WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1–33 of 33 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.8 Medium | Easy Media Replace | Cross-Site Scripting Author+ Stored XSS via Attachment Title |
≤ 0.2.0 |
CVE-2026-15253 |
WPScan | |
| 5.9 Medium | Enable Media Replace | Cross-Site Scripting |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2026-57722 |
Patchstack | |
| 4.3 Medium | Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization | Cross-Site Request Forgery Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action No login needed |
≤ 4.2.6 |
CVE-2026-11784 |
Wordfence | |
| 6.4 Medium | Enable Media Replace | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter |
≤ 4.1.8 |
CVE-2026-5714 |
Wordfence | |
| 4.4 Medium | Word Replacer | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Replacement' Parameter |
≤ 0.4 |
CVE-2026-3620 |
Wordfence | |
| 6.5 Medium | GenerateBlocks | Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via Dynamic Tag Replacements |
≤ 2.2.0 |
CVE-2026-3454 |
Wordfence | |
| 5.4 Medium | Better Find and Replace – AI-Powered Suggestions | Cross-Site Scripting AI-Powered Suggestions <= 1.7.9 - Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Title |
≤ 1.7.9 |
CVE-2026-3369 |
Wordfence | |
| 5.4 Medium | Enable Media Replace | Broken Access Control Improper Authorization to Authenticated (Author+) Arbitrary Attachment Change via Background Replace |
≤ 4.1.7 |
CVE-2026-2732 |
Wordfence | |
| 4.7 Medium | Update URLs – Quick and Easy way to search old links and replace them with new links in | Open Redirect Quick and Easy way to search old links and replace them with new links in WordPress plugin <= 1.4.0 - Open Redirection No login needed |
≤ 1.4.3 |
CVE-2026-25392 |
Patchstack | |
| 6.5 Medium | WebPurify Profanity Filter | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Change via webpurify_save_options No login needed |
≤ 4.0.2 |
CVE-2026-0572 |
Wordfence | |
| 4.3 Medium | Easy Replace Image | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement |
≤ 3.5.2 |
CVE-2026-1298 |
Wordfence | |
| 4.3 Medium | Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager | Broken Access Control Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager <= 3.1.5 - Missing Authorization to Authenticated (Author+) Media Replacement |
≤ 3.1.5 |
CVE-2025-12640 |
Wordfence | |
| 4.3 Medium | CM On Demand Search And Replace | Broken Access Control |
≤ 1.5.5 |
CVE-2025-54045 |
Patchstack | |
| 4.3 Medium | Better Find and Replace | Broken Access Control Missing Authorization |
≤ 1.7.7 |
CVE-2025-12360 |
Wordfence | |
| 6.4 Medium | Enable Media Replace | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode |
≤ 4.1.6 |
CVE-2025-9496 |
Wordfence | |
| 5.9 Medium | Better Find and Replace | Cross-Site Scripting |
≤ 1.7.6 Fixed in 1.7.7 |
CVE-2025-53466 |
Patchstack | |
| 5.9 Medium | CM On Demand Search And Replace | Cross-Site Scripting |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2025-54727 |
Patchstack | |
| 4.3 Medium | CM On Demand Search And Replace | Cross-Site Request Forgery No login needed |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2025-54728 |
Patchstack | |
| 5.9 Medium | Add & Replace Affiliate Links for Amazon | Cross-Site Scripting |
≤ 1.0.6 |
CVE-2025-53285 |
Patchstack | |
| 4.3 Medium | TM Replace Howdy | Cross-Site Request Forgery No login needed |
≤ 1.4.2 |
CVE-2025-49972 |
Patchstack | |
| 6.1 Medium | Smooth Gallery Replacement | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0 |
CVE-2024-8032 |
WPScan | |
| 4.9 Medium | Easy Replace Image | Server-Side Request Forgery |
≤ 3.5.0 Fixed in 3.5.1 |
CVE-2025-47483 |
Patchstack | |
| 4.3 Medium | 404 Image Redirection (Replace Broken Images) | Cross-Site Request Forgery No login needed |
≤ 1.4 |
CVE-2025-32266 |
Patchstack | |
| 4.3 Medium | External image replace | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.0.8 |
CVE-2025-30535 |
Patchstack | |
| 6.5 Medium | Easy Replace | Cross-Site Scripting |
≤ 1.3 |
CVE-2024-54244 |
Patchstack | |
| 6.4 Medium | Debrandify · Remove or Replace WordPress Branding | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.1.2 |
CVE-2024-9674 |
Wordfence | |
| 6.1 Medium | Lucas String Replace | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0.5 |
CVE-2024-8734 |
Wordfence | |
| 5.4 Medium | Search & Replace | PHP Object Injection Deserialization of untrusted data No login needed |
≤ 3.2.2 Fixed in 3.2.3 |
CVE-2024-38759 |
Patchstack | |
| 6.5 Medium | CM WordPress Search And Replace | Cross-Site Request Forgery Plugin Reset via CSRF |
< 1.3.9 Fixed in 1.3.9 |
CVE-2024-5028 |
WPScan | |
| 4.3 Medium | Replace Image | Broken Access Control Insecure Direct Object Reference |
≤ 1.1.10 |
CVE-2024-4873 |
Wordfence | |
| 6.5 Medium | Word Replacer Pro | Broken Access Control No login needed |
≤ 1.0 |
CVE-2023-52229 |
Patchstack | |
| 5.3 Medium | Word Replacer Pro | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Content Update No login needed |
≤ 1.0 |
CVE-2024-1733 |
Wordfence | |
| 4.7 Medium | Enable Media Replace | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.1.4 |
CVE-2023-6737 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.