WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–49 of 49 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.8 Medium | Easy Media Replace | Cross-Site Scripting Author+ Stored XSS via Attachment Title |
≤ 0.2.0 |
CVE-2026-15253 |
WPScan | |
| 5.9 Medium | Enable Media Replace | Cross-Site Scripting |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2026-57722 |
Patchstack | |
| 4.3 Medium | Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization | Cross-Site Request Forgery Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action No login needed |
≤ 4.2.6 |
CVE-2026-11784 |
Wordfence | |
| 6.4 Medium | Enable Media Replace | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter |
≤ 4.1.8 |
CVE-2026-5714 |
Wordfence | |
| 4.4 Medium | Word Replacer | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter |
≤ 0.4 |
CVE-2026-3620 |
Wordfence | |
| 6.5 Medium | GenerateBlocks | Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Dynamic Tag Replacements |
≤ 2.2.0 |
CVE-2026-3454 |
Wordfence | |
| 5.4 Medium | Better Find and Replace – AI-Powered Suggestions | Cross-Site Scripting AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title |
≤ 1.7.9 |
CVE-2026-3369 |
Wordfence | |
| 8.8 High | Linksy Search and Replace | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Database Update via linksy_search_and_replace_item_details |
≤ 1.0.4 |
CVE-2026-2941 |
Wordfence | |
| 5.4 Medium | Enable Media Replace | Broken Access Control Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace |
≤ 4.1.7 |
CVE-2026-2732 |
Wordfence | |
| 4.7 Medium | Update URLs – Quick and Easy way to search old links and replace them with new links in | Open Redirect Quick and Easy way to search old links and replace them with new links in WordPress plugin <= 1.4.0 - Open Redirection No login needed |
≤ 1.4.3 |
CVE-2026-25392 |
Patchstack | |
| 6.5 Medium | WebPurify Profanity Filter | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Change via webpurify_save_options No login needed |
≤ 4.0.2 |
CVE-2026-0572 |
Wordfence | |
| 4.3 Medium | Easy Replace Image | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement |
≤ 3.5.2 |
CVE-2026-1298 |
Wordfence | |
| 8.1 High | Nexter Extension – Site Enhancements Toolkit | PHP Object Injection Site Enhancements Toolkit <= 4.4.6 - Unauthenticated PHP Object Injection via 'nxt_unserialize_replace' No login needed |
≤ 4.4.6 |
CVE-2026-0726 |
Wordfence | |
| 4.3 Medium | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager | Broken Access Control Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 - Missing Authorization to Authenticated (Author+) Media Replacement |
≤ 3.1.5 |
CVE-2025-12640 |
Wordfence | |
| 4.3 Medium | CM On Demand Search And Replace | Broken Access Control |
≤ 1.5.5 |
CVE-2025-54045 |
Patchstack | |
| 8.8 High | Better Find and Replace | Remote Code Execution Authenticated (Subscriber+) Limited Code Injection |
≤ 1.7.7 |
CVE-2025-9334 |
Wordfence | |
| 4.3 Medium | Better Find and Replace | Broken Access Control Missing Authorization |
≤ 1.7.7 |
CVE-2025-12360 |
Wordfence | |
| 7.2 High | Find And Replace content | Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-10313 |
Wordfence | |
| 6.4 Medium | Enable Media Replace | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode |
≤ 4.1.6 |
CVE-2025-9496 |
Wordfence | |
| 5.9 Medium | Better Find and Replace | Cross-Site Scripting |
≤ 1.7.6 Fixed in 1.7.7 |
CVE-2025-53466 |
Patchstack | |
| 5.9 Medium | CM On Demand Search And Replace | Cross-Site Scripting |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2025-54727 |
Patchstack | |
| 4.3 Medium | CM On Demand Search And Replace | Cross-Site Request Forgery No login needed |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2025-54728 |
Patchstack | |
| 7.1 High | re.place | Cross-Site Request Forgery No login needed |
≤ 0.2.1 |
CVE-2025-53338 |
Patchstack | |
| 5.9 Medium | Add & Replace Affiliate Links for Amazon | Cross-Site Scripting |
≤ 1.0.6 |
CVE-2025-53285 |
Patchstack | |
| 4.3 Medium | TM Replace Howdy | Cross-Site Request Forgery No login needed |
≤ 1.4.2 |
CVE-2025-49972 |
Patchstack | |
| 6.1 Medium | Smooth Gallery Replacement | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0 |
CVE-2024-8032 |
WPScan | |
| 4.9 Medium | Easy Replace Image | Server-Side Request Forgery |
≤ 3.5.0 Fixed in 3.5.1 |
CVE-2025-47483 |
Patchstack | |
| 8.8 High | External image replace | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 1.0.8 |
CVE-2025-4279 |
Wordfence | |
| 4.3 Medium | 404 Image Redirection (Replace Broken Images) | Cross-Site Request Forgery No login needed |
≤ 1.4 |
CVE-2025-32266 |
Patchstack | |
| 7.1 High | Enable Media Replace | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.1.5 Fixed in 4.1.6 |
CVE-2025-31081 |
Patchstack | |
| 7.1 High | Replace Default Words | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.3 |
CVE-2025-30612 |
Patchstack | |
| 4.3 Medium | External image replace | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.0.8 |
CVE-2025-30535 |
Patchstack | |
| 7.6 High | Bravo Search & Replace | SQL Injection |
≤ 1.0 |
CVE-2025-27297 |
Patchstack | |
| 8.8 High | Better Find and Replace | Privilege Escalation |
≤ 1.6.7 Fixed in 1.6.8 |
CVE-2025-24734 |
Patchstack | |
| 7.1 High | WPEX Replace DB Urls | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.4.0 |
CVE-2025-22586 |
Patchstack | |
| 8.8 High | Backup Migration | PHP Object Injection Unauthenticated PHP Object Injection via 'recursive_unserialize_replace' No login needed |
≤ 1.4.6 |
CVE-2024-10932 |
Wordfence | |
| 6.5 Medium | Easy Replace | Cross-Site Scripting |
≤ 1.3 |
CVE-2024-54244 |
Patchstack | |
| 8.8 High | Clone | PHP Object Injection Unauthenticated PHP Object Injection via 'recursive_unserialized_replace' No login needed |
≤ 2.4.6 |
CVE-2024-10913 |
Wordfence | |
| 6.4 Medium | Debrandify · Remove or Replace WordPress Branding | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.1.2 |
CVE-2024-9674 |
Wordfence | |
| 6.1 Medium | Lucas String Replace | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0.5 |
CVE-2024-8734 |
Wordfence | |
| 8.3 High | Better Find and Replace | PHP Object Injection No login needed |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-39636 |
Patchstack | |
| 5.4 Medium | Search & Replace | PHP Object Injection Deserialization of untrusted data No login needed |
≤ 3.2.2 Fixed in 3.2.3 |
CVE-2024-38759 |
Patchstack | |
| 6.5 Medium | CM WordPress Search And Replace | Cross-Site Request Forgery Plugin Reset via CSRF |
< 1.3.9 Fixed in 1.3.9 |
CVE-2024-5028 |
WPScan | |
| 4.3 Medium | Replace Image | Broken Access Control Insecure Direct Object Reference |
≤ 1.1.10 |
CVE-2024-4873 |
Wordfence | |
| 3.8 Low | Search & Replace | SQL Injection Admin+ SQL injection |
< 3.2.2 Fixed in 3.2.2 |
CVE-2024-4145 |
WPScan | |
| 6.5 Medium | Word Replacer Pro | Broken Access Control No login needed |
≤ 1.0 |
CVE-2023-52229 |
Patchstack | |
| 5.3 Medium | Word Replacer Pro | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Content Update No login needed |
≤ 1.0 |
CVE-2024-1733 |
Wordfence | |
| 8.8 High | Better Search Replace | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 1.4.4 |
CVE-2023-6933 |
Wordfence | |
| 4.7 Medium | Enable Media Replace | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.1.4 |
CVE-2023-6737 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.