WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–27 of 27 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored XSS via Consent Logs No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85130 WPScan
6.5 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Arbitrary Post Deletion via CSRF No login needed < 4.4.4 Fixed in 4.4.4 CVE-2026-85131 WPScan
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter No login needed ≤ 4.4.1 CVE-2026-14989 Wordfence
5.4 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions < 4.4.2 Fixed in 4.4.2 CVE-2026-85133 WPScan
4.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Information Disclosure Subscriber+ Cookie Scan Schedule Disclosure via gcc_get_schedule_scan 4.0.2 – < 4.4.2 Fixed in 4.4.2 CVE-2026-85132 WPScan
4.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Subscriber+ Banner Settings Overwrite and A/B Test Data Reset 3.6.5 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82185 WPScan
5.3 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery Unauthenticated IAB TCF Consent Option Update No login needed 3.5.0 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82184 WPScan
4.1 Medium WPLP Cookie Consent Plugin gdpr-cookie-consent SQL Injection Admin+ SQLi via 'offset' Parameter 3.0.0 – < 4.4.2 Fixed in 4.4.2 CVE-2026-82186 WPScan
9.8 Critical WPLP Cookie Consent Plugin gdpr-cookie-consent Arbitrary File Upload Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint No login needed ≤ 4.4.1 CVE-2026-75865 Wordfence
10.0 Critical WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Arbitrary File Upload No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2026-82970 Patchstack
6.5 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Cross-Site Scripting ≤ 4.3.9 Fixed in 4.4.0 CVE-2026-73359 Patchstack
7.2 High Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'regionArray' Parameter No login needed ≤ 4.3.5 CVE-2026-13360 Wordfence
4.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries No login needed ≤ 4.3.7 CVE-2026-15136 Wordfence
4.3 Medium Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action ≤ 4.3.6 CVE-2026-12955 Wordfence
4.9 Medium Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent SQL Injection Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter ≤ 4.3.6 CVE-2026-14475 Wordfence
4.9 Medium Cookie Banner for GDPR / CCPA Plugin gdpr-cookie-consent SQL Injection Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 4.3.5 CVE-2026-12920 Wordfence
6.4 Medium WP GDPR Cookie Consent Plugin wp-gdpr-cookie-consent Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions' AJAX Action ≤ 1.0.0 CVE-2026-8977 Wordfence
7.5 High Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Sensitive Information Exposure No login needed ≤ 4.1.2 CVE-2025-11754 Wordfence
5.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Broken Access Control No login needed ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-66080 Patchstack
5.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 4.0.7 CVE-2025-14061 Wordfence
5.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Broken Access Control No login needed ≤ 4.0.7 Fixed in 4.0.8 CVE-2025-66133 Patchstack
4.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Broken Access Control ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-66075 Patchstack
7.1 High WP GDPR Cookie Consent Plugin wp-gdpr-cookie-consent Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-53316 Patchstack
4.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery No login needed ≤ 3.8.0 Fixed in 3.8.1 CVE-2025-49285 Patchstack
4.3 Medium Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) Plugin gdpr-cookie-consent Broken Access Control Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script ≤ 3.6.5 CVE-2024-11724 Wordfence
7.2 High WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) Plugin gdpr-cookie-consent Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Client-IP header No login needed ≤ 3.2.0 CVE-2024-4869 Wordfence
5.3 Medium WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 3.0.2 CVE-2024-3599 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only