WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–23 of 23 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Pagelayer Plugin pagelayer Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts' ≤ 2.0.9 CVE-2026-2470 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block ≤ 2.0.9 CVE-2026-3297 Wordfence
6.4 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes ≤ 2.0.8 CVE-2026-2509 Wordfence
4.3 Medium PageLayer Plugin pagelayer Information Disclosure Sensitive Data Exposure ≤ 2.0.8 Fixed in 2.0.9 CVE-2026-39469 Patchstack
5.3 Medium Pagelayer Plugin pagelayer Content Injection Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via 'email' No login needed ≤ 2.0.7 CVE-2026-2442 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Broken Access Control Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference ≤ 2.0.5 CVE-2025-12366 Wordfence
4.7 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter No login needed ≤ 2.0.0 CVE-2025-4223 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link ≤ 2.0.0 CVE-2024-13427 Wordfence
4.8 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Page Builder: Pagelayer < 1.9.0- Admin+ Stored XSS < 1.9.0 Fixed in 1.9.0 CVE-2024-8618 WPScan
4.8 Medium Pagelayer Plugin Cross-Site Scripting Admin+ Stored XSS < 1.8.8 Fixed in 1.8.8 CVE-2024-8426 WPScan
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Broken Access Control Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication ≤ 1.9.8 CVE-2025-2104 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Information Disclosure Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode ≤ 1.9.8 CVE-2024-13430 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
6.5 Medium PageLayer Plugin pagelayer Cross-Site Scripting ≤ 1.9.4 Fixed in 1.9.5 CVE-2025-24573 Patchstack
4.3 Medium PageLayer Plugin pagelayer Broken Access Control ≤ 1.7.7 Fixed in 1.7.8 CVE-2023-49196 Patchstack
5.9 Medium PageLayer Plugin pagelayer Cross-Site Scripting Drag and Drop website builder plugin <= 1.8.7 - Cross Site Scripting (XSS) ≤ 1.8.7 Fixed in 1.8.8 CVE-2024-43972 Patchstack
6.5 Medium PageLayer Plugin pagelayer Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2024-30465 Patchstack
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes ≤ 1.8.4 CVE-2024-2504 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes ≤ 1.8.3 CVE-2024-2127 Wordfence
4.8 Medium PageLayer Plugin Cross-Site Scripting Admin+ Stored XSS < 1.8.1 Fixed in 1.8.1 CVE-2023-7115 WPScan
4.6 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button ≤ 1.8.2 CVE-2024-1590 Wordfence
4.8 Medium PageLayer Plugin Cross-Site Scripting Author+ Stored XSS 1.3.2 – < 1.8.0 Fixed in 1.8.0 CVE-2023-5124 WPScan
5.4 Medium PageLayer Plugin pagelayer Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields ≤ 1.7.8 CVE-2023-6738 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only