WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–33 of 33 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Mark on Map Longitude/Latitude Fields No login needed ≤ 1.15.47 CVE-2026-96813 Wordfence
6.1 Medium Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker Cross-Site Scripting Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting No login needed ≤ 1.15.46 CVE-2026-85645 Wordfence
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting No login needed ≤ 1.15.48 CVE-2026-66616 Patchstack
5.3 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Subscriber+) SQL Injection via '{username}' Placeholder in Dynamic-Choice Field WHERE Clause ≤ 1.15.44 CVE-2026-15993 Wordfence
8.1 High Form Maker by 10Web Plugin form-maker SQL Injection Subscriber+ SQL Injection via display_name < 1.15.45 Fixed in 1.15.45 CVE-2026-16977 WPScan
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter ≤ 1.15.43 CVE-2026-11776 Wordfence
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Administrator+) SQL Injection via 'name' Parameter ≤ 1.15.43 CVE-2026-11777 Wordfence
9.3 Critical Form Maker by 10Web Plugin form-maker SQL Injection No login needed ≤ 1.15.38 Fixed in 1.15.39 CVE-2026-39502 Patchstack
4.0 Medium Contact Form Maker Plugin contact-form-maker Cross-Site Request Forgery Contact Form by WD 1.13.1 CSRF to Local File Inclusion No login needed 1.13.1 CVE-2019-25734 VulnCheck
7.1 High Contact Form Maker Plugin contact-form-maker SQL Injection WordPress Contact Form Maker Plugin 1.12.20 SQL Injection ≤ 1.12.20 CVE-2018-25347 VulnCheck
7.5 High Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker SQL Injection Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.42 - Unauthenticated SQL Injection via 'inputs' No login needed ≤ 1.15.42 CVE-2026-3359 Wordfence
4.9 Medium Form Maker by 10Web Plugin form-maker SQL Injection Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter ≤ 1.15.40 CVE-2026-3330 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Matrix Field Text Box No login needed ≤ 1.15.40 CVE-2026-4388 Wordfence
6.8 Medium Form Maker Plugin form-maker SQL Injection No login needed < 1.15.38 Fixed in 1.15.38 CVE-2025-15441 WPScan
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Hidden Field No login needed ≤ 1.15.35 CVE-2026-1058 Wordfence
7.2 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG file No login needed ≤ 1.15.35 CVE-2026-1065 Wordfence
5.9 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting ≤ 1.15.33 Fixed in 1.15.34 CVE-2025-48341 Patchstack
4.8 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS via Theme Title < 1.15.33 Fixed in 1.15.33 CVE-2024-13053 WPScan
4.8 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.32 Fixed in 1.15.32 CVE-2024-10680 WPScan
3.5 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.30 Fixed in 1.15.30 CVE-2024-10560 WPScan
3.5 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.30 Fixed in 1.15.30 CVE-2024-10558 WPScan
4.8 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.33 Fixed in 1.15.33 CVE-2024-13605 WPScan
2.7 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.31 Fixed in 1.15.31 CVE-2024-10562 WPScan
6.1 Medium Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker Cross-Site Scripting Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.30 - Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 1.15.30 CVE-2024-10265 Wordfence
5.5 Medium Form Maker Plugin form-maker Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.15.27 CVE-2024-8633 Wordfence
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.15.26 CVE-2024-43220 Patchstack
4.8 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.26 Fixed in 1.15.26 CVE-2024-6130 WPScan
5.3 Medium Form Maker by 10Web Plugin form-maker Authentication Bypass Captcha Bypass Vulnerability No login needed ≤ 1.15.20 Fixed in 1.15.21 CVE-2023-48290 Patchstack
5.9 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting ≤ 1.15.24 Fixed in 1.15.25 CVE-2024-34437 Patchstack
4.4 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting ≤ 1.15.24 CVE-2024-2258 Wordfence
5.9 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting ≤ 1.15.23 Fixed in 1.15.24 CVE-2024-32534 Patchstack
5.9 Medium Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker Information Disclosure Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure No login needed ≤ 1.15.22 CVE-2024-2112 Wordfence
5.4 Medium Form-Maker (twb_form-maker) Plugin form-maker Cross-Site Request Forgery Cross-Site Request Forgery to Limited Code Execution via Execute No login needed ≤ 1.15.21 CVE-2024-0667 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only