WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 102 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 11.2.5 Fixed in 11.2.6 CVE-2026-62140 Patchstack
4.3 Medium Modal Survey Plugin modal-survey Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.0.2.2.3 CVE-2026-66634 Patchstack
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'randon_category' Quiz Option ≤ 11.2.1 CVE-2026-15963 Wordfence
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI <= 3.5.2 - Missing Authorization to Authenticated (Delegated+) Arbitrary Plugin Activation via REST API and AJAX Endpoints ≤ 3.5.2 CVE-2026-13167 Wordfence
6.4 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'question_title' Parameter ≤ 11.2.1 CVE-2026-11780 Wordfence
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Authentication Bypass Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin <= 1.9.0 - Broken Authentication No login needed ≤ 1.9.0 Fixed in 2.0.0 CVE-2026-66425 Patchstack
4.8 Medium Quiz And Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS via Polar Question < 11.2.2 Fixed in 11.2.2 CVE-2026-14824 WPScan
5.3 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.9.0 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification/Trash via process_bulk_action() No login needed ≤ 1.9.0 CVE-2026-11995 Wordfence
4.3 Medium Survey Form Block Plugin survey-form-block Broken Access Control Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export ≤ 1.0.1 CVE-2026-5626 Wordfence
5.3 Medium Quiz And Survey Master Plugin Information Disclosure Unauthenticated User Enumeration and Password Oracle via Quiz Login No login needed < 11.1.3 Fixed in 11.1.3 CVE-2026-14820 WPScan
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Custom+) SQL Injection via 'pages' Parameter ≤ 11.2.0 CVE-2026-13767 Wordfence
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structure ≤ 11.1.4 CVE-2026-9230 Wordfence
4.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Modification via qsm_insert_quiz_template AJAX Action ≤ 11.1.4 CVE-2026-9233 Wordfence
4.9 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters ≤ 11.1.2 CVE-2026-6448 Wordfence
4.3 Medium Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder Plugin everest-forms Broken Access Control Contact Form, Payment Form, Quiz, Survey & Custom Form Builder <= 3.4.7 - Missing Authorization to Authenticated (Subscriber+) Email Sending ≤ 3.4.7 CVE-2026-4888 Wordfence
5.3 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Content Injection Unauthenticated Shortcode Injection Leading to Arbitrary Quiz Result Disclosure via Quiz Answer Text Input Fields No login needed ≤ 10.1.0 CVE-2026-5797 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Broken Access Control Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 6.1.21 - Insecure Direct Object Reference in Stripe SCA Confirmation to Unauthenticated Payment Status Modification No login needed 6.1.21 CVE-2026-4160 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Contributor+) SQL Injection via 'merged_question' Parameter ≤ 10.3.5 CVE-2026-2412 Wordfence
5.6 Medium Contact Form, Survey, Quiz & Popup Form Builder – ARForms Plugin arforms-form-builder Arbitrary Shortcode Execution ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution No login needed ≤ 1.7.2 CVE-2024-13785 Wordfence
4.4 Medium Survey Plugin survey Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.1 CVE-2026-1247 Wordfence
6.5 Medium Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder Plugin gutena-forms Broken Access Control Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder <= 1.6.0 - Authenticated (Contributor+) Limited Options Update in save_gutena_forms_schema() ≤ 1.6.0 CVE-2026-1674 Wordfence
6.1 Medium Survey Maker Plugin survey-maker Cross-Site Scripting WordPress Plugin "Survey Maker" versions 5.1.7.7 and prior contain a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in… No login needed 5.1.7.7 and prior CVE-2026-26370 jpcert
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 10.3.4 Fixed in 10.3.5 CVE-2026-25329 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 10.3.4 Fixed in 10.3.5 CVE-2026-25324 Patchstack
6.4 Medium QuestionPro Surveys Plugin questionpro-surveys Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.0 CVE-2026-1901 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed ≤ 2.5.2 CVE-2025-13205 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed ≤ 2.5.2 CVE-2025-13139 Wordfence
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 10.3.3 Fixed in 10.3.4 CVE-2026-24358 Patchstack
5.1 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Scripting Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS < 19.6.25 Fixed in 19.6.25 CVE-2019-25297 VulnCheck
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next SQL Injection Authenticated (Subscriber+) SQL Injection via `is_linking` Query Parameter ≤ 10.3.1 CVE-2025-9318 Wordfence
6.5 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Broken Access Control Missing Authorization to Unpublished, Private And Password-Protected Quiz Information Disclosure And Image Response Uploads No login needed ≤ 10.3.1 CVE-2025-9637 Wordfence
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control Missing Authorization to Authenticated (Subscriber+) Quiz Results Deletion ≤ 10.3.1 CVE-2025-9294 Wordfence
5.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Broken Access Control No login needed ≤ 19.12.0 Fixed in 19.12.1 CVE-2025-68594 Patchstack
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control No login needed ≤ 10.3.2 Fixed in 10.3.3 CVE-2025-63054 Patchstack
5.3 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Information Disclosure Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure No login needed ≤ 1.1.5 CVE-2025-13006 Wordfence
6.4 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Cross-Site Scripting Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.5 CVE-2025-12417 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Request Forgery Cross-Site Request Forgery to Account Disconnection No login needed ≤ 19.12.0 CVE-2025-13143 Wordfence
6.5 Medium Survey Maker Plugin survey-maker Broken Access Control ≤ 5.1.9.4 Fixed in 5.1.9.5 CVE-2025-64276 Patchstack
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 5.1.9.4 CVE-2025-12891 Wordfence
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control Missing Authorization to Unauthenticated Limited Option Update No login needed ≤ 5.1.9.4 CVE-2025-12892 Wordfence
5.3 Medium User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Plugin userfeedback-lite Broken Access Control Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure No login needed ≤ 1.8.0 CVE-2025-10694 Wordfence
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 5.1.8.8 Fixed in 5.1.8.9 CVE-2025-48095 Patchstack
6.4 Medium SurveyAnyplace Plugin surveyanyplace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-10196 Wordfence
6.5 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read 5.1.16 – 6.1.1 CVE-2025-9260 Wordfence
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Plugin Settings Update ≤ 19.9.0 CVE-2025-3880 Wordfence
6.1 Medium Spiritual Gifts Survey Plugin Cross-Site Request Forgery Unauthenticated CSRF to XSS No login needed ≤ 0.9.10 CVE-2025-0688 WPScan
6.1 Medium Spiritual Gifts Survey Plugin Cross-Site Request Forgery Unauthenticated CSRF to XSS No login needed ≤ 0.9.10 CVE-2025-0687 WPScan
6.4 Medium SurveyJS Plugin surveyjs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.12.32 CVE-2025-3815 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only