WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–33 of 33 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb Links No login needed < 7.9.6 Fixed in 7.9.6 CVE-2026-78393 WPScan
6.4 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'src' Attribute of <img> Tags ≤ 3.3.2 CVE-2026-12106 Wordfence
4.8 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags No login needed 3.14.10 – < 3.15.2 Fixed in 3.15.2 CVE-2026-80437 WPScan
4.8 Medium Redirection for Contact Form 7 Plugin wpcf7-redirect Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Action Setting Mail-Tags No login needed 2.2.7 – < 3.2.11 Fixed in 3.2.11 CVE-2026-80439 WPScan
4.8 Medium MW WP Form Plugin mw-wp-form Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Completion Message Merge Tags No login needed < 5.1.5 Fixed in 5.1.5 CVE-2026-78363 WPScan
6.1 Medium Sentence To SEO (keywords, description and tags) Plugin sentence-to-seo Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via Settings Page Parameters No login needed ≤ 1.0 CVE-2026-6391 Wordfence
4.4 Medium Sentence To SEO (keywords, description and tags) Plugin sentence-to-seo Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Permanent keywords' Field ≤ 1.0 CVE-2026-4142 Wordfence
4.3 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Deletion via 'b2s_reset_social_meta_tags' AJAX Action ≤ 8.8.2 CVE-2026-4331 Wordfence
4.3 Medium TaxoPress Plugin simple-tags Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Tag Modification ≤ 3.41.0 CVE-2025-14371 Wordfence
5.3 Medium Product Filtering by Categories, Tags, Price Range for WooCommerce Plugin filter-plus Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 1.1.6 CVE-2025-13314 Wordfence
6.5 Medium Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Plugin simple-tags SQL Injection AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection via ORDER BY Clause ≤ 3.40.1 CVE-2025-13922 Wordfence
6.5 Medium Simple Meta Tags Plugin simple-meta-tags Cross-Site Scripting ≤ 1.5 CVE-2025-60142 Patchstack
6.5 Medium xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting ≤ 1.12.06 CVE-2025-58240 Patchstack
4.3 Medium TaxoPress Plugin simple-tags Information Disclosure Sensitive Data Exposure ≤ 3.37.2 Fixed in 3.37.3 CVE-2025-55710 Patchstack
4.3 Medium Smart Hashtags [#hashtagger] Plugin hashtagger Broken Access Control ≤ 7.2.3 CVE-2025-46470 Patchstack
6.5 Medium WooCommerce Display Products by Tags Plugin woocommerce-display-products-by-tags Cross-Site Scripting ≤ 1.0.0 CVE-2025-27331 Patchstack
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
6.1 Medium xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.12.04 CVE-2024-9357 Wordfence
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
6.1 Medium WordPress Social Share Buttons Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.19 CVE-2024-9219 Wordfence
4.3 Medium Multiline files upload for contact form 7 Plugin tags Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation ≤ 2.8.1 CVE-2024-9891 Wordfence
6.1 Medium ShiftController Employee Shift Scheduling Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.9.66 CVE-2024-9435 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Tags ≤ 2.1.2 CVE-2024-2922 Wordfence
6.4 Medium Elegant Addons for elementor Plugin elegant-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML tags ≤ 1.0.8 CVE-2024-3066 Wordfence
6.4 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates ≤ 3.4.6 CVE-2024-1679 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 3.10.5 CVE-2024-3891 Wordfence
6.3 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Broken Access Control Improper Authorization ≤ 3.4.6 CVE-2024-1677 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags ≤ 1.3.971 CVE-2024-3889 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 1.3.971 CVE-2024-2799 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 4.8.8 CVE-2024-2736 Wordfence
6.4 Medium WordPress Tag and Category Manager – AI Autotagger Plugin simple-tags Cross-Site Scripting AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.0 CVE-2024-2830 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 2.6.2 CVE-2024-1326 Wordfence
6.5 Medium HREFLANG Tags Lite Plugin hreflang-tags-by-dcgws Authentication Bypass WordPress HREFLANG Tags Lite Plugin <= 2.0.0 is vulnerable to Broken Authentication No login needed ≤ 2.0.0 CVE-2022-36418 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only