WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–42 of 42 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium FluentForm Plugin fluentform Cross-Site Scripting ≤ 6.2.14 Fixed in 6.2.15 CVE-2026-103343 Patchstack
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 6.2.14 Fixed in 6.2.15 CVE-2026-103353 Patchstack
7.5 High Fluent Forms Pro Add On Pack Plugin fluentformpro Privilege Escalation ≤ 6.2.12 Fixed in 6.2.13 CVE-2026-81297 Patchstack
7.5 High Fluent Forms Pro Add On Pack Plugin fluentformpro Broken Access Control No login needed ≤ 6.2.12 Fixed in 6.2.13 CVE-2026-81296 Patchstack
7.1 High Fluent Forms Pro Add On Pack Plugin fluentformpro Cross-Site Scripting No login needed < 6.2.12 Fixed in 6.2.12 CVE-2026-66633 Patchstack
9.8 Critical Fluent Forms Pro Plugin fluentformpro Other Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build No login needed 6.2.7 CVE-2026-73532 VulnCheck
7.2 High Fluent Forms Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Notification Smartcode Values No login needed ≤ 6.2.11 CVE-2026-18146 Wordfence
6.1 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Reflected Cross-Site Scripting via 'param' No login needed ≤ 6.2.8 CVE-2026-17571 Wordfence
5.3 Medium Fluent Forms Plugin fluentform Information Disclosure Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter No login needed ≤ 6.2.8 CVE-2026-17567 Wordfence
6.1 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Contributor+ Stored XSS via Date/Time Field No login needed < 6.2.6 Fixed in 6.2.6 CVE-2026-11881 WPScan
7.2 High Fluent Forms Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member No login needed ≤ 6.2.7 CVE-2026-16655 Wordfence
5.4 Medium Fluent Forms Plugin fluentform Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' ≤ 6.2.1 CVE-2026-5069 Wordfence
2.7 Low Fluent Forms Plugin fluentform Broken Access Control Form Manager+ Cross-Form Submission Entry Deletion via IDOR < 6.2.5 Fixed in 6.2.5 CVE-2026-11578 WPScan
3.1 Low Fluent Forms Plugin fluentform Broken Access Control Subscriber+ Subscription Cancellation via IDOR < 6.2.1 Fixed in 6.2.1 CVE-2026-11880 WPScan
8.2 High Fluent Forms Plugin fluentform Broken Access Control Authenticated (Subscriber+) Authorization Bypass via 'table' Parameter No login needed ≤ 6.2.0 CVE-2026-5395 Wordfence
8.2 High Fluent Forms Plugin fluentform Broken Access Control Authenticated (Subscriber+) Authorization Bypass via 'form_id' Parameter No login needed ≤ 6.1.21 CVE-2026-5396 Wordfence
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute ≤ 6.2.1 CVE-2026-6828 Wordfence
4.9 Medium Fluent Forms Plugin fluentform Path Traversal Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment ≤ 6.2.1 CVE-2026-6344 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
7.2 High Fluent Forms Pro Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Draft Form Submission No login needed ≤ 6.1.17 CVE-2026-2365 Wordfence
4.3 Medium FluentForm Plugin fluentform Broken Access Control ≤ 6.1.14 Fixed in 6.1.15 CVE-2026-25313 Patchstack
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module ≤ 6.1.14 CVE-2026-0996 Wordfence
5.3 Medium FluentForm Plugin fluentform Arbitrary Shortcode Execution No login needed ≤ 6.1.11 Fixed in 6.1.12 CVE-2025-69001 Patchstack
5.3 Medium Fluent Forms Plugin fluentform Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder No login needed ≤ 6.1.7 CVE-2025-13722 Wordfence
5.3 Medium Fluent Forms Plugin fluentform Broken Access Control Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id No login needed ≤ 6.1.7 CVE-2025-13748 Wordfence
6.5 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read 5.1.16 – 6.1.1 CVE-2025-9260 Wordfence
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.2 CVE-2025-3615 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Other Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing No login needed ≤ 5.2.12 CVE-2024-13666 Wordfence
7.2 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Subject No login needed ≤ 5.2.6 CVE-2024-10646 Wordfence
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 5.0.8 Fixed in 5.0.9 CVE-2023-41952 Patchstack
4.9 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Form Manager+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-9528 Wordfence
4.2 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification ≤ 5.1.18 CVE-2024-5053 Wordfence
4.9 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields ≤ 5.1.19 CVE-2024-6703 Wordfence
4.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-6518 Wordfence
4.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-6520 Wordfence
4.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-6521 Wordfence
7.5 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform PHP Object Injection PHP Object Injection via extractDynamicValues ≤ 5.1.15 CVE-2024-4157 Wordfence
6.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.16 CVE-2024-4709 Wordfence
7.5 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Setting Manipulation No login needed ≤ 5.1.16 CVE-2024-2782 Wordfence
9.8 Critical Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Settings Update and Limited Privilege Escalation No login needed ≤ 5.1.16 CVE-2024-2771 Wordfence
4.9 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.9 CVE-2023-6957 Wordfence
4.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title ≤ 5.1.5 CVE-2024-0618 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only