WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–48 of 48 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links No login needed < 7.9.6 Fixed in 7.9.6 CVE-2026-78393 WPScan
6.4 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'src' Attribute of <img> Tags ≤ 3.3.2 CVE-2026-12106 Wordfence
4.8 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags No login needed 3.14.10 – < 3.15.2 Fixed in 3.15.2 CVE-2026-80437 WPScan
4.8 Medium Redirection for Contact Form 7 Plugin wpcf7-redirect Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags No login needed 2.2.7 – < 3.2.11 Fixed in 3.2.11 CVE-2026-80439 WPScan
4.8 Medium MW WP Form Plugin mw-wp-form Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Completion Message Merge Tags No login needed < 5.1.5 Fixed in 5.1.5 CVE-2026-78363 WPScan
8.8 High TaxoPress Plugin simple-tags PHP Object Injection ≤ 3.51.0 Fixed in 3.52.0 CVE-2026-74012 Patchstack
6.1 Medium Sentence To SEO (keywords, description and tags) Plugin sentence-to-seo Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page Parameters No login needed ≤ 1.0 CVE-2026-6391 Wordfence
7.6 High TaxoPress Plugin simple-tags SQL Injection ≤ 3.44.0 Fixed in 3.45.0 CVE-2026-42646 Patchstack
4.4 Medium Sentence To SEO (keywords, description and tags) Plugin sentence-to-seo Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Permanent keywords' Field ≤ 1.0 CVE-2026-4142 Wordfence
4.3 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action ≤ 8.8.2 CVE-2026-4331 Wordfence
7.2 High Lucky Wheel Giveaway Plugin wp-lucky-wheel Remote Code Execution Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter ≤ 1.0.22 CVE-2025-14541 Wordfence
4.3 Medium TaxoPress Plugin simple-tags Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification ≤ 3.41.0 CVE-2025-14371 Wordfence
7.2 High Lucky Wheel for WooCommerce – Spin a Sale Plugin woo-lucky-wheel Remote Code Execution Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags ≤ 1.1.13 CVE-2025-14509 Wordfence
5.3 Medium Product Filtering by Categories, Tags, Price Range for WooCommerce Plugin filter-plus Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 1.1.6 CVE-2025-13314 Wordfence
6.5 Medium Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Plugin simple-tags SQL Injection AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection via ORDER BY Clause ≤ 3.40.1 CVE-2025-13922 Wordfence
6.5 Medium Simple Meta Tags Plugin simple-meta-tags Cross-Site Scripting ≤ 1.5 CVE-2025-60142 Patchstack
6.5 Medium xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting ≤ 1.12.06 CVE-2025-58240 Patchstack
4.3 Medium TaxoPress Plugin simple-tags Information Disclosure Sensitive Data Exposure ≤ 3.37.2 Fixed in 3.37.3 CVE-2025-55710 Patchstack
7.5 High GravityWP - Merge Tags Plugin gravitywp-merge-tags Local File Inclusion Merge Tags <= 1.4.4 - Local File Inclusion No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-49271 Patchstack
7.1 High xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.12.06 CVE-2025-47680 Patchstack
4.3 Medium Smart Hashtags [#hashtagger] Plugin hashtagger Broken Access Control ≤ 7.2.3 CVE-2025-46470 Patchstack
7.1 High Empty Tags Remover Plugin empty-tags-remover Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.1.0 CVE-2025-24640 Patchstack
8.8 High Seo Meta Tags Plugin seo-meta-tags Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.4 CVE-2025-31023 Patchstack
7.1 High OmniLeads Scripts and Tags Manager Plugin omnileads-scripts-and-tags-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-31460 Patchstack
7.1 High UTM tags tracking for Contact Form 7 Plugin cf7-utm-tracking Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26544 Patchstack
7.1 High LH OGP Meta Plugin lh-ogp-meta-tags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.73 CVE-2025-30587 Patchstack
7.1 High Hashtags Plugin wp-hashtags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-28931 Patchstack
6.5 Medium WooCommerce Display Products by Tags Plugin woocommerce-display-products-by-tags Cross-Site Scripting ≤ 1.0.0 CVE-2025-27331 Patchstack
7.1 High Tags to Keywords Plugin tags-to-meta-keywords Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-22685 Patchstack
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
8.5 High DynamicTags Plugin dynamictags SQL Injection ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-22348 Patchstack
6.1 Medium xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.12.04 CVE-2024-9357 Wordfence
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
6.1 Medium WordPress Social Share Buttons Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.19 CVE-2024-9219 Wordfence
4.3 Medium Multiline files upload for contact form 7 Plugin tags Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation ≤ 2.8.1 CVE-2024-9891 Wordfence
6.1 Medium ShiftController Employee Shift Scheduling Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.9.66 CVE-2024-9435 Wordfence
7.3 High Special Text Boxes Plugin tags Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 6.2.4 CVE-2024-8481 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Tags ≤ 2.1.2 CVE-2024-2922 Wordfence
6.4 Medium Elegant Addons for elementor Plugin elegant-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML tags ≤ 1.0.8 CVE-2024-3066 Wordfence
6.4 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates ≤ 3.4.6 CVE-2024-1679 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 3.10.5 CVE-2024-3891 Wordfence
6.3 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Broken Access Control Improper Authorization ≤ 3.4.6 CVE-2024-1677 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags ≤ 1.3.971 CVE-2024-3889 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 1.3.971 CVE-2024-2799 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 4.8.8 CVE-2024-2736 Wordfence
6.4 Medium WordPress Tag and Category Manager – AI Autotagger Plugin simple-tags Cross-Site Scripting AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.0 CVE-2024-2830 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 2.6.2 CVE-2024-1326 Wordfence
6.5 Medium HREFLANG Tags Lite Plugin hreflang-tags-by-dcgws Authentication Bypass WordPress HREFLANG Tags Lite Plugin <= 2.0.0 is vulnerable to Broken Authentication No login needed ≤ 2.0.0 CVE-2022-36418 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only