WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–10 of 10 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical WS Form LITE Plugin ws-form PHP Object Injection Unauthenticated PHP Object Injection via Form Submission No login needed ≤ 1.10.80 CVE-2026-4703 Wordfence
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager PHP Object Injection No login needed ≤ 6.0.9.7 Fixed in 6.0.9.8 CVE-2026-73341 Patchstack
9.1 Critical Easy Post Submission Plugin easy-post-submission Broken Access Control Missing Authorization No login needed ≤ 2.3.0 CVE-2026-4431 Wordfence
9.1 Critical Link Library Plugin link-library SQL Injection Unauthenticated SQL Injection via the Front-End Link Submission Form No login needed < 7.9.3 Fixed in 7.9.3 CVE-2026-16532 WPScan
9.3 Critical Ninja Forms Plugin ninja-forms Cross-Site Scripting Ninja Forms Unauthenticated Stored Cross-Site Scripting via Repeatable Fieldset Submission Index No login needed 3.10.4 – < 3.14.9 Fixed in 3.14.9 CVE-2026-65048 VulnCheck
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Authentication Bypass Broken Authentication No login needed ≤ 6.0.8.6 Fixed in 6.0.8.7 CVE-2026-49764 Patchstack
9.1 Critical Order Notification for WooCommerce Plugin Authentication Bypass Unauthenticated WooCommerce REST Permission Bypass No login needed < 3.6.3 Fixed in 3.6.3 CVE-2025-15484 WPScan
9.8 Critical RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Unauthenticated Privilege Escalation via admin_order No login needed ≤ 6.0.7.1 CVE-2025-15403 Wordfence
9.8 Critical RegistrationMagic - Custom Registration Forms Plugin custom-registration-form-builder-with-submission-manager PHP Object Injection Custom Registration Forms <= 3.7.9.2 - PHP Object Injection No login needed < 3.7.9.3 Fixed in 3.7.9.3 CVE-2017-20208 Wordfence
9.8 Critical RegistrationMagic – User Registration Plugin with Custom Registration Forms Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery No login needed ≤ 6.0.2.6 CVE-2024-10508 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only