WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 1–33 of 33 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Flexible PDF Coupons | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 1.14.11 Fixed in 1.14.12 |
CVE-2026-62081 |
Patchstack | |
| 4.3 Medium | Flex Import | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via 'license_activate_fleximp' and 'license_deactivate_fleximp' AJAX Actions |
≤ 3.0 |
CVE-2026-9615 |
Wordfence | |
| 8.6 High | VikRentItems Flexible Rental Management System | SQL Injection Unauthenticated SQLi No login needed |
< 1.2.4 Fixed in 1.2.4 |
CVE-2026-88926 |
WPScan | |
| 5.3 Medium | Flexible Quantity – Measurement Price Calculator for WooCommerce | Broken Access Control Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control No login needed |
≤ 2.3.21 Fixed in 2.3.22 |
CVE-2026-62136 |
Patchstack | |
| 9.8 Critical | Flexible Subscriptions | PHP Object Injection No login needed |
≤ 1.8.1 Fixed in 1.8.2 |
CVE-2026-73364 |
Patchstack | |
| 7.2 High | VikRentItems Flexible Rental Management System | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.2.1 |
CVE-2026-16143 |
Wordfence | |
| 6.5 Medium | Flexible Refund and Return Order for WooCommerce | Cross-Site Scripting |
≤ 1.0.51 Fixed in 1.0.52 |
CVE-2026-57402 |
Patchstack | |
| 5.5 Medium | Multi Functional Flexi Lightbox | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via 'message' Parameter |
≤ 1.2 |
CVE-2026-3347 |
Wordfence | |
| 7.5 High | Flexi Product Slider and Grid for WooCommerce | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute |
≤ 1.0.5 |
CVE-2026-1988 |
Wordfence | |
| 6.1 Medium | VikRentItems Flexible Rental Management System | Cross-Site Scripting Reflected Cross-Site Scripting via 'delto' Parameter No login needed |
≤ 1.2.0 |
CVE-2025-14049 |
Wordfence | |
| 6.5 Medium | ACF Flexible Layouts Manager | Broken Access Control Missing Authorization to Unauthenticated Custom Field Update No login needed |
≤ 1.1.6 |
CVE-2025-12937 |
Wordfence | |
| 5.3 Medium | Flexible Refund and Return Order for WooCommerce | Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Refund Status Update No login needed |
≤ 1.0.42 |
CVE-2025-12621 |
Wordfence | |
| 4.3 Medium | Flexible Refund and Return Order for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Refund |
≤ 1.0.38 |
CVE-2025-10570 |
Wordfence | |
| 6.4 Medium | Flexi | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via flexi-form-tag Shortcode |
≤ 4.28 |
CVE-2025-9129 |
Wordfence | |
| 7.1 High | Flexible PDF Invoices for WooCommerce & | Cross-Site Request Forgery No login needed |
≤ 6.0.13 Fixed in 6.0.14 |
CVE-2025-57977 |
Patchstack | |
| 4.3 Medium | Flexible FAQ | Cross-Site Request Forgery No login needed |
≤ 0.2 |
CVE-2025-58200 |
Patchstack | |
| 6.4 Medium | Flexible Maps | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Flexible Maps Shortcode |
≤ 1.18.0 |
CVE-2025-8622 |
Wordfence | |
| 6.5 Medium | Meks Flexible Shortcodes | Cross-Site Scripting |
≤ 1.3.7 Fixed in 1.3.8 |
CVE-2025-49855 |
Patchstack | |
| 6.5 Medium | Meks Flexible Shortcodes | Cross-Site Scripting |
≤ 1.3.6 Fixed in 1.3.7 |
CVE-2025-47621 |
Patchstack | |
| 8.1 High | Flexi – Guest Submit | Local File Inclusion Guest Submit Plugin <= 4.28 - Local File Inclusion No login needed |
≤ 4.28 |
CVE-2025-32589 |
Patchstack | |
| 4.3 Medium | Flexible Cookies | Cross-Site Request Forgery No login needed |
≤ 1.1.8 Fixed in 1.1.9 |
CVE-2025-30805 |
Patchstack | |
| 4.3 Medium | Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later | Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed |
≤ 1.2.26 |
CVE-2024-13718 |
Wordfence | |
| 6.5 Medium | FlexIDX Home Search | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 2.1.2 |
CVE-2025-25082 |
Patchstack | |
| 7.2 High | Flexible Wishlist for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via wishlist_name Parameter No login needed |
≤ 1.2.25 |
CVE-2024-13696 |
Wordfence | |
| 7.1 High | Flexible Blogtitle | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.1 |
CVE-2025-23846 |
Patchstack | |
| 6.5 Medium | Flexible PDF Coupons | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.10.3 Fixed in 1.10.3 |
CVE-2025-22825 |
Patchstack | |
| 8.2 High | Flexible Woocommerce Checkout Field Editor | Broken Access Control No login needed |
≤ 2.0.1 |
CVE-2023-49817 |
Patchstack | |
| 4.3 Medium | UPS Live Rates and Access Points | Broken Access Control Missing Authorization to Plugin API key reset |
≤ 2.3.12 |
CVE-2024-9109 |
Wordfence | |
| 5.3 Medium | USPS Shipping for WooCommerce – Live Rates | Information Disclosure Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File No login needed |
≤ 1.9.4 Fixed in 1.10.0 |
CVE-2024-32811 |
Patchstack | |
| 4.3 Medium | Flexible Checkout Fields for WooCommerce | Broken Access Control |
≤ 4.1.2 Fixed in 4.1.3 |
CVE-2024-31267 |
Patchstack | |
| 4.3 Medium | Flexible Shipping | Broken Access Control |
≤ 4.24.15 Fixed in 4.24.16 |
CVE-2024-32828 |
Patchstack | |
| 4.3 Medium | USPS Shipping for WooCommerce – Live Rates | Cross-Site Request Forgery No login needed |
≤ 1.9.2 Fixed in 1.9.3 |
CVE-2024-31943 |
Patchstack | |
| 4.3 Medium | WooCommerce UPS Shipping – Live Rates and Access Points | Cross-Site Request Forgery No login needed |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2024-31944 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.