WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 77 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WPLMS Theme wplms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.972 CVE-2026-39722 Patchstack
7.5 High Creator LMS Plugin creatorlms Path Traversal ≤ 1.2.19 Fixed in 1.2.20 CVE-2026-97244 Patchstack
7.2 High MasterStudy LMS 3.5.29 Plugin Local File Inclusion < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget 3.5.29 – < 3.7.50 Fixed in 3.7.50 CVE-2026-88843 WPScan
7.2 High Tutor LMS 2.7.1 Plugin Privilege Escalation < 4.0.8 - Read-Only API Key Privilege Escalation via REST Request Misclassification 2.7.1 – < 4.0.8 Fixed in 4.0.8 CVE-2026-85569 WPScan
8.8 High Tutor LMS Plugin tutor PHP Object Injection Authenticated (Subscriber+) PHP Object Injection to Remote Code Execution ≤ 4.0.7 CVE-2026-78175 Wordfence
8.8 High Masteriyo - LMS Plugin learning-management-system PHP Object Injection LMS plugin <= 3.4.0 - PHP Object Injection ≤ 3.4.0 Fixed in 3.4.1 CVE-2026-62107 Patchstack
7.5 High LearnDash LMS Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler ≤ 5.1.5 CVE-2026-12483 Wordfence
8.1 High Agentimus – AI SEO, llms.txt & MCP for AI Agents Plugin agentimus Broken Access Control AI SEO, llms.txt & MCP for AI Agents plugin <= 1.51.0 - Broken Access Control ≤ 1.51.0 Fixed in 1.51.1 CVE-2026-84779 Patchstack
8.6 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Arbitrary File Deletion No login needed ≤ 3.7.42 Fixed in 3.7.43 CVE-2026-78284 Patchstack
7.1 High Tutor LMS Plugin tutor Broken Access Control Subscriber+ Unauthorized Course Enrollment and Private Course Content Disclosure via Droip/Kirki Integration < 3.9.13 Fixed in 3.9.13 CVE-2026-12275 WPScan
7.1 High LMS Theme lms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.7 CVE-2026-27404 Patchstack
8.0 High Academy LMS Pro Plugin academy-pro Arbitrary File Upload < 3.5.2 Fixed in 3.5.2 CVE-2026-39598 Patchstack
8.5 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection ≤ 3.7.25 Fixed in 3.7.26 CVE-2026-40766 Patchstack
7.5 High Masteriyo - LMS Plugin learning-management-system Price Manipulation LMS plugin <= 2.1.5 - Payment Bypass No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2026-39524 Patchstack
8.8 High Masteriyo - LMS Plugin learning-management-system Privilege Escalation LMS plugin <= 2.2.0 - Privilege Escalation ≤ 2.2.0 Fixed in 2.2.1 CVE-2026-49111 Patchstack
8.5 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection ≤ 3.7.29 Fixed in 3.7.30 CVE-2026-42730 Patchstack
7.5 High Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter No login needed ≤ 3.9.7 CVE-2026-3360 Wordfence
8.8 High Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator ≤ 2.1.6 CVE-2026-4484 Wordfence
8.8 High Creator LMS Plugin creatorlms Privilege Escalation ≤ <= 1.1.18 Fixed in 1.1.19 CVE-2026-32530 Patchstack
8.1 High Tutor LMS Pro Plugin tutor-pro Authentication Bypass Broken Authentication No login needed ≤ 3.9.4 CVE-2026-25406 Patchstack
7.1 High Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.2.6 Fixed in 8.2.7 CVE-2026-27068 Patchstack
8.5 High Fox LMS Plugin fox-lms SQL Injection ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2026-31922 Patchstack
7.5 High Tutor LMS Plugin tutor SQL Injection Unauthenticated SQL Injection via coupon_code No login needed ≤ 3.9.6 CVE-2025-13673 Wordfence
8.1 High Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion ≤ 3.9.5 CVE-2026-1375 Wordfence
8.6 High WPLMS Plugin wplms_plugin Arbitrary File Deletion No login needed ≤ 1.9.9.5.4 CVE-2025-69097 Patchstack
8.8 High Creator LMS – The LMS for Creators, Coaches, and Trainers Plugin creatorlms Broken Access Control The LMS for Creators, Coaches, and Trainers <= 1.1.12 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update ≤ 1.1.12 CVE-2025-15347 Wordfence
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64214 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64213 Patchstack
8.8 High LifterLMS Plugin lifterlms Privilege Escalation WP LMS for eLearning, Online Courses, & Quizzes - Various Versions - Authenticated (Student+) Privilege Escalation 3.5.3 – 3.41.1, 4.0.0 – 4.21.3, 5.0.0 – 5.10.0, … CVE-2025-11923 Wordfence
7.2 High Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy PHP Object Injection WordPress LMS Plugin for Complete eLearning Solution <= 3.3.8 - Authenticated (Administrator+) PHP Object Injection via 'import_all_courses' ≤ 3.3.8 CVE-2025-12099 Wordfence
8.5 High CoSchool LMS Plugin coschool SQL Injection ≤ 1.4.3 CVE-2025-60239 Patchstack
7.6 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection ≤ 3.6.27 Fixed in 3.6.28 CVE-2025-64366 Patchstack
7.1 High WPLMS Plugin wplms_plugin Cross-Site Scripting No login needed ≤ 1.9.9.8 CVE-2025-53420 Patchstack
7.5 High WPLMS Plugin wplms_plugin Broken Access Control No login needed ≤ 1.9.9.7 Fixed in 1.9.9.8 CVE-2025-49925 Patchstack
8.1 High Academy LMS Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation via Social Login Addon No login needed ≤ 3.3.7 CVE-2025-11086 Wordfence
7.6 High Tutor LMS Plugin tutor SQL Injection ≤ 3.7.4 Fixed in 3.8.0 CVE-2025-58993 Patchstack
8.8 High Tutor LMS Pro – eLearning and online course solution Plugin tutor SQL Injection eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection ≤ 3.7.0 CVE-2025-6184 Wordfence
8.8 High WPLMS Learning Management System for WordPress, WordPress LMS Theme Privilege Escalation ≤ 1.8.4.1 CVE-2015-10139 Wordfence
7.5 High MasterStudy LMS – Online Courses, eLearning PRO Plus Plugin Arbitrary File Upload Online Courses, eLearning PRO Plus <= 4.7.9 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.7.9 CVE-2025-7438 Wordfence
7.1 High LMS Plugin lms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.2 Fixed in 9.3 CVE-2025-52799 Patchstack
8.8 High MasterStudy LMS Pro Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.7.0 CVE-2025-4800 Wordfence
8.8 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Local File Inclusion ≤ 3.5.28 Fixed in 3.5.29 CVE-2025-32141 Patchstack
7.1 High Sikshya LMS Plugin sikshya Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.21 Fixed in 0.0.22 CVE-2025-24630 Patchstack
7.1 High LucidLMS Plugin lucidlms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2025-22498 Patchstack
8.5 High WPLMS Plugin wplms_plugin SQL Injection Subscriber+ SQL Injection ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56047 Patchstack
7.6 High WPLMS Plugin wplms_plugin SQL Injection Instructor+ SQL Injection ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56053 Patchstack
8.8 High WPLMS Plugin wplms_plugin Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56048 Patchstack
8.5 High WPLMS Plugin wplms_plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56049 Patchstack
8.5 High WPLMS Plugin wplms_plugin Arbitrary File Deletion Arbitrary Directory Deletion ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56055 Patchstack
8.5 High WPLMS Plugin wplms_plugin Remote Code Execution Student+ Remote Code Execution (RCE) ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56051 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only