WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–42 of 42 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Progress Planner Plugin progress-planner Broken Access Control ≤ 1.10.0 Fixed in 1.10.1 CVE-2026-62072 Patchstack
7.1 High Progressify - Progressive Web App (PWA) Plugin daftplug-progressify Cross-Site Scripting Progressive Web App (PWA) plugin <= 1.6.0 - Cross Site Scripting (XSS) No login needed ≤ 1.6.0 CVE-2026-32570 Patchstack
4.3 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Subscriber+ Arbitrary User Course Progress Disclosure via IDOR < 3.4.2 Fixed in 3.4.2 CVE-2026-82849 WPScan
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Unauthenticated Arbitrary Course Progress Deletion No login needed ≤ 2.2.0 CVE-2026-8279 Wordfence
4.3 Medium Ninja Forms - Save Progress Plugin Broken Access Control Save Progress <= 3.0.30 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Data Deletion via admin-ajax.php with admin_init Hook ≤ 3.0.30 CVE-2026-15550 Wordfence
4.4 Medium Super Progressive Web Apps Plugin super-progressive-web-apps Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Offline Message Setting ≤ 2.2.43 CVE-2026-5108 Wordfence
4.8 Medium Bit Form Plugin bit-form Cross-Site Scripting Admin+ Stored XSS via Conversational Form Progress Label < 3.1.4 Fixed in 3.1.4 CVE-2025-15669 WPScan
5.4 Medium Academy LMS Plugin academy Broken Access Control Subscriber+ Cross-User Lesson Note and Progress Modification via IDOR < 3.8.1 Fixed in 3.8.1 CVE-2026-14184 WPScan
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Reading Progress Global Color Settings ≤ 6.6.11 CVE-2026-15156 Wordfence
7.5 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting ≤ 1.6.1 CVE-2026-15338 Wordfence
6.5 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Unauthenticated Course Progress Disclosure and Deletion No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-10824 WPScan
5.9 Medium Progress Planner Plugin progress-planner Cross-Site Scripting ≤ 1.9.0 Fixed in 1.9.1 CVE-2026-28116 Patchstack
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar ≤ 6.4.9 CVE-2026-3311 Wordfence
7.1 High Vayvo Theme vayvo-progression Cross-Site Scripting Media Streaming & Membership WordPress Theme theme < 6.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 6.8 Fixed in 6.8 CVE-2026-25373 Patchstack
4.3 Medium Reading progressbar Plugin reading-progress-bar Cross-Site Scripting Admin+ Stored XSS < 1.3.1 Fixed in 1.3.1 CVE-2026-2687 WPScan
8.1 High Progress Theme progress Local File Inclusion No login needed ≤ 1.2 CVE-2026-28034 Patchstack
6.4 Medium Kingcabs Theme kingcabs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter ≤ 1.1.9 CVE-2025-7058 Wordfence
5.4 Medium Progress Bar Blocks for Gutenberg Plugin progressmatify-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 1.0.0 CVE-2025-12880 Wordfence
8.8 High Progress Planner Plugin progress-planner Privilege Escalation ≤ 1.8.0 Fixed in 1.8.1 CVE-2025-48082 Patchstack
6.4 Medium Responsive Progress Bar Plugin responsive-progress-bar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11883 Wordfence
6.4 Medium Appzend Theme appzend Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter ≤ 1.2.6 CVE-2025-5587 Wordfence
6.5 Medium Progress Bar Plugin progress-bar Cross-Site Scripting ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-47441 Patchstack
6.5 Medium Author WIP Progress Bar Plugin author-work-in-progress-bar Cross-Site Scripting ≤ 1.0 CVE-2025-39516 Patchstack
6.5 Medium MyBookProgress by Stormhill Media Plugin mybookprogress Cross-Site Scripting ≤ 1.0.8 CVE-2025-30982 Patchstack
4.3 Medium MyBookProgress by Stormhill Media Plugin mybookprogress Broken Access Control ≤ 1.0.8 CVE-2025-31887 Patchstack
6.4 Medium MyBookProgress by Stormhill Media Plugin mybookprogress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via book Parameter ≤ 1.0.8 CVE-2024-12598 Wordfence
6.5 Medium CC Circle Progress Bar Plugin cc-circle-progress-bar Cross-Site Scripting ≤ 1.0.0 CVE-2025-23936 Patchstack
6.5 Medium Progress Tracker Plugin progress-tracker Cross-Site Scripting ≤ 0.9.3 CVE-2025-23892 Patchstack
4.3 Medium Super Progressive Web Apps Plugin super-progressive-web-apps Broken Access Control No login needed ≤ 2.2.21 Fixed in 2.2.22 CVE-2023-48277 Patchstack
6.4 Medium Rescue Shortcodes Plugin rescue-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via rescue_progressbar Shortcode ≤ 2.9 CVE-2024-11199 Wordfence
6.4 Medium Pure CSS Circle Progress bar Plugin pure-css-circle-progress-bar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2024-11385 Wordfence
6.5 Medium Awesome Progress Bar Plugin awesome-progess-bar Cross-Site Scripting ≤ 1.0.13 Fixed in 1.1.0 CVE-2024-50548 Patchstack
5.3 Medium Progress Planner Plugin progress-planner Broken Access Control No login needed ≤ 0.9.1 Fixed in 0.9.2 CVE-2024-37411 Patchstack
9.9 Critical 3D Work In Progress Plugin renee-work-in-progress Arbitrary File Upload ≤ 1.0.3 CVE-2024-49652 Patchstack
7.7 High 3D Work In Progress Plugin renee-work-in-progress Arbitrary File Deletion ≤ 1.0.3 CVE-2024-49657 Patchstack
6.4 Medium PWA — easy way to Progressive Web App Plugin iworks-pwa Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.6.3 CVE-2024-8967 Wordfence
6.5 Medium Progress Planner Plugin progress-planner Cross-Site Scripting ≤ 0.9.2 Fixed in 0.9.3 CVE-2024-37422 Patchstack
8.8 High KKProgressbar2 Free Plugin kkprogressbar Cross-Site Request Forgery Progress Bar Deletion via CSRF No login needed ≤ 1.1.4.2 CVE-2024-4535 WPScan
6.1 Medium KKProgressbar2 Free Plugin kkprogressbar Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.1.4.2 CVE-2024-4534 WPScan
6.5 Medium KKProgressbar2 Free Plugin kkprogressbar SQL Injection Admin+ SQL Injection ≤ 1.1.4.2 CVE-2024-4533 WPScan
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box ≤ 5.5.4 CVE-2024-3718 Wordfence
4.3 Medium Progressive WordPress (PWA) Plugin progressive-wp Broken Access Control ≤ 2.1.13 CVE-2024-33937 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only