WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–50 of 60 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High WP ERP Plugin erp SQL Injection ≤ 1.17.9 Fixed in 1.17.10 CVE-2026-96346 Patchstack
7.2 High WP ERP Plugin erp PHP Object Injection ≤ 1.17.9 Fixed in 1.17.10 CVE-2026-96343 Patchstack
8.8 High MemberPress Corporate Accounts Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Mass Assignment in Sub-Account Creation ≤ 1.5.39 CVE-2026-15451 Wordfence
7.1 High Blubrry PowerPress Plugin Server-Side Request Forgery Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL < 11.17.1 Fixed in 11.17.1 CVE-2026-16294 WPScan
7.1 High Slider Pro Plugin sliderpro Cross-Site Scripting No login needed ≤ 4.8.13 Fixed in 4.8.14 CVE-2026-57699 Patchstack
8.8 High MailerPress Plugin mailerpress Privilege Escalation ≤ 2.0.2 Fixed in 2.0.3 CVE-2026-57410 Patchstack
8.8 High PowerPack Pro for Elementor Plugin powerpack-elements Authentication Bypass Broken Authentication No login needed < v2.13.0 Fixed in 2.13.0 CVE-2026-42629 Patchstack
8.5 High PowerPress Podcasting Plugin powerpress SQL Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-24637 Patchstack
7.5 High WP ERP Pro Plugin SQL Injection Unauthenticated SQL Injection via 'search_key' Parameter No login needed ≤ 1.5.1 CVE-2026-4834 Wordfence
8.5 High WP ERP Plugin erp SQL Injection ≤ 1.16.10 Fixed in 1.16.11 CVE-2026-31917 Patchstack
7.1 High UberSlider PerpetuumMobile Plugin uberslider_perpetuummobile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28100 Patchstack
8.8 High PowerPress Podcasting Plugin powerpress PHP Object Injection ≤ 11.15.10 Fixed in 11.15.11 CVE-2026-23798 Patchstack
7.5 High TopperPack – Complete Elementor Addons, Theme & CPT Builder Plugin topper-pack Local File Inclusion Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion No login needed ≤ 1.2.1 CVE-2025-68841 Patchstack
7.1 High MemberPress Discord Addon Plugin expresstechsoftwares-memberpress-discord-add-on Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-68838 Patchstack
7.1 High Scroll rss excerpt Plugin scroll-rss-excerpt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.0 CVE-2025-68892 Patchstack
7.5 High Userpro Plugin userpro Broken Access Control No login needed ≤ 5.1.9 CVE-2025-68608 Patchstack
7.5 High PowerPack Pro for Elementor Plugin powerpack-elements Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 2.10.6 Fixed in 2.10.8 CVE-2024-24844 Patchstack
7.5 High Ray Enterprise Translation Plugin lingotek-translation Local File Inclusion No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2025-60076 Patchstack
8.8 High Blubrry PowerPress Plugin powerpress Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload via 'powerpress_edit_post' ≤ 11.15.2 CVE-2025-13536 Wordfence
7.3 High Rehub Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via re_filterpost No login needed ≤ 19.9.7 CVE-2025-7366 Wordfence
7.5 High WooCommerce Payment Gateway for Saferpay Plugin woocommerce-payment-gateway-for-saferpay Path Traversal No login needed ≤ 0.4.9 CVE-2025-48317 Patchstack
7.3 High The E-Commerce ERP Plugin profitori Broken Access Control No login needed ≤ 2.1.1.3 CVE-2025-52800 Patchstack
8.1 High SERPed.net Plugin serped-net Local File Inclusion No login needed ≤ 4.6 Fixed in 4.7 CVE-2025-28998 Patchstack
7.1 High Memberpress Plugin memberpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 1.12.0 Fixed in 1.12.0 CVE-2025-39407 Patchstack
7.5 High WP ERP Plugin Broken Access Control Custom+ Unauthorized Access to Terminated Employee Information No login needed < 1.13.4 Fixed in 1.13.4 CVE-2024-12812 WPScan
7.5 High Ray Enterprise Translation Plugin lingotek-translation Local File Inclusion Local File Inclusion via CSRF No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-31030 Patchstack
7.1 High MemberPress Discord Addon Plugin expresstechsoftwares-memberpress-discord-add-on Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-32605 Patchstack
7.1 High SERPed.net Plugin serped-net Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.6 Fixed in 4.7 CVE-2025-32651 Patchstack
8.1 High DyaPress ERP/CRM Plugin dyapress Local File Inclusion No login needed ≤ 18.0.2.0 CVE-2025-30582 Patchstack
7.1 High Blubrry PowerPress Podcasting plugin MultiSite add-on Plugin powerpress-multisite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.1 CVE-2025-31436 Patchstack
8.8 High Media Manager for UserPro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.12.0 CVE-2024-12821 Wordfence
7.1 High Passwordless WP – Login with your glance or fingerprint Plugin passwordless-wp Cross-Site Scripting Login with your glance or fingerprint Plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23792 Patchstack
8.5 High SERPed.net Plugin serped-net SQL Injection ≤ 4.4 Fixed in 4.6 CVE-2025-24669 Patchstack
7.1 High Private Messages for UserPro Plugin userpro-messaging Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.10.0 CVE-2025-22322 Patchstack
7.5 High Private Messages for UserPro Plugin userpro-messaging Local File Inclusion No login needed ≤ 4.10.0 CVE-2025-22311 Patchstack
7.1 High Twitter Post Plugin twitterpost Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1 CVE-2025-23654 Patchstack
7.1 High Userpro Plugin userpro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.9 CVE-2024-56210 Patchstack
8.5 High Userpro Plugin userpro SQL Injection ≤ 5.1.9 CVE-2024-56212 Patchstack
8.8 High Userpro Plugin userpro Broken Access Control Authenticated Arbitrary User Meta Update ≤ 5.1.9 CVE-2024-56211 Patchstack
8.3 High Userpro Plugin userpro Local File Inclusion No login needed ≤ 5.1.9 CVE-2024-56214 Patchstack
8.8 High Minterpress Plugin minterpress Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.0.5 CVE-2024-54379 Patchstack
7.1 High CarDealerPress Plugin cardealerpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.2410.02 Fixed in 6.7.2411.00 CVE-2024-54325 Patchstack
7.1 High WP ERP Plugin erp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.2 Fixed in 1.13.3 CVE-2024-47640 Patchstack
7.2 High UserPlus Plugin userplus Privilege Escalation Authenticated (Editor+) Registration Form Update to Privilege Escalation ≤ 2.0 CVE-2024-9519 Wordfence
7.1 High PowerPack for Beaver Builder Plugin bbpowerpack Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 2.37.4 Fixed in 2.37.4 CVE-2024-43330 Patchstack
8.8 High PowerPack for Beaver Builder Plugin Privilege Escalation Contributor+ Privilege Escalation ≤ 2.33.0 Fixed in 2.33.1 CVE-2024-39633 Patchstack
8.8 High PowerPack Pro for Elementor Plugin Privilege Escalation Contributor+ Privilege Escalation ≤ 2.10.14 Fixed in 2.10.15 CVE-2024-39634 Patchstack
7.1 High Counterpoint Theme counterpoint Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 CVE-2024-37559 Patchstack
8.8 High WP ERP Plugin erp SQL Injection Authenticated (Accounting Manager+) SQL Injection via vendor_id ≤ 1.13.0 CVE-2024-6666 Wordfence
8.8 High PowerPack Pro for Elementor Plugin Privilege Escalation Authenticated (Contributor+) Privilege Escalation ≤ 2.10.17 CVE-2024-3668 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only