WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–40 of 40 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium Featured Image with URL Plugin featured-image-with-url Cross-Site Scripting Contributor+ Stored XSS via Image Alt Text < 1.0.6 Fixed in 1.0.6 CVE-2026-86780 WPScan
6.5 Medium Featured Image from URL Plugin featured-image-from-url Cross-Site Scripting ≤ 5.3.3 Fixed in 6.0.0 CVE-2026-73340 Patchstack
6.5 Medium Featured Image Plugin featured-image Cross-Site Scripting ≤ 2.1 Fixed in 2.2 CVE-2026-57431 Patchstack
5.9 Medium FSM Custom Featured Image Caption Plugin fsm-custom-featured-image-caption Cross-Site Scripting ≤ 1.25.1 CVE-2026-39693 Patchstack
5.3 Medium Featured Image from Content Plugin featured-image-from-content Server-Side Request Forgery Featured Image from Content < 1.7 Authenticated SSRF via save_post < 1.7 Fixed in 1.7 CVE-2026-27759 VulnCheck
4.3 Medium Automatic Featured Images from Videos Plugin automatic-featured-images-from-videos Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2026-24535 Patchstack
4.3 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'fifu_input_url' ≤ 5.3.1 CVE-2025-13393 Wordfence
5.3 Medium Featured Image Generator Plugin featured-image-generator Broken Access Control No login needed ≤ 1.3.4 CVE-2025-62747 Patchstack
5.9 Medium Add Featured Image Custom Link Plugin custom-url-to-featured-image Cross-Site Scripting ≤ 2.0.0 CVE-2025-62119 Patchstack
8.8 High Featured Image via URL Plugin featured-image-via-url Arbitrary File Upload Authenticated (Contributor+) Arbitrary FIle Upload ≤ 0.1 CVE-2025-12153 Wordfence
4.4 Medium Featured Image Plugin featured-image Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.1 CVE-2025-12019 Wordfence
4.9 Medium Quick Featured Images Plugin quick-featured-images SQL Injection Authenticated (Editor+) SQL Injection via delete_orphaned ≤ 13.7.3 CVE-2025-11980 Wordfence
6.5 Medium Post List Featured Image Plugin post-list-featured-image Cross-Site Scripting ≤ 0.5.9 CVE-2025-62937 Patchstack
4.3 Medium Quick Featured Images Plugin quick-featured-images Broken Access Control Insecure Direct Object Reference to Image Manipulation ≤ 13.7.2 CVE-2025-11176 Wordfence
6.4 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields ≤ 5.2.7 CVE-2025-7400 Wordfence
4.9 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url SQL Injection Authenticated (Admin+) SQL Injection ≤ 5.2.7 CVE-2025-10036 Wordfence
5.3 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Information Disclosure Unauthenticated Information Exposure via Log File No login needed ≤ 5.2.7 CVE-2025-9985 Wordfence
4.9 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url SQL Injection Authenticated (Admin+) SQL Injection ≤ 5.2.7 CVE-2025-10037 Wordfence
5.3 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Broken Access Control Missing Authorization to Password Protected Post Disclosure No login needed ≤ 5.2.7 CVE-2025-9984 Wordfence
5.9 Medium Category Featured Images Extended Plugin category-featured-images-extended Cross-Site Scripting ≤ 1.52 CVE-2025-57920 Patchstack
5.9 Medium Category Featured Images Plugin category-featured-images Cross-Site Scripting ≤ 1.1.8 CVE-2025-58655 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-58819 Patchstack
5.5 Medium Featured Image Plus – Quick & Bulk Edit with Unsplash Plugin featured-image-plus Server-Side Request Forgery Quick & Bulk Edit with Unsplash <= 1.6.6 - Authenticated (Admin+) Server-Side Request Forgery ≤ 1.6.6 CVE-2025-5818 Wordfence
6.4 Medium Simple Featured Image Plugin simple-featured-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slideshow Parameter ≤ 1.3.1 CVE-2025-7059 Wordfence
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-28951 Patchstack
4.3 Medium Featured Image Plus Plugin featured-image-plus Broken Access Control Missing Authorization to Authenticated (Subscriber+) Featured Image Update ≤ 1.6.4 CVE-2025-4431 Wordfence
4.3 Medium Bulk Featured Image Plugin bulk-featured-image Broken Access Control ≤ 1.2.4 CVE-2025-47591 Patchstack
7.1 High WooCommerce Products without featured images Plugin woocommerce-products-without-featured-images Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-32545 Patchstack
4.3 Medium Automatic Featured Images from Videos Plugin automatic-featured-images-from-videos Broken Access Control ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-31820 Patchstack
7.1 High azurecurve Floating Featured Image Plugin azurecurve-floating-featured-image Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2025-23482 Patchstack
5.3 Medium Featured Image from URL Plugin featured-image-from-url Broken Access Control No login needed ≤ 4.8.1 Fixed in 4.8.2 CVE-2024-37276 Patchstack
6.3 Medium Featured Image from URL Plugin featured-image-from-url Broken Access Control ≤ 4.8.2 Fixed in 4.8.3 CVE-2024-37516 Patchstack
9.9 Critical External featured image from bing Plugin external-featured-image-from-bing Remote Code Execution ≤ 1.0.2 CVE-2024-48027 Patchstack
6.1 Medium Auto Featured Image from Title Plugin auto-featured-image-from-title Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.3 CVE-2024-8786 Wordfence
6.4 Medium Dynamic Featured Image Plugin dynamic-featured-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via dfiFeatured Parameter ≤ 3.7.0 CVE-2024-6929 Wordfence
4.3 Medium Featured Image Generator Plugin featured-image-generator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Images Upload ≤ 1.3.1 CVE-2024-5677 Wordfence
8.8 High Auto Featured Image Plugin auto-featured-image Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.2 CVE-2024-6054 Wordfence
4.3 Medium Quick Featured Images Plugin quick-featured-images Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Thumbnail Deletion/Setting ≤ 13.7.0 CVE-2024-3664 Wordfence
6.4 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fifu_input_url ≤ 4.6.2 CVE-2024-1496 Wordfence
6.4 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text ≤ 4.5.3 CVE-2023-6561 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only