WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–15 of 15 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High TaxoPress Plugin simple-tags PHP Object Injection ≤ 3.51.0 Fixed in 3.52.0 CVE-2026-74012 Patchstack
7.6 High TaxoPress Plugin simple-tags SQL Injection ≤ 3.44.0 Fixed in 3.45.0 CVE-2026-42646 Patchstack
7.2 High Lucky Wheel Giveaway Plugin wp-lucky-wheel Remote Code Execution Authenticated (Administrator+) Remote Code Execution via 'conditional_tags' Parameter ≤ 1.0.22 CVE-2025-14541 Wordfence
7.2 High Lucky Wheel for WooCommerce – Spin a Sale Plugin woo-lucky-wheel Remote Code Execution Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags ≤ 1.1.13 CVE-2025-14509 Wordfence
7.5 High GravityWP - Merge Tags Plugin gravitywp-merge-tags Local File Inclusion Merge Tags <= 1.4.4 - Local File Inclusion No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2025-49271 Patchstack
7.1 High xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.12.06 CVE-2025-47680 Patchstack
7.1 High Empty Tags Remover Plugin empty-tags-remover Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.1.0 CVE-2025-24640 Patchstack
8.8 High Seo Meta Tags Plugin seo-meta-tags Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.4 CVE-2025-31023 Patchstack
7.1 High OmniLeads Scripts and Tags Manager Plugin omnileads-scripts-and-tags-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-31460 Patchstack
7.1 High UTM tags tracking for Contact Form 7 Plugin cf7-utm-tracking Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26544 Patchstack
7.1 High LH OGP Meta Plugin lh-ogp-meta-tags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.73 CVE-2025-30587 Patchstack
7.1 High Hashtags Plugin wp-hashtags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-28931 Patchstack
7.1 High Tags to Keywords Plugin tags-to-meta-keywords Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-22685 Patchstack
8.5 High DynamicTags Plugin dynamictags SQL Injection ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-22348 Patchstack
7.3 High Special Text Boxes Plugin tags Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 6.2.4 CVE-2024-8481 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only