WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 142 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting No login needed ≤ 11.2.6 Fixed in 11.2.7 CVE-2026-97289 Patchstack
7.2 High Quill Forms | Conversational Multi Step Forms, Surveys & quizzes Plugin quillforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Multiple Choice 'Other' Value No login needed ≤ 5.7.1 CVE-2026-15664 Wordfence
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 11.2.5 Fixed in 11.2.6 CVE-2026-62140 Patchstack
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Question Bank and Answer Key Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-79615 WPScan
2.7 Low Quiz And Survey Master Plugin Information Disclosure Contributor+ Cross-Quiz Email and Results Configuration Disclosure via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14826 WPScan
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Quiz Text Settings Update via IDOR < 11.2.4 Fixed in 11.2.4 CVE-2026-14825 WPScan
4.3 Medium Modal Survey Plugin modal-survey Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0.2.2.3 CVE-2026-66634 Patchstack
9.8 Critical Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder PHP Object Injection ARForms <= 1.8.5 - Unauthenticated PHP Object Injection No login needed ≤ 1.8.5 CVE-2024-13784 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option ≤ 11.2.1 CVE-2026-15963 Wordfence
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints ≤ 3.5.2 CVE-2026-13167 Wordfence
6.4 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter ≤ 11.2.1 CVE-2026-11780 Wordfence
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Authentication Bypass Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication No login needed ≤ 1.9.0 Fixed in 2.0.0 CVE-2026-66425 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.3.3 Fixed in 5.2.3.4 CVE-2026-65565 Patchstack
4.8 Medium Quiz And Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS via Polar Question < 11.2.2 Fixed in 11.2.2 CVE-2026-14824 WPScan
5.3 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action() No login needed ≤ 1.9.0 CVE-2026-11995 Wordfence
4.3 Medium Survey Form Block Plugin survey-form-block Broken Access Control Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export ≤ 1.0.1 CVE-2026-5626 Wordfence
2.7 Low Quiz And Survey Master Plugin Broken Access Control Contributor+ Arbitrary Template Deletion < 11.1.5 Fixed in 11.1.5 CVE-2026-14821 WPScan
5.3 Medium Quiz And Survey Master Plugin Information Disclosure Unauthenticated User Enumeration and Password Oracle via Quiz Login No login needed < 11.1.3 Fixed in 11.1.3 CVE-2026-14820 WPScan
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 11.2.0 Fixed in 11.2.1 CVE-2026-65454 Patchstack
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Custom+) SQL Injection via 'pages' Parameter ≤ 11.2.0 CVE-2026-13767 Wordfence
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure ≤ 11.1.4 CVE-2026-9230 Wordfence
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.2.2.5 Fixed in 5.2.2.6 CVE-2026-57361 Patchstack
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action ≤ 11.1.4 CVE-2026-9233 Wordfence
7.1 High Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting No login needed ≤ 11.1.2 Fixed in 11.1.3 CVE-2026-48867 Patchstack
7.1 High Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting No login needed ≤ 11.0.0 Fixed in 11.1.0 CVE-2026-40787 Patchstack
4.9 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters ≤ 11.1.2 CVE-2026-6448 Wordfence
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending ≤ 3.4.7 CVE-2026-4888 Wordfence
8.2 High Survey & Poll Plugin SQL Injection WordPress Plugin Survey & Poll 1.5.7.3 SQL Injection via sss_params No login needed 1.5.7.3 CVE-2021-47941 VulnCheck
5.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Content Injection Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields No login needed ≤ 10.1.0 CVE-2026-5797 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter ≤ 10.3.5 CVE-2026-2412 Wordfence
5.6 Medium Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder Arbitrary Shortcode Execution ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution No login needed ≤ 1.7.2 CVE-2024-13785 Wordfence
4.4 Medium Survey Plugin survey Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.1 CVE-2026-1247 Wordfence
7.2 High SurveyJS: Drag & Drop Form Builder Plugin surveyjs Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.5.3 CVE-2026-2440 Wordfence
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() ≤ 1.6.0 CVE-2026-1674 Wordfence
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 10.3.1 Fixed in 10.3.2 CVE-2025-67987 Patchstack
6.1 Medium Survey Maker Plugin survey-maker Cross-Site Scripting WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in… No login needed 5.1.7.7 and prior CVE-2026-26370 jpcert
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 10.3.4 Fixed in 10.3.5 CVE-2026-25329 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 10.3.4 Fixed in 10.3.5 CVE-2026-25324 Patchstack
6.4 Medium QuestionPro Surveys Plugin questionpro-surveys Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0 CVE-2026-1901 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed ≤ 2.5.2 CVE-2025-13205 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed ≤ 2.5.2 CVE-2025-13139 Wordfence
3.7 Low MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Plugin metform Information Disclosure Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value No login needed ≤ 4.1.0 CVE-2026-0633 Wordfence
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 10.3.3 Fixed in 10.3.4 CVE-2026-24358 Patchstack
5.1 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Scripting Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS < 19.6.25 Fixed in 19.6.25 CVE-2019-25297 VulnCheck
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter ≤ 10.3.1 CVE-2025-9318 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads No login needed ≤ 10.3.1 CVE-2025-9637 Wordfence
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion ≤ 10.3.1 CVE-2025-9294 Wordfence
5.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Broken Access Control No login needed ≤ 19.12.0 Fixed in 19.12.1 CVE-2025-68594 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only