WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–28 of 28 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Fluent Forms Pro Add On Pack Plugin fluentformpro Broken Access Control No login needed ≤ 6.2.13 Fixed in 6.2.14 CVE-2026-94669 Patchstack
6.5 Medium FluentForm Plugin fluentform Cross-Site Scripting ≤ 6.2.14 Fixed in 6.2.15 CVE-2026-103343 Patchstack
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 6.2.14 Fixed in 6.2.15 CVE-2026-103353 Patchstack
6.1 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Reflected Cross-Site Scripting via 'param' No login needed ≤ 6.2.8 CVE-2026-17571 Wordfence
5.3 Medium Fluent Forms Plugin fluentform Information Disclosure Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter No login needed ≤ 6.2.8 CVE-2026-17567 Wordfence
6.1 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Contributor+ Stored XSS via Date/Time Field No login needed < 6.2.6 Fixed in 6.2.6 CVE-2026-11881 WPScan
5.4 Medium Fluent Forms Plugin fluentform Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id' ≤ 6.2.1 CVE-2026-5069 Wordfence
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'permission_message' Shortcode Attribute ≤ 6.2.1 CVE-2026-6828 Wordfence
4.9 Medium Fluent Forms Plugin fluentform Path Traversal Authenticated (Administrator+) Arbitrary File Read via Path Traversal in Email Attachment ≤ 6.2.1 CVE-2026-6344 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
4.3 Medium FluentForm Plugin fluentform Broken Access Control ≤ 6.1.14 Fixed in 6.1.15 CVE-2026-25313 Patchstack
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via AI Form Builder Module ≤ 6.1.14 CVE-2026-0996 Wordfence
5.3 Medium FluentForm Plugin fluentform Arbitrary Shortcode Execution No login needed ≤ 6.1.11 Fixed in 6.1.12 CVE-2025-69001 Patchstack
5.3 Medium Fluent Forms Plugin fluentform Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Creation via AI Builder No login needed ≤ 6.1.7 CVE-2025-13722 Wordfence
5.3 Medium Fluent Forms Plugin fluentform Broken Access Control Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id No login needed ≤ 6.1.7 CVE-2025-13748 Wordfence
6.5 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read 5.1.16 – 6.1.1 CVE-2025-9260 Wordfence
6.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.2 CVE-2025-3615 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Other Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing No login needed ≤ 5.2.12 CVE-2024-13666 Wordfence
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 5.0.8 Fixed in 5.0.9 CVE-2023-41952 Patchstack
4.9 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Form Manager+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-9528 Wordfence
4.2 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification ≤ 5.1.18 CVE-2024-5053 Wordfence
4.9 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Welcome Screen Fields ≤ 5.1.19 CVE-2024-6703 Wordfence
4.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-6518 Wordfence
4.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-6520 Wordfence
4.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.19 CVE-2024-6521 Wordfence
6.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.16 CVE-2024-4709 Wordfence
4.9 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.9 CVE-2023-6957 Wordfence
4.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title ≤ 5.1.5 CVE-2024-0618 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only