WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–50 of 144 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Newsletter | Information Disclosure Unauthenticated Insufficiently Protected Credentials via '/tnp/l/' Click-Tracking REST Endpoint (Raw Subscriber Token Cookie Disclosure) No login needed |
≤ 9.3.9 |
CVE-2026-92537 |
Wordfence | |
| 6.5 Medium | Pixel Manager for WooCommerce | Cross-Site Scripting |
≤ 1.69.0 Fixed in 1.69.1 |
CVE-2026-94674 |
Patchstack | |
| 6.5 Medium | Breeze Cache | Other Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters No login needed |
1.2.5 – < 2.5.15 Fixed in 2.5.15 |
CVE-2026-79713 |
WPScan | |
| 4.8 Medium | Newsletter | Information Disclosure Unauthenticated Subscriber PII Disclosure and Modification via Predictable Tracking Signature Key No login needed |
< 9.3.8 Fixed in 9.3.8 |
CVE-2026-86824 |
WPScan | |
| 6.8 Medium | Xpro Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS via Interactive Circle Widget |
< 1.7.9 Fixed in 1.7.9 |
CVE-2026-84088 |
WPScan | |
| 5.3 Medium | 3D FlipBook | Information Disclosure Unauthenticated Sensitive Information Exposure in 'id' Parameter No login needed |
≤ 1.16.20 |
CVE-2026-15758 |
Wordfence | |
| 5.3 Medium | Royal Addons for Elementor | Information Disclosure Unauthenticated Sensitive Information Exposure via Unfiltered meta_query LIKE Oracle in 'wpr_keyword' Parameter No login needed |
≤ 1.7.1066 |
CVE-2026-17585 |
Wordfence | |
| 6.5 Medium | WP Fastest Cache | Other Unauthenticated Cache Poisoning via Unkeyed Tracking Parameters No login needed |
0.8.7.7 – < 1.5.1 Fixed in 1.5.1 |
CVE-2026-74916 |
WPScan | |
| 5.4 Medium | MapSVG | Server-Side Request Forgery No login needed |
≤ 8.15.0 |
CVE-2026-82852 |
Patchstack | |
| 5.3 Medium | Document Embedder | Broken Access Control Unauthenticated Private Document Download via Token Oracle No login needed |
< 2.3.1 Fixed in 2.3.1 |
CVE-2026-16567 |
WPScan | |
| 5.3 Medium | 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery | Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery plugin <= 1.16.20 - Sensitive Data Exposure No login needed |
≤ 1.16.20 |
CVE-2026-74007 |
Patchstack | |
| 6.4 Medium | Loco Translate | Cross-Site Scripting Authenticated (Translator+) Stored Cross-Site Scripting via PO File Extracted Comments |
≤ 2.8.7 |
CVE-2026-15066 |
Wordfence | |
| 6.5 Medium | AfterShip Tracking | Cross-Site Scripting |
≤ 1.18.1 |
CVE-2026-66460 |
Patchstack | |
| 4.3 Medium | Facturación Electrónica Costa Rica | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 2.0.2 |
CVE-2026-9720 |
Wordfence | |
| 5.3 Medium | Quiz And Survey Master | Information Disclosure Unauthenticated User Enumeration and Password Oracle via Quiz Login No login needed |
< 11.1.3 Fixed in 11.1.3 |
CVE-2026-14820 |
WPScan | |
| 6.4 Medium | MapSVG Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 8.14.0 |
CVE-2025-9205 |
Wordfence | |
| 6.5 Medium | MapSVG | Cross-Site Scripting |
≤ 8.14.0 Fixed in 8.14.1 |
CVE-2026-65449 |
Patchstack | |
| 6.5 Medium | Shipment Tracker for Woocommerce | Cross-Site Scripting |
≤ 1.5.3.2 Fixed in 1.5.3.3 |
CVE-2026-39540 |
Patchstack | |
| 5.4 Medium | Iptanus File Upload | Arbitrary File Upload File Overwrite via Race Condition |
< 5.1.7 Fixed in 5.1.7 |
CVE-2025-15546 |
WPScan | |
| 4.3 Medium | WooCommerce Conversion Tracking | Cross-Site Request Forgery No login needed |
≤ 2.0.10 Fixed in 2.0.11 |
CVE-2022-47150 |
Patchstack | |
| 6.5 Medium | Independent Analytics | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Tracking Route No login needed |
≤ 2.14.9 |
CVE-2026-5737 |
Wordfence | |
| 6.1 Medium | MapGeo - Interactive Geo Maps | Cross-Site Scripting Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parameter No login needed |
≤ 1.6.27 |
CVE-2025-15345 |
Wordfence | |
| 5.3 Medium | Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity | Information Disclosure Unauthenticated Information Disclosure via REST API No login needed |
≤ 3.3.6 |
CVE-2026-8198 |
Wordfence | |
| 5.3 Medium | 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery | Broken Access Control PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.17 - Missing Authorization to Unauthenticated Private/Draft Flipbook Data Exposure No login needed |
≤ 1.16.17 |
CVE-2026-1314 |
Wordfence | |
| 6.4 Medium | Extensions for Leaflet Map | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'elevation-track' Shortcode |
≤ 4.14 |
CVE-2026-5451 |
Wordfence | |
| 5.3 Medium | AnyTrack Affiliate Link Manager | Broken Access Control No login needed |
≤ 1.5.5 |
CVE-2026-39715 |
Patchstack | |
| 5.3 Medium | Order Tracking | Broken Access Control No login needed |
≤ 3.4.3 |
CVE-2026-39602 |
Patchstack | |
| 5.3 Medium | Hustle – Email Marketing, Lead Generation, Optins, Popups | Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation No login needed |
≤ 7.8.10.2 |
CVE-2026-2263 |
Wordfence | |
| 5.4 Medium | Gracey | PHP Object Injection Arbitrary Object Instantiation |
≤ < 1.4 Fixed in 1.4 |
CVE-2026-32509 |
Patchstack | |
| 6.1 Medium | iTracker360 | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_license' Settings Field No login needed |
≤ 2.2.0 |
CVE-2026-3572 |
Wordfence | |
| 6.5 Medium | TeraWallet – For WooCommerce | Other For WooCommerce plugin <= 1.5.15 - Race Condition |
≤ 1.5.15 Fixed in 1.5.16 |
CVE-2026-32398 |
Patchstack | |
| 6.4 Medium | InteractiveCalculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 1.0.3 |
CVE-2026-1807 |
Wordfence | |
| 4.3 Medium | MMA Call Tracking | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 2.3.15 |
CVE-2026-1215 |
Wordfence | |
| 6.4 Medium | Wikiloops Track Player | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.1 |
CVE-2026-1611 |
Wordfence | |
| 5.3 Medium | Magic Import Document Extractor | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.0.6 |
CVE-2025-15508 |
Wordfence | |
| 5.3 Medium | Magic Import Document Extractor | Broken Access Control Missing Authorization to Unauthenticated Plugin License Status Modification No login needed |
≤ 1.0.5 |
CVE-2025-15507 |
Wordfence | |
| 4.3 Medium | WP Forms Signature Contract Add-On | Broken Access Control Broken Access Control to Notice Dismissal |
≤ 1.8.2 Fixed in 1.8.3 |
CVE-2026-24985 |
Patchstack | |
| 6.4 Medium | Interactions – Create Interactive Experiences in the Block Editor | Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-12709 |
Wordfence | |
| 5.9 Medium | Affiliate Link Tracker | Cross-Site Scripting |
≤ 0.2 |
CVE-2025-62077 |
Patchstack | |
| 4.3 Medium | GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools | Broken Access Control AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion |
≤ 4.3.0 |
CVE-2026-1003 |
Wordfence | |
| 6.5 Medium | AdWords Conversion Tracking Code | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-62118 |
Patchstack | |
| 6.5 Medium | Fancy Product Designer | WooCommerce | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed |
≤ 6.4.8 |
CVE-2025-13231 |
Wordfence | |
| 4.3 Medium | WP Attractive Donations System - Easy Stripe & Paypal donations | Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.25 |
CVE-2025-58999 |
Patchstack | |
| 4.3 Medium | Employee Spotlight – Team Member Showcase & Meet the Team | Broken Access Control Team Member Showcase & Meet the Team Plugin <= 5.1.3 - Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification |
≤ 5.1.3 |
CVE-2025-13403 |
Wordfence | |
| 5.3 Medium | Pixel Manager for WooCommerce | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.51.1 Fixed in 1.52.0 |
CVE-2025-67564 |
Patchstack | |
| 4.3 Medium | EPROLO Dropshipping | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Tracking Data Modification |
≤ 2.3.1 |
CVE-2025-12133 |
Wordfence | |
| 4.3 Medium | Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Contract Address Update |
≤ 2.4.7 |
CVE-2025-11773 |
Wordfence | |
| 5.3 Medium | Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more | Information Disclosure Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information Exposure No login needed |
≤ 1.49.2 |
CVE-2025-12545 |
Wordfence | |
| 5.3 Medium | Restrictions for BuddyPress | Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed |
≤ 1.5.2 |
CVE-2025-12391 |
Wordfence | |
| 5.3 Medium | Cryptocurrency Payment Gateway for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed |
≤ 2.0.25 |
CVE-2025-12392 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.