WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–16 of 16 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Elfsight WhatsApp Chat CC Plugin elfsight-whatsapp-chat Cross-Site Scripting ≤ 1.2.0 CVE-2026-39696 Patchstack
6.5 Medium WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-insightly Broken Access Control ≤ <= 1.1.5 Fixed in 1.1.6 CVE-2026-32527 Patchstack
4.3 Medium NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-52767 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.1 CVE-2025-31588 Patchstack
5.9 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Scripting ≤ 1.0.1 CVE-2025-31587 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Broken Access Control ≤ 1.0.1 CVE-2025-31584 Patchstack
5.9 Medium Elfsight Yottie Lite Plugin yottie-lite Cross-Site Scripting ≤ 1.3.3 CVE-2025-26561 Patchstack
4.3 Medium PayPal Marketing Solutions Plugin paypal-promotions-and-insights Broken Access Control ≤ 1.2 CVE-2025-23930 Patchstack
6.4 Medium Elfsight Telegram Chat CC Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-10390 Wordfence
5.3 Medium Sight – Professional Image Gallery and Portfolio Plugin sight Broken Access Control Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title No login needed ≤ 1.1.2 CVE-2024-9025 Wordfence
5.3 Medium WP2Speed Faster Plugin wp2speed Information Disclosure Optimize PageSpeed Insights Score 90-100 plugin <= 1.0.1 - Sensitive Data Exposure No login needed ≤ 1.0.1 CVE-2024-37924 Patchstack
5.4 Medium Pricing Table Plugin elfsight-pricing-table Broken Access Control Missing Authorization ≤ 2.0.1 CVE-2024-4102 Wordfence
5.3 Medium Pricing Table Plugin elfsight-pricing-table Cross-Site Request Forgery Cross-Site Request Forgery via ajax() No login needed ≤ 2.0.1 CVE-2024-4100 Wordfence
5.3 Medium WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 Plugin wp2speed Broken Access Control Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due to use of Hardcoded Credentials No login needed ≤ 1.0.1 CVE-2024-5810 Wordfence
4.3 Medium Google Analytics by Monster Insights Plugin google-analytics-for-wordpress Broken Access Control ≤ 8.21.0 Fixed in 8.22.0 CVE-2023-52220 Patchstack
6.1 Medium Analytics Insights for Google Analytics 4 Plugin Open Redirect No login needed < 6.3 Fixed in 6.3 CVE-2024-0250 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only