WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 56 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN Plugin hummingbird-performance Remote Code Execution Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log No login needed ≤ 3.21.0 CVE-2026-83627 Wordfence
9.3 Critical Icollect Plugin Path Traversal Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing Password No login needed ≤ 1.0.0 CVE-2026-77012 WPScan
9.1 Critical Total Processing Card Payments for WooCommerce Plugin Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed ≤ 7.3 CVE-2026-16947 WPScan
9.8 Critical Mailgun Plugin mailgun Server-Side Request Forgery Unauthenticated Server-Side Request Forgery (SSRF) via 'addresses' Array Keys No login needed ≤ 2.2.0 CVE-2026-78003 Wordfence
9.6 Critical Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Request Forgery No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2026-28164 Patchstack
9.8 Critical Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder PHP Object Injection ARForms <= 1.8.5 - Unauthenticated PHP Object Injection No login needed ≤ 1.8.5 CVE-2024-13784 Wordfence
10.0 Critical Premium SEO Plugin Remote Code Execution Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection) No login needed Not stated CVE-2026-14812 WPScan
9.6 Critical Avada Core Plugin fusion-core Cross-Site Request Forgery No login needed ≤ 5.15.6 Fixed in 5.15.7 CVE-2026-65471 Patchstack
9.6 Critical Ninja Forms File Uploads Extension Plugin ninja-forms-uploads Arbitrary File Upload Cross Site Request Forgery (CSRF) No login needed ≤ 3.3.26 CVE-2026-57784 Patchstack
9.6 Critical Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Remote Code Execution No login needed ≤ 3.2 CVE-2026-39640 Patchstack
9.6 Critical Appointment Plugin appointment Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 3.5.5 CVE-2026-39620 Patchstack
9.6 Critical Busiprof Plugin busiprof Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2026-39619 Patchstack
9.6 Critical Bluestreet Plugin bluestreet Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary Plugin Installation No login needed ≤ 1.7.3 CVE-2026-39617 Patchstack
9.6 Critical WING WordPress Migrator Plugin wing-migrator Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 2.0.0 CVE-2025-52835 Patchstack
10.0 Critical TNC Toolbox: Web Performance Plugin tnc-toolbox Information Disclosure Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover No login needed ≤ 1.4.2 CVE-2025-12539 Wordfence
9.6 Critical AR Plugin ar-for-wordpress Cross-Site Request Forgery No login needed ≤ 8.34 CVE-2025-60156 Patchstack
9.6 Critical Custom Post Type Images Plugin custom-post-types-image Cross-Site Request Forgery No login needed ≤ 0.5 CVE-2025-58255 Patchstack
9.6 Critical Mow Plugin mow Cross-Site Request Forgery No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-58997 Patchstack
9.6 Critical ads.txt Guru Connect Plugin adstxt-guru-connect Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-49381 Patchstack
9.6 Critical FluentSnippets Plugin easy-code-manager Cross-Site Request Forgery No login needed ≤ 10.50 Fixed in 10.51 CVE-2025-54010 Patchstack
9.6 Critical WP Optimizer Plugin wp-optimizer Cross-Site Request Forgery No login needed ≤ 2.5.0 CVE-2025-53314 Patchstack
9.8 Critical User Profile Meta Manager Plugin user-profile-meta Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.02 CVE-2025-48340 Patchstack
9.6 Critical Custom CSS, JS & PHP Plugin custom-css Cross-Site Request Forgery CSRF to RCE No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-39601 Patchstack
9.6 Critical WPJobBoard Plugin wpjobboard Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed < 5.11.1 Fixed in 5.11.1 CVE-2025-30967 Patchstack
9.8 Critical Buddypress Humanity Plugin buddypress-humanity Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.2 CVE-2025-31033 Patchstack
9.6 Critical Ultra Demo Importer Plugin ut-demo-importer Cross-Site Request Forgery CSRF to RCE No login needed ≤ 1.0.5 CVE-2025-32496 Patchstack
9.6 Critical WP shop Plugin wpshop Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.6.1 CVE-2025-32576 Patchstack
9.6 Critical Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-32641 Patchstack
9.6 Critical Vite Coupon Plugin vite-coupon Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-32642 Patchstack
9.8 Critical PHP/MySQL CPU performance statistics Plugin mywebtonet-performancestats PHP Object Injection No login needed ≤ 1.2.1 CVE-2025-22526 Patchstack
9.6 Critical WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 0.6.2 CVE-2025-30615 Patchstack
9.3 Critical Awesome Logos Plugin awesome-logos Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.2 CVE-2025-30528 Patchstack
9.6 Critical Munk Sites Plugin munk-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 1.0.7 CVE-2025-25101 Patchstack
9.6 Critical OneStore Sites Plugin onestore-sites Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 0.1.1 CVE-2025-25107 Patchstack
9.6 Critical Starter Templates by FancyWP Plugin starter-templates Cross-Site Request Forgery CSRF to Arbitrary Plugin Installation No login needed ≤ 2.0.0 CVE-2025-25106 Patchstack
9.1 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.15.3 Fixed in 2.15.4 CVE-2025-24650 Patchstack
10.0 Critical iSpring Embedder Plugin embed-ispring Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.0 CVE-2025-23922 Patchstack
9.8 Critical WP Options Editor Plugin wp-options-editor Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.1 CVE-2025-23797 Patchstack
9.6 Critical GitSync Plugin git-sync Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 1.1.0 CVE-2024-54368 Patchstack
9.6 Critical Insertify Plugin insertify Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 1.1.4 CVE-2024-54372 Patchstack
9.8 Critical Flash News / Post (Responsive) Plugin flashnews-fading-effect-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.1 CVE-2024-56012 Patchstack
9.6 Critical Exclusive Content Password Protect Plugin exclusive-content-password-protect Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.1.0 CVE-2024-52402 Patchstack
9.6 Critical Hacklog DownloadManager Plugin hacklog-downloadmanager Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.1.4 CVE-2024-52401 Patchstack
9.1 Critical CDI Plugin collect-and-deliver-interface-for-woocommerce Arbitrary File Upload ≤ 5.5.3 Fixed in 5.5.6 CVE-2024-52398 Patchstack
9.6 Critical Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 4.1.13 Fixed in 4.1.14 CVE-2024-43984 Patchstack
9.6 Critical EKC Tournament Manager Plugin ekc-tournament-manager Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2024-49674 Patchstack
9.6 Critical Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery CSRF to Arbitrary File Upload ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-37555 Patchstack
10.0 Critical Several WordPress.org Plugins <= Various Versions Plugin social-warfare Other Injected Backdoor No login needed 4.4.6.4 – 4.4.7.1, 1.0.4 – 1.0.5, 1.2.1 – 1.2.2, … CVE-2024-6297 Wordfence
9.8 Critical ArForms Plugin Remote Code Execution Unauthenticated RCE No login needed < 6.6 Fixed in 6.6 CVE-2024-4620 WPScan
9.3 Critical Automatic Plugin Path Traversal Unauthenticated Arbitrary File Download and SSRF No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27954 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only