WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–33 of 33 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium Easy Media Replace Plugin Cross-Site Scripting Author+ Stored XSS via Attachment Title ≤ 0.2.0 CVE-2026-15253 WPScan
5.9 Medium Enable Media Replace Plugin enable-media-replace Cross-Site Scripting ≤ 4.2.1 Fixed in 4.2.2 CVE-2026-57722 Patchstack
4.3 Medium Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization Plugin optimole-wp Cross-Site Request Forgery Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action No login needed ≤ 4.2.6 CVE-2026-11784 Wordfence
6.4 Medium Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter ≤ 4.1.8 CVE-2026-5714 Wordfence
4.4 Medium Word Replacer Plugin word-replacer Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter ≤ 0.4 CVE-2026-3620 Wordfence
6.5 Medium GenerateBlocks Plugin generateblocks Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Dynamic Tag Replacements ≤ 2.2.0 CVE-2026-3454 Wordfence
5.4 Medium Better Find and Replace – AI-Powered Suggestions Plugin real-time-auto-find-and-replace Cross-Site Scripting AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title ≤ 1.7.9 CVE-2026-3369 Wordfence
5.4 Medium Enable Media Replace Plugin enable-media-replace Broken Access Control Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace ≤ 4.1.7 CVE-2026-2732 Wordfence
4.7 Medium Update URLs – Quick and Easy way to search old links and replace them with new links in Plugin update-urls Open Redirect Quick and Easy way to search old links and replace them with new links in WordPress plugin <= 1.4.0 - Open Redirection No login needed ≤ 1.4.3 CVE-2026-25392 Patchstack
6.5 Medium WebPurify Profanity Filter Plugin webpurifytextreplace Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Change via webpurify_save_options No login needed ≤ 4.0.2 CVE-2026-0572 Wordfence
4.3 Medium Easy Replace Image Plugin easy-replace-image Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement ≤ 3.5.2 CVE-2026-1298 Wordfence
4.3 Medium Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager Plugin folders Broken Access Control Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 - Missing Authorization to Authenticated (Author+) Media Replacement ≤ 3.1.5 CVE-2025-12640 Wordfence
4.3 Medium CM On Demand Search And Replace Plugin cm-on-demand-search-and-replace Broken Access Control ≤ 1.5.5 CVE-2025-54045 Patchstack
4.3 Medium Better Find and Replace Plugin real-time-auto-find-and-replace Broken Access Control Missing Authorization ≤ 1.7.7 CVE-2025-12360 Wordfence
6.4 Medium Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode ≤ 4.1.6 CVE-2025-9496 Wordfence
5.9 Medium Better Find and Replace Plugin real-time-auto-find-and-replace Cross-Site Scripting ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-53466 Patchstack
5.9 Medium CM On Demand Search And Replace Plugin cm-on-demand-search-and-replace Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-54727 Patchstack
4.3 Medium CM On Demand Search And Replace Plugin cm-on-demand-search-and-replace Cross-Site Request Forgery No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-54728 Patchstack
5.9 Medium Add & Replace Affiliate Links for Amazon Plugin add-replace-affiliate-links-for-amazon Cross-Site Scripting ≤ 1.0.6 CVE-2025-53285 Patchstack
4.3 Medium TM Replace Howdy Plugin tm-replace-howdy Cross-Site Request Forgery No login needed ≤ 1.4.2 CVE-2025-49972 Patchstack
6.1 Medium Smooth Gallery Replacement Plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-8032 WPScan
4.9 Medium Easy Replace Image Plugin easy-replace-image Server-Side Request Forgery ≤ 3.5.0 Fixed in 3.5.1 CVE-2025-47483 Patchstack
4.3 Medium 404 Image Redirection (Replace Broken Images) Plugin broken-images-redirection Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-32266 Patchstack
4.3 Medium External image replace Plugin external-image-replace Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.8 CVE-2025-30535 Patchstack
6.5 Medium Easy Replace Plugin easy-replace Cross-Site Scripting ≤ 1.3 CVE-2024-54244 Patchstack
6.4 Medium Debrandify · Remove or Replace WordPress Branding Plugin debrandify Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.2 CVE-2024-9674 Wordfence
6.1 Medium Lucas String Replace Plugin lucas-string-replace Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.5 CVE-2024-8734 Wordfence
5.4 Medium Search & Replace Plugin search-and-replace PHP Object Injection Deserialization of untrusted data No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2024-38759 Patchstack
6.5 Medium CM WordPress Search And Replace Plugin Cross-Site Request Forgery Plugin Reset via CSRF < 1.3.9 Fixed in 1.3.9 CVE-2024-5028 WPScan
4.3 Medium Replace Image Plugin replace-image Broken Access Control Insecure Direct Object Reference ≤ 1.1.10 CVE-2024-4873 Wordfence
6.5 Medium Word Replacer Pro Plugin word-replacer-ultra Broken Access Control No login needed ≤ 1.0 CVE-2023-52229 Patchstack
5.3 Medium Word Replacer Pro Plugin word-replacer-ultra Broken Access Control Missing Authorization to Unauthenticated Arbitrary Content Update No login needed ≤ 1.0 CVE-2024-1733 Wordfence
4.7 Medium Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.1.4 CVE-2023-6737 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only