WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–14 of 14 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WPC Smart Compare for WooCommerce Plugin woo-smart-compare Information Disclosure Unauthenticated Password-Protected Product Description Disclosure via woosc_load No login needed < 6.6.1 Fixed in 6.6.1 CVE-2026-90985 WPScan
5.3 Medium Motors – Car Dealership & Classified Listings Plugin Broken Access Control Car Dealership & Classified Listings <= 1.4.120 - Missing Authorization to Unauthenticated Private/Draft/Password-Protected Listings Exposure No login needed ≤ 1.4.120 CVE-2026-16750 Wordfence
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema Output No login needed < 1.66 Fixed in 1.66 CVE-2026-82124 WPScan
5.3 Medium Post Carousel Plugin Information Disclosure Unauthenticated Password-Protected Post Content and post_password Disclosure via sp_handle_post_id No login needed 4.0.0 – < 4.0.8 Fixed in 4.0.8 CVE-2026-78149 WPScan
5.3 Medium Rank Math SEO Plugin seo-by-rank-math Information Disclosure Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt No login needed < 1.0.277.1 Fixed in 1.0.277.1 CVE-2026-77782 WPScan
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Information Disclosure Unauthenticated Password-Protected Product Information Disclosure No login needed < 1.34.1 Fixed in 1.34.1 CVE-2026-16612 WPScan
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads No login needed ≤ 10.3.1 CVE-2025-9637 Wordfence
5.3 Medium Zip Attachments Plugin zip-attachments Broken Access Control Missing Authorization to Unauthenticated Private And Password-Protected Posts Attachment Disclosure No login needed ≤ 1.6 CVE-2025-11701 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Missing Authorization to Unauthenticated Password-Protected Information Disclosure No login needed ≤ 6.15.2 CVE-2025-9808 Wordfence
5.3 Medium BetterDocs Plugin betterdocs Broken Access Control Missing Authorization to Private And Password-Protected Posts Information Disclosure No login needed ≤ 4.1.1 CVE-2025-7499 Wordfence
5.3 Medium Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products Plugin password-protected Information Disclosure Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.7.7 CVE-2025-3453 Wordfence
5.3 Medium Download manager Plugin download-manager Broken Access Control Improper Authorization to Unauthenticated Download of Password-Protected Files No login needed ≤ 3.3.03 CVE-2024-11768 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure No login needed ≤ 4.0.4.3 CVE-2024-8369 Wordfence
5.3 Medium Password Protected Store for WooCommerce Plugin password-protected-woo-store Information Disclosure Information Exposure via REST API No login needed ≤ 2.2 CVE-2024-1088 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only