WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–38 of 38 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Masteriyo LMS Plugin learning-management-system PHP Object Injection Subscriber+ PHP Object Injection < 3.4.1 Fixed in 3.4.1 CVE-2026-82845 WPScan
9.8 Critical Tutor LMS Plugin tutor Content Injection Unauthenticated Arbitrary Zero-Argument Function Invocation via Template Variable Shadowing No login needed 2.1.3 – < 4.0.6 Fixed in 4.0.6 CVE-2026-19092 WPScan
9.8 Critical Masteriyo - LMS Plugin learning-management-system Arbitrary File Upload LMS plugin <= 2.3.2 - Arbitrary File Upload No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-73996 Patchstack
9.1 Critical Masteriyo LMS Plugin learning-management-system Denial of Service Unauthenticated Arbitrary User Session Termination (Denial of Service) No login needed < 2.3.1 Fixed in 2.3.1 CVE-2026-13332 WPScan
9.3 Critical Tutor LMS Pro Plugin tutor-pro SQL Injection No login needed ≤ 3.9.6 Fixed in 3.9.7 CVE-2026-22332 Patchstack
9.8 Critical Masteriyo LMS PRO Plugin learning-management-system-pro Privilege Escalation No login needed ≤ 2.20.0 Fixed in 2.20.1 CVE-2025-53209 Patchstack
9.8 Critical Tutor LMS Pro Plugin Authentication Bypass Authentication Bypass via Social Login No login needed ≤ 3.9.5 CVE-2026-0953 Wordfence
9.8 Critical LMS Elementor Pro Plugin lms-elementor-pro Privilege Escalation No login needed ≤ 1.0.4 CVE-2026-27983 Patchstack
9.8 Critical Lizza LMS Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2025-13563 Wordfence
9.8 Critical Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy Privilege Escalation WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.5.0 CVE-2025-15521 Wordfence
9.8 Critical Fox LMS – WordPress LMS Plugin fox-lms Privilege Escalation WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder' No login needed 1.0.4.7 – 1.0.5.1 CVE-2025-14156 Wordfence
9.8 Critical DesignThemes LMS Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.4 CVE-2025-13542 Wordfence
9.8 Critical CoSchool LMS Plugin coschool PHP Object Injection No login needed ≤ 1.4.3 CVE-2025-30973 Patchstack
9.3 Critical LMS Plugin lms SQL Injection No login needed ≤ 9.2 Fixed in 9.3 CVE-2025-52833 Patchstack
9.8 Critical Education Center | LMS & Online Courses Theme PHP Object Injection No login needed ≤ 3.6.10 CVE-2024-13786 Wordfence
9.3 Critical LifterLMS Plugin lifterlms SQL Injection No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2025-52717 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56045 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Authentication Bypass Unauthenticated Arbitrary User Token Generation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56044 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56043 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56042 Patchstack
10.0 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56046 Patchstack
9.9 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56050 Patchstack
9.9 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Student+ Arbitrary File Upload ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56052 Patchstack
9.1 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Instructor+ Arbitrary File Upload ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56054 Patchstack
9.9 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56057 Patchstack
9.8 Critical CoSchool LMS Plugin coschool Privilege Escalation Account Takeover No login needed ≤ 1.4.3 CVE-2024-54296 Patchstack
9.8 Critical WPLMS Learning Management System Theme Path Traversal Unauthenticated Arbitrary File Read and Deletion No login needed ≤ 4.962 CVE-2024-10470 Wordfence
9.9 Critical Property Lot Management System Plugin plms Arbitrary File Upload ≤ 4.2.38 CVE-2024-49331 Patchstack
10.0 Critical LearnPress – WordPress LMS Plugin SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' No login needed ≤ 4.2.7 CVE-2024-8529 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' No login needed ≤ 4.2.7 CVE-2024-8522 Wordfence
9.1 Critical MasterStudy LMS Plugin Privilege Escalation Privilege Escalation to Instructor No login needed < 3.3.24 Fixed in 3.3.24 CVE-2024-5973 WPScan
9.8 Critical Masteriyo - LMS Plugin learning-management-system Privilege Escalation No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-24882 Patchstack
9.8 Critical Tutor LMS Plugin tutor Broken Access Control Missing Authorization No login needed ≤ 2.7.0 CVE-2024-4223 Wordfence
9.8 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection No login needed ≤ 4.2.6.5 CVE-2024-4434 Wordfence
9.8 Critical MasterStudy LMS Plugin masterstudy-lms-learning-management-system Local File Inclusion Unauthenticated Local File Inclusion via template No login needed ≤ 3.3.3 CVE-2024-3136 Wordfence
9.8 Critical MasterStudy LMS Plugin masterstudy-lms-learning-management-system Local File Inclusion Unauthenticated Local File Inclusion via modal No login needed ≤ 3.3.0 CVE-2024-2411 Wordfence
9.8 Critical MasterStudy LMS Plugin masterstudy-lms-learning-management-system Privilege Escalation Unauthenticated Privilege Escalation via stm_lms_register AJAX Action No login needed ≤ 3.3.1 CVE-2024-2409 Wordfence
9.8 Critical MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system SQL Injection for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection No login needed ≤ 3.2.5 CVE-2024-1512 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only