WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.
Showing 1–25 of 25 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.9 Medium | Rank Math SEO | Broken Access Control Author+ Arbitrary Post and User Metadata Overwrite via updateSchemas |
1.0.48 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77788 |
WPScan | |
| 2.7 Low | Rank Math SEO | Broken Access Control Author+ Term Metadata Update and Cross-Object Post Title Overwrite via updateMetaBulk |
1.0.255 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77787 |
WPScan | |
| 2.7 Low | Rank Math SEO | Information Disclosure Author+ Non-Public Post Content Disclosure via Abilities API |
1.0.272 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77785 |
WPScan | |
| 2.7 Low | Rank Math SEO | Broken Access Control Author+ Robots and Pillar Content Meta Update on Non-Owned Objects via mark_page_as |
< 1.0.277 Fixed in 1.0.277 |
CVE-2026-77784 |
WPScan | |
| 3.7 Low | Rank Math SEO | Information Disclosure Unauthenticated Non-Public Post Schema and Content Disclosure No login needed |
1.0.48 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77783 |
WPScan | |
| 5.3 Medium | Rank Math SEO | Information Disclosure Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txt No login needed |
< 1.0.277.1 Fixed in 1.0.277.1 |
CVE-2026-77782 |
WPScan | |
| 4.9 Medium | Rank Math SEO | Broken Access Control Editor+ Core Settings Modification via fix-site-seo Ability |
1.0.271 – < 1.0.277 Fixed in 1.0.277 |
CVE-2026-77786 |
WPScan | |
| 7.2 High | Rank Math SEO | Remote Code Execution |
≤ 1.0.276 Fixed in 1.0.277 |
CVE-2026-81757 |
Patchstack | |
| 7.1 High | Rank Math SEO | Cross-Site Scripting No login needed |
≤ 1.0.274.1 Fixed in 1.0.275 |
CVE-2026-66702 |
Patchstack | |
| 6.5 Medium | Rank Math SEO | Broken Access Control |
≤ 1.0.271 Fixed in 1.0.271.1 |
CVE-2026-34892 |
Patchstack | |
| 5.3 Medium | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | Broken Access Control AI SEO Tools to Dominate SEO Rankings <= 1.0.271 - Missing Authorization to Unauthenticated Homepage Settings Modification No login needed |
≤ 1.0.271 |
CVE-2025-12714 |
Wordfence | |
| 4.3 Medium | Rank Math SEO PRO | Broken Access Control |
≤ 3.0.95 |
CVE-2026-28080 |
Patchstack | |
| 4.3 Medium | Rank Math SEO | Information Disclosure Sensitive Data Exposure |
≤ 1.0.252.1 Fixed in 1.0.253 |
CVE-2025-64351 |
Patchstack | |
| 3.8 Low | Rank Math SEO | Broken Access Control |
≤ 1.0.252.1 Fixed in 1.0.253 |
CVE-2025-64350 |
Patchstack | |
| 4.3 Medium | Rank Math SEO | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Schema Deletion |
≤ 1.0.235 |
CVE-2024-13229 |
Wordfence | |
| 6.4 Medium | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | Cross-Site Scripting AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API |
≤ 1.0.235 |
CVE-2024-13227 |
Wordfence | |
| 7.2 High | Rank Math SEO | Remote Code Execution Arbitrary .htaccess Overwrite to Remote Code Execution (RCE) |
≤ 1.0.231 Fixed in 1.0.232 |
CVE-2024-11620 |
Patchstack | |
| 7.2 High | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | PHP Object Injection AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection |
≤ 1.0.228 |
CVE-2024-9314 |
Wordfence | |
| 6.5 Medium | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | Broken Access Control AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete No login needed |
≤ 1.0.228 |
CVE-2024-9161 |
Wordfence | |
| 5.5 Medium | Rank Math SEO | Cross-Site Scripting Authenticated Stored XSS |
< 1.0.219 Fixed in 1.0.219 |
CVE-2024-4627 |
WPScan | |
| 7.6 High | Rank Math SEO | Local File Inclusion |
≤ 1.0.107.2 Fixed in 1.0.107.3 |
CVE-2023-23888 |
Patchstack | |
| 6.4 Medium | Rank Math SEO with AI Best SEO Tools | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.218 |
CVE-2024-4617 |
Wordfence | |
| 6.4 Medium | Rank Math SEO with AI Best SEO Tools | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.217 |
CVE-2024-4335 |
Wordfence | |
| 6.4 Medium | Rank Math SEO with AI SEO Tools | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleWrapper' |
≤ 1.0.216 |
CVE-2024-3665 |
Wordfence | |
| 6.4 Medium | Rank Math SEO with AI SEO Tools | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributes |
≤ 1.0.214 |
CVE-2024-2536 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.