WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 93 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Team Showcase Supreme Plugin Information Disclosure Unauthenticated Sensitive Data Disclosure via wpm_6310_team_member_details No login needed < 9.3 Fixed in 9.3 CVE-2026-11871 WPScan
5.3 Medium Team Plugin tlp-team Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0 Fixed in 6.0.1 CVE-2026-95592 Patchstack
8.1 High OAuth Single Sign On Plugin miniorange-login-with-eve-online-google-facebook Privilege Escalation Unauthenticated Account Takeover via Unverified Steam OpenID Assertion No login needed 6.25.0 – < 7.0.1 Fixed in 7.0.1 CVE-2026-82183 WPScan
6.5 Medium Simply Schedule Appointments Plugin simply-schedule-appointments Information Disclosure Team Member+ User Email Disclosure via Users and Customers REST Endpoints < 1.6.12.17 Fixed in 1.6.12.17 CVE-2026-16541 WPScan
4.4 Medium Team Members Plugin team-showcase-supreme Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter ≤ 8.7 CVE-2026-12114 Wordfence
6.4 Medium Team Master Plugin team-master Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.1.2 CVE-2026-8870 Wordfence
6.5 Medium Team Showcase Plugin team Cross-Site Scripting ≤ 1.22.28 CVE-2025-62745 Patchstack
8.8 High Wishlist Member Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action ≤ 3.30.1 CVE-2026-6897 Wordfence
4.3 Medium Multicollab: Content Team Collaboration and Editorial Workflow Plugin commenting-feature Broken Access Control Missing Authorization to Authenticated (Subscriber+) Collaboration Comment ≤ 5.2 CVE-2025-4202 Wordfence
7.6 High Team Member Plugin team-showcase-supreme SQL Injection ≤ 8.5 Fixed in 8.6 CVE-2025-68060 Patchstack
7.5 High Team Plugin tlp-team Broken Access Control No login needed ≤ 5.0.11 Fixed in 5.0.12 CVE-2026-25026 Patchstack
5.3 Medium Team Plugin tlp-team Broken Access Control No login needed ≤ 5.0.13 Fixed in 5.0.14 CVE-2026-32396 Patchstack
8.1 High FixTeam Theme fixteam Local File Inclusion No login needed ≤ 1.5.0 CVE-2026-22416 Patchstack
7.7 High Inpersttion For Plugin err-our-team Remote Code Execution Arbitrary Code Execution ≤ 1.0 CVE-2025-52744 Patchstack
6.4 Medium Team Section Block Plugin team-section Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Social Network Link ≤ 2.0.0 CVE-2026-0833 Wordfence
7.1 High Woocommerce Sales Funnel Builder Plugin woosales Cross-Site Scripting Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins No login needed ≤ 1.1, ≤ 1.2 CVE-2025-30631 Patchstack
8.8 High Premium Age Verification / Restriction Plugin age-restriction Privilege Escalation Privilege Escalation Vulnerability in AA-Team WordPress plugins ≤ 3.0.2, ≤ 3.0 CVE-2025-29004 Patchstack
6.5 Medium Team Showcase Plugin team-showcase Cross-Site Scripting ≤ 2.9 Fixed in 3.0.0 CVE-2025-69335 Patchstack
8.6 High Team Plugin tlp-team SQL Injection Unauthenticated SQLi No login needed < 5.0.11 Fixed in 5.0.11 CVE-2025-14124 WPScan
6.4 Medium All-in-One Addons for Elementor – WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team and Countdown Widgets ≤ 2.5.6 CVE-2025-8779 Wordfence
5.3 Medium Devs CRM – Manage tasks, attendance and teams all together Plugin devs-crm Broken Access Control Manage tasks, attendance and teams all together <= 1.1.8 - Unauthenticated Information Expsoure No login needed ≤ 1.1.8 CVE-2025-13092 Wordfence
5.3 Medium Devs CRM – Manage tasks, attendance and teams all together Plugin devs-crm Broken Access Control Manage tasks, attendance and teams all together <= 1.1.8 - Missing Authorization to Unauthenticated Lead Tag Update No login needed ≤ 1.1.8 CVE-2025-13093 Wordfence
4.3 Medium Employee Spotlight – Team Member Showcase & Meet the Team Plugin employee-spotlight Broken Access Control Team Member Showcase & Meet the Team Plugin <= 5.1.3 - Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification ≤ 5.1.3 CVE-2025-13403 Wordfence
7.1 High Team Members Showcase Plugin wps-team Cross-Site Scripting Reflected XSS No login needed < 3.5.0 Fixed in 3.5.0 CVE-2025-11560 WPScan
6.1 Medium Centangle Team Showcase Plugin centangle-team Cross-Site Request Forgery Cross-Site Request Forgery To Plugin's Settings Modification And Stored Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-12456 Wordfence
6.4 Medium Employee Spotlight – Team Member Showcase & Meet the Team Plugin Cross-Site Scripting Team Member Showcase & Meet the Team Plugin <= 5.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.2 CVE-2025-12090 Wordfence
5.3 Medium eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams Plugin eroom-zoom-meetings-webinar Information Disclosure Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information Exposure No login needed ≤ 1.5.6 CVE-2025-11760 Wordfence
6.4 Medium WP Responsive Meet The Team Plugin wp-responsive-meet-the-team Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.1 CVE-2025-11818 Wordfence
6.4 Medium Team Members Plugin team-members Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.5 CVE-2025-8440 Wordfence
7.5 High immonex Kickstart Team Plugin immonex-kickstart-team Local File Inclusion ≤ 1.6.9 Fixed in 1.7.0 CVE-2025-57925 Patchstack
4.3 Medium Team Plugin tlp-team Broken Access Control ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-57975 Patchstack
5.3 Medium Team Manager Plugin wp-team-manager Broken Access Control No login needed ≤ 2.6.8 CVE-2025-58222 Patchstack
6.5 Medium Custom Team Manager Plugin custom-team-manager Cross-Site Scripting ≤ 2.4.2 CVE-2025-58840 Patchstack
8.1 High Employee Directory – Staff Listing & Team Directory Plugin employee-directory PHP Object Injection Staff Listing & Team Directory plugin for WordPress plugin <= 4.5.5 - PHP Object Injection No login needed ≤ 4.5.5 CVE-2025-53243 Patchstack
6.3 Medium Inpersttion For Plugin err-our-team Remote Code Execution Authenticated (Contributor+) Arbitrary Function Call ≤ 1.0 CVE-2025-8905 Wordfence
10.0 Critical BeeTeam368 Extensions Plugin beeteam368-extensions Local File Inclusion No login needed ≤ 1.9.4 CVE-2025-25174 Patchstack
8.8 High BeeTeam368 Extensions Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 2.3.5 CVE-2025-6423 Wordfence
7.1 High Team Showcase Plugin team-showcase-cm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49247 Patchstack
8.8 High BeeTeam368 Extensions Plugin Path Traversal Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion ≤ 2.3.4 CVE-2025-6381 Wordfence
8.8 High BeeTeam368 Extensions Pro Plugin Path Traversal Authenticated (Subscriber+) Directory Traversal to Arbitrary File Deletion ≤ 2.3.4 CVE-2025-6379 Wordfence
6.5 Medium Theme Junkie Team Content Plugin theme-junkie-team-content Cross-Site Scripting ≤ 0.1.1 CVE-2025-53301 Patchstack
7.6 High Team Builder Plugin a-team-showcase Broken Access Control ≤ 1.5.7 CVE-2025-32308 Patchstack
6.5 Medium HT Team Member Plugin ht-team-member Cross-Site Scripting ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-49309 Patchstack
4.3 Medium Team Showcase Plugin team-showcase-cm Arbitrary Shortcode Execution ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49250 Patchstack
4.3 Medium Team Showcase Plugin team-showcase-cm Broken Access Control ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49248 Patchstack
6.4 Medium NinjaTeam Chat for Telegram Plugin ninjateam-telegram Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via username Parameter ≤ 1.1 CVE-2025-5236 Wordfence
5.4 Medium EKC Tournament Manager Plugin ekc-tournament-manager Cross-Site Request Forgery Create Tournaments/Teams via CSRF < 2.2.2 Fixed in 2.2.2 CVE-2024-9709 WPScan
4.8 Medium Team Members Showcase Plugin wps-team Cross-Site Scripting Editor+ Stored XSS < 4.4.2 Fixed in 4.4.2 CVE-2024-9236 WPScan
6.4 Medium Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder Plugin wps-team Cross-Site Scripting Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.1 CVE-2025-3521 Wordfence
8.8 High Team Members Plugin wps-team PHP Object Injection ≤ 3.4.4 Fixed in 3.4.5 CVE-2025-32686 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only