WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–24 of 24 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute ≤ 4.0.8 CVE-2026-92746 Wordfence
8.8 High Gutenverse News Plugin gutenverse-news Cross-Site Scripting Unauthenticated Stored XSS via Comment Content No login needed < 3.3.3 Fixed in 3.3.3 CVE-2026-85677 WPScan
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Blocks ≤ 4.0.2 CVE-2026-3002 Wordfence
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' Block Attribute ≤ 4.0.2 CVE-2026-19943 Wordfence
7.2 High Gutenverse Companion Plugin gutenverse-companion Server-Side Request Forgery No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-66704 Patchstack
4.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via 'fonts[].font.font.value' Parameter ≤ 3.8.0 CVE-2026-12399 Wordfence
7.1 High Gutenverse Form Plugin gutenverse-form Cross-Site Scripting No login needed ≤ 2.4.7 Fixed in 2.5.0 CVE-2026-56040 Patchstack
7.5 High Gutenverse Companion Plugin gutenverse-companion Broken Access Control No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2026-54832 Patchstack
6.1 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Reflected Cross-Site Scripting via 's' Parameter No login needed ≤ 3.4.6 CVE-2026-3001 Wordfence
6.4 Medium Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem Plugin gutenverse Server-Side Request Forgery Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Server-Side Request Forgery via 'imageUrl' ≤ 3.5.3 CVE-2026-2948 Wordfence
6.4 Medium Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem Plugin gutenverse Cross-Site Scripting Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'separatorIconSVG' ≤ 3.5.3 CVE-2026-2868 Wordfence
6.4 Medium Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem Plugin gutenverse Cross-Site Scripting Ultimate WordPress FSE Blocks Addons & Ecosystem <= 3.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'imageLoad' ≤ 3.4.6 CVE-2026-2924 Wordfence
6.4 Medium Gutenverse Form Plugin gutenverse-form Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.3.2 CVE-2025-14984 Wordfence
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-68511 Patchstack
6.5 Medium Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons Plugin gutenverse-news Broken Access Control Advanced News Magazine Blog Gutenberg Blocks Addons plugin <= 3.0.2 - Broken Access Control ≤ 3.0.2 Fixed in 3.1.0 CVE-2025-62090 Patchstack
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.2.0 Fixed in 2.3.0 CVE-2025-66079 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Broken Access Control ≤ 3.2.1 Fixed in 3.3.0 CVE-2025-66065 Patchstack
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Fun Fact Blocks ≤ 3.1.0 CVE-2025-7727 Wordfence
6.4 Medium Gutenverse News Plugin gutenverse-news Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via elementId Parameter ≤ 1.0.4 CVE-2025-5234 Wordfence
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via countdown Block ≤ 2.2.1 CVE-2025-2893 Wordfence
5.3 Medium Gutenverse Plugin gutenverse Broken Access Control Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.8.5 - Broken Access Control No login needed ≤ 1.8.5 Fixed in 1.8.6 CVE-2023-35875 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.9.4 - Cross Site Scripting (XSS) ≤ 1.9.4 Fixed in 2.0.0 CVE-2024-43920 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Cross-Site Scripting ≤ 1.9.2 Fixed in 1.9.3 CVE-2024-38785 Patchstack
6.1 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Contributor+ Stored XSS No login needed < 1.9.1 Fixed in 1.9.1 CVE-2024-3692 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only