WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 1–30 of 30 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Popup Builder Plugin popup-builder Cross-Site Scripting WordPress Popup Builder 3.49 Persistent Cross-Site Scripting 3.49 CVE-2019-25744 VulnCheck
5.3 Medium Instant Popup Builder Plugin instant-popup-builder Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter No login needed ≤ 1.1.7 CVE-2026-3475 Wordfence
5.3 Medium Popup Builder - Create highly converting, mobile friendly marketing popups. Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed ≤ 4.4.2 CVE-2025-13079 Wordfence
5.4 Medium PopupKit Plugin popup-builder-block Broken Access Control Missing Authorization to Sensitive Information Disclosure and Data Deletion ≤ 2.2.0 CVE-2025-14895 Wordfence
8.2 High Popup builder with Gamification Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via Multiple REST API Endpoints No login needed ≤ 2.2.0 CVE-2025-13192 Wordfence
6.4 Medium ConvertForce Popup Builder Plugin convertforce-popup-builder Cross-Site Scripting Stored Cross-Site Scripting via entrance_animation ≤ 0.0.7 CVE-2025-14506 Wordfence
4.3 Medium Popupkit Plugin popup-builder-block Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data Deletion ≤ 2.2.0 CVE-2025-14441 Wordfence
4.3 Medium PopupKit Plugin popup-builder-block Information Disclosure Sensitive Data Exposure ≤ 2.1.5 Fixed in 2.2.1 CVE-2025-69026 Patchstack
5.3 Medium Brave Plugin brave-popup-builder Broken Access Control No login needed ≤ 0.8.3 Fixed in 0.8.4 CVE-2025-68508 Patchstack
8.5 High PopupKit Plugin popup-builder-block SQL Injection ≤ 2.1.5 Fixed in 2.2.0 CVE-2025-14314 Patchstack
6.4 Medium Popup Builder – Create highly converting, mobile friendly marketing popups. Plugin popup-builder Cross-Site Scripting Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.4.1 CVE-2025-9856 Wordfence
5.3 Medium WP Popup Builder Plugin wp-popup-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.8 Fixed in 1.3.9 CVE-2025-62902 Patchstack
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.1.4 CVE-2025-10861 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 2.1.3 CVE-2025-10862 Wordfence
5.9 Medium Pretty Simple Popup Builder Plugin pretty-simple-popup-builder Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.9 Fixed in 1.0.10 CVE-2024-56298 Patchstack
4.8 Medium Popup Builder Plugin popup-builder Cross-Site Scripting Admin+ Stored XSS < 4.3.5 Fixed in 4.3.5 CVE-2024-9428 WPScan
7.3 High WP Popup Builder – Popup Forms and Marketing Lead Generation Plugin wp-popup-builder Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed ≤ 1.3.5 CVE-2024-9061 Wordfence
5.3 Medium Popup Builder Plugin popup-builder Information Disclosure Sensitive Information Exposure via Imported Subscribers CSV File No login needed ≤ 4.3.6 CVE-2024-2541 Wordfence
4.3 Medium Brave Popup Builder Plugin brave-popup-builder Cross-Site Request Forgery No login needed ≤ 0.7.0 Fixed in 0.7.1 CVE-2024-43337 Patchstack
5.9 Medium Pretty Simple Popup Builder Plugin pretty-simple-popup-builder Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2024-39626 Patchstack
4.3 Medium Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer Plugin promolayer-popup-builder Broken Access Control Promolayer <= 1.1.0 - Missing Authorization ≤ 1.1.0 CVE-2024-3602 Wordfence
8.1 High Popup Builder – Create highly converting, mobile friendly marketing popups Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure ≤ 4.3.1 CVE-2023-6696 Wordfence
7.4 High Popup Builder Plugin popup-builder Broken Access Control Missing Authorization in Multiple AJAX Actions ≤ 4.3.0 CVE-2024-2544 Wordfence
5.9 Medium Brave Plugin brave-popup-builder Cross-Site Scripting Interactive Content plugin <= 0.6.9 - Cross Site Scripting (XSS) ≤ 0.6.9 Fixed in 0.7.0 CVE-2024-35655 Patchstack
6.4 Medium Popup Builder Plugin popup-builder Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 4.2.7 CVE-2024-2506 Wordfence
5.4 Medium Brave Popup Builder Plugin brave-popup-builder Server-Side Request Forgery No login needed ≤ 0.6.5 Fixed in 0.6.6 CVE-2024-30453 Patchstack
6.5 Medium Popup Builder Plugin popup-builder Cross-Site Scripting ≤ 4.2.6 Fixed in 4.2.7 CVE-2024-30184 Patchstack
7.5 High popup-builder Plugin Server-Side Request Forgery Admin+ SSRF & File Read No login needed < 4.2.6 Fixed in 4.2.6 CVE-2023-6294 WPScan
5.9 Medium Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content Plugin brave-popup-builder Cross-Site Scripting WordPress Brave Popup Builder Plugin <= 0.6.2 is vulnerable to Cross Site Scripting (XSS) ≤ 0.6.2 Fixed in 0.6.3 CVE-2023-51534 Patchstack
6.1 Medium Popup Builder Plugin popup-builder Cross-Site Scripting Unauthenticated Stored XSS No login needed < 4.2.3 Fixed in 4.2.3 CVE-2023-6000 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only