WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 144 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Newsletter Plugin newsletter Information Disclosure Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure) No login needed ≤ 9.3.9 CVE-2026-92537 Wordfence
6.5 Medium Pixel Manager for WooCommerce Plugin woocommerce-google-adwords-conversion-tracking-tag Cross-Site Scripting ≤ 1.69.0 Fixed in 1.69.1 CVE-2026-94674 Patchstack
6.5 Medium Breeze Cache Plugin breeze Other Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters No login needed 1.2.5 – < 2.5.15 Fixed in 2.5.15 CVE-2026-79713 WPScan
4.8 Medium Newsletter Plugin newsletter Information Disclosure Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key No login needed < 9.3.8 Fixed in 9.3.8 CVE-2026-86824 WPScan
6.8 Medium Xpro Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS via Interactive Circle Widget < 1.7.9 Fixed in 1.7.9 CVE-2026-84088 WPScan
5.3 Medium 3D FlipBook Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure Unauthenticated Sensitive Information Exposure in 'id' Parameter No login needed ≤ 1.16.20 CVE-2026-15758 Wordfence
5.3 Medium Royal Addons for Elementor Plugin royal-elementor-addons Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed ≤ 1.7.1066 CVE-2026-17585 Wordfence
6.5 Medium WP Fastest Cache Plugin wp-fastest-cache Other Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters No login needed 0.8.7.7 – < 1.5.1 Fixed in 1.5.1 CVE-2026-74916 WPScan
5.4 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Server-Side Request Forgery No login needed ≤ 8.15.0 CVE-2026-82852 Patchstack
5.3 Medium Document Embedder Plugin document-emberdder Broken Access Control Unauthenticated Private Document Download via Token Oracle No login needed < 2.3.1 Fixed in 2.3.1 CVE-2026-16567 WPScan
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure No login needed ≤ 1.16.20 CVE-2026-74007 Patchstack
6.4 Medium Loco Translate Plugin loco-translate Cross-Site Scripting Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments ≤ 2.8.7 CVE-2026-15066 Wordfence
6.5 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Cross-Site Scripting ≤ 1.18.1 CVE-2026-66460 Patchstack
4.3 Medium Facturación Electrónica Costa Rica Plugin factura-electronica-cr Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 2.0.2 CVE-2026-9720 Wordfence
5.3 Medium Quiz And Survey Master Plugin Information Disclosure Unauthenticated User Enumeration and Password Oracle via Quiz Login No login needed < 11.1.3 Fixed in 11.1.3 CVE-2026-14820 WPScan
6.4 Medium MapSVG Lite Plugin mapsvg-lite-interactive-vector-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.14.0 CVE-2025-9205 Wordfence
6.5 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Cross-Site Scripting ≤ 8.14.0 Fixed in 8.14.1 CVE-2026-65449 Patchstack
6.5 Medium Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting ≤ 1.5.3.2 Fixed in 1.5.3.3 CVE-2026-39540 Patchstack
5.4 Medium Iptanus File Upload Plugin wp-file-upload Arbitrary File Upload File Overwrite via Race Condition < 5.1.7 Fixed in 5.1.7 CVE-2025-15546 WPScan
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Cross-Site Request Forgery No login needed ≤ 2.0.10 Fixed in 2.0.11 CVE-2022-47150 Patchstack
6.5 Medium Independent Analytics Plugin independent-analytics Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Tracking Route No login needed ≤ 2.14.9 CVE-2026-5737 Wordfence
6.1 Medium MapGeo - Interactive Geo Maps Plugin Cross-Site Scripting Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter No login needed ≤ 1.6.27 CVE-2025-15345 Wordfence
5.3 Medium Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Plugin logtivity Information Disclosure Unauthenticated Information Disclosure via REST API No login needed ≤ 3.3.6 CVE-2026-8198 Wordfence
5.3 Medium 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Broken Access Control PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure No login needed ≤ 1.16.17 CVE-2026-1314 Wordfence
6.4 Medium Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'elevation-track' Shortcode ≤ 4.14 CVE-2026-5451 Wordfence
5.3 Medium AnyTrack Affiliate Link Manager Plugin anytrack-affiliate-link-manager Broken Access Control No login needed ≤ 1.5.5 CVE-2026-39715 Patchstack
5.3 Medium Order Tracking Plugin order-tracking Broken Access Control No login needed ≤ 3.4.3 CVE-2026-39602 Patchstack
5.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation No login needed ≤ 7.8.10.2 CVE-2026-2263 Wordfence
5.4 Medium Gracey Theme gracey PHP Object Injection Arbitrary Object Instantiation ≤ < 1.4 Fixed in 1.4 CVE-2026-32509 Patchstack
6.1 Medium iTracker360 Plugin itracker360 Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_license' Settings Field No login needed ≤ 2.2.0 CVE-2026-3572 Wordfence
6.5 Medium TeraWallet – For WooCommerce Plugin woo-wallet Other For WooCommerce plugin <= 1.5.15 - Race Condition ≤ 1.5.15 Fixed in 1.5.16 CVE-2026-32398 Patchstack
6.4 Medium InteractiveCalculator Plugin interactivecalculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.0.3 CVE-2026-1807 Wordfence
4.3 Medium MMA Call Tracking Plugin mma-call-tracking Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 2.3.15 CVE-2026-1215 Wordfence
6.4 Medium Wikiloops Track Player Plugin wikiloops-track-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.1 CVE-2026-1611 Wordfence
5.3 Medium Magic Import Document Extractor Plugin magic-import-document-extractor Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.6 CVE-2025-15508 Wordfence
5.3 Medium Magic Import Document Extractor Plugin magic-import-document-extractor Broken Access Control Missing Authorization to Unauthenticated Plugin License Status Modification No login needed ≤ 1.0.5 CVE-2025-15507 Wordfence
4.3 Medium WP Forms Signature Contract Add-On Plugin wp-forms-signature-contract-add-on Broken Access Control Broken Access Control to Notice Dismissal ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-24985 Patchstack
6.4 Medium Interactions – Create Interactive Experiences in the Block Editor Plugin Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-12709 Wordfence
5.9 Medium Affiliate Link Tracker Plugin affiliate-link-tracker Cross-Site Scripting ≤ 0.2 CVE-2025-62077 Patchstack
4.3 Medium GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools Plugin getgenie Broken Access Control AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion ≤ 4.3.0 CVE-2026-1003 Wordfence
6.5 Medium AdWords Conversion Tracking Code Plugin adwords-conversion-tracking-code Cross-Site Scripting ≤ 1.0 CVE-2025-62118 Patchstack
6.5 Medium Fancy Product Designer | WooCommerce Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed ≤ 6.4.8 CVE-2025-13231 Wordfence
4.3 Medium WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.25 CVE-2025-58999 Patchstack
4.3 Medium Employee Spotlight – Team Member Showcase & Meet the Team Plugin employee-spotlight Broken Access Control Team Member Showcase & Meet the Team Plugin <= 5.1.3 - Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification ≤ 5.1.3 CVE-2025-13403 Wordfence
5.3 Medium Pixel Manager for WooCommerce Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Sensitive Data Exposure No login needed ≤ 1.51.1 Fixed in 1.52.0 CVE-2025-67564 Patchstack
4.3 Medium EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control Missing Authorization to Authenticated (Subscriber+) Tracking Data Modification ≤ 2.3.1 CVE-2025-12133 Wordfence
4.3 Medium Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO Plugin tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop Broken Access Control Missing Authorization to Authenticated (Subscriber+) Contract Address Update ≤ 2.4.7 CVE-2025-11773 Wordfence
5.3 Medium Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information Exposure No login needed ≤ 1.49.2 CVE-2025-12545 Wordfence
5.3 Medium Restrictions for BuddyPress Plugin bp-restrict Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 1.5.2 CVE-2025-12391 Wordfence
5.3 Medium Cryptocurrency Payment Gateway for WooCommerce Plugin triplea-cryptocurrency-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 2.0.25 CVE-2025-12392 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only