Author+ Stored XSS via Package Icon |
< 3.3.71 Fixed in 3.3.71 |
CVE-2026-86610 |
WPScan | |
| 6.5 Medium | Download Manager | Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'wpdm_duplicate' Parameter |
≤ 3.3.68 |
CVE-2026-92714 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' Shortcode Attribute |
≤ 3.3.66 |
CVE-2026-16685 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes |
≤ 3.3.61 |
CVE-2026-14343 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute |
≤ 3.3.60 |
CVE-2026-13733 |
Wordfence | |
| 4.3 Medium | Download Manager | Broken Access Control Missing Authorization to Authenticated (Contributor+) Media File Protection Removal |
≤ 3.3.51 |
CVE-2026-4057 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 3.3.52 |
CVE-2026-5357 |
Wordfence | |
| 5.3 Medium | Download Manager | Broken Access Control No login needed |
≤ 3.3.52 Fixed in 3.3.53 |
CVE-2026-39676 |
Patchstack | |
| 5.9 Medium | Download Manager | Cross-Site Scripting |
≤ 3.3.53 |
CVE-2026-39615 |
Patchstack | |
| 4.3 Medium | Download Manager | Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Email Enumeration via 'user' Parameter |
≤ 3.3.49 |
CVE-2026-2571 |
Wordfence | |
| 6.1 Medium | Download Manager | Cross-Site Scripting Reflected Cross-Site Scripting via 'redirect_to' Parameter No login needed |
≤ 3.3.46 |
CVE-2026-1666 |
Wordfence | |
| 4.3 Medium | Download Manager | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure |
≤ 3.3.32 |
CVE-2025-13498 |
Wordfence | |
| 4.3 Medium | Download Manager | Information Disclosure Sensitive Data Exposure |
≤ 3.3.32 Fixed in 3.3.33 |
CVE-2025-63070 |
Patchstack | |
| 5.3 Medium | Download Manager | Broken Access Control Unauthenticated Cron Trigger due to Hardcoded Cron Key No login needed |
≤ 3.3.30 |
CVE-2025-12177 |
Wordfence | |
| 4.3 Medium | Download Manager | Cross-Site Request Forgery No login needed |
≤ 3.3.24 Fixed in 3.3.25 |
CVE-2025-60093 |
Patchstack | |
| 5.3 Medium | Download Manager | Information Disclosure Sensitive Data Exposure No login needed |
≤ 3.3.25 Fixed in 3.3.26 |
CVE-2025-60092 |
Patchstack | |
| 6.1 Medium | Download Manager | Cross-Site Scripting Reflected Cross-Site Scripting via `user_ids` Parameter No login needed |
≤ 3.3.23 |
CVE-2025-10146 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Author+) Stored Cross-site Scripting via wpdm_user_dashboard Shortcode |
≤ 3.3.18 |
CVE-2025-4367 |
Wordfence | |
| 4.8 Medium | Download Manager | Cross-Site Scripting Admin+ Stored XSS |
< 3.2.99 Fixed in 3.2.99 |
CVE-2024-8284 |
WPScan | |
| 5.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 3.3.12 |
CVE-2025-3056 |
Wordfence | |
| 4.6 Medium | Download Manager | Information Disclosure Unauthenticated Data Exposure |
< 3.3.07 Fixed in 3.3.07 |
CVE-2024-13126 |
WPScan | |
| 5.4 Medium | Download Manager | Path Traversal Authenticated (Author+) Path Traversal to Limited File Overwrite |
≤ 3.3.08 |
CVE-2025-1785 |
Wordfence | |
| 4.3 Medium | Download Manager | Broken Access Control |
≤ 3.3.03 Fixed in 3.3.04 |
CVE-2024-56217 |
Patchstack | |
| 4.8 Medium | Download Manager | Cross-Site Scripting Admin+ Stored XSS |
< 3.3.03 Fixed in 3.3.03 |
CVE-2024-10706 |
WPScan | |
| 5.3 Medium | Download manager | Broken Access Control Improper Authorization to Unauthenticated Download of Password-Protected Files No login needed |
≤ 3.3.03 |
CVE-2024-11768 |
Wordfence | |
| 5.4 Medium | Download Manager | Cross-Site Scripting Contributor+ Stored XSS |
< 3.3.00 Fixed in 3.3.00 |
CVE-2024-8444 |
WPScan | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.2.97 |
CVE-2024-6208 |
Wordfence | |
| 4.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting |
≤ 3.2.86 |
CVE-2024-1766 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Multiple Shortcodes |
≤ 3.2.92 |
CVE-2024-5266 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm_modal_login_form Shortcode |
≤ 3.2.93 |
CVE-2024-4001 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode |
≤ 3.2.90 |
CVE-2024-4160 |
Wordfence | |
| 5.3 Medium | Download Manager | Information Disclosure File Password Lock Bypass No login needed |
≤ 3.2.82 Fixed in 3.2.83 |
CVE-2024-32131 |
Patchstack | |
| 4.8 Medium | CM Download Manager | Cross-Site Request Forgery Download Deletion via CSRF |
< 2.9.0 Fixed in 2.9.0 |
CVE-2024-1232 |
WPScan | |
| 6.5 Medium | Download Manager | Cross-Site Scripting |
≤ 3.2.84 Fixed in 3.2.85 |
CVE-2024-29114 |
Patchstack | |
| 5.3 Medium | Download Manager | Broken Access Control Missing Authorization No login needed |
≤ 3.2.84 |
CVE-2023-6785 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.2.85 |
CVE-2023-6954 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.