WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 60 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-62061 Patchstack
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Unauthenticated Group Member List Disclosure via pm_get_all_users_from_group No login needed < 6.0.0.0 Fixed in 6.0.0.0 CVE-2026-16290 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group < 6.0.0.0 Fixed in 6.0.0.0 CVE-2026-16289 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Arbitrary Notification Deletion via IDOR < 5.9.9.8 Fixed in 5.9.9.8 CVE-2026-16291 WPScan
7.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Privilege Escalation Unauthenticated Privilege Escalation via Unrestricted Group ID No login needed < 5.9.9.8 Fixed in 5.9.9.8 CVE-2026-12687 WPScan
3.8 Low ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Premium License Tampering via Missing Authorization < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12690 WPScan
5.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12689 WPScan
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Price Manipulation Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery No login needed < 5.9.9.7 Fixed in 5.9.9.7 CVE-2026-12688 WPScan
7.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Authentication Bypass Broken Authentication No login needed ≤ 5.9.9.6 Fixed in 5.9.9.7 CVE-2026-57697 Patchstack
4.3 Medium Memberships and User Profiles for WooCommerce Plugin ecommerce-user-profiles-by-profilegrid Broken Access Control Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation ≤ 3.4 CVE-2026-11359 Wordfence
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 6.0.0.2 Fixed in 6.0.0.3 CVE-2026-57759 Patchstack
6.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content ≤ 5.9.9.2 CVE-2026-4610 Wordfence
7.1 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Group Joining ≤ 5.9.8.4 CVE-2026-4609 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Group Settings Modification ≤ 5.9.8.4 CVE-2026-4607 Wordfence
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection Authenticated (Subscriber+) SQL Injection via 'rid' Parameter ≤ 5.9.8.4 CVE-2026-4608 Wordfence
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting ≤ 5.9.8.1 Fixed in 5.9.8.2 CVE-2026-25417 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery Cross-Site Request Forgery to Group Membership Request Approval/Denial No login needed ≤ 5.9.8.2 CVE-2026-2494 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion ≤ 5.9.8.1 CVE-2026-2488 Wordfence
5.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Profile and Cover Image Modification No login needed ≤ 5.9.7.2 CVE-2026-1271 Wordfence
4.3 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.9.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Suspension ≤ 5.9.7.2 CVE-2025-13416 Wordfence
7.1 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.9.5.7 Fixed in 5.9.5.8 CVE-2025-4957 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.3 Fixed in 5.9.5.4 CVE-2025-49033 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49876 Patchstack
6.1 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function No login needed ≤ 5.9.5.4 CVE-2025-6977 Wordfence
4.3 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Broken Access Control ≤ 1.0.6 CVE-2025-49980 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Information Disclosure Full Path Disclosure (FPD) ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-52719 Patchstack
4.9 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49877 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.0 Fixed in 5.9.5.1 CVE-2025-47478 Patchstack
9.8 Critical User Profile Meta Manager Plugin user-profile-meta Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.02 CVE-2025-48340 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control ≤ 5.9.5.1 Fixed in 5.9.5.2 CVE-2025-48079 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.4.8 Fixed in 5.9.4.9 CVE-2025-39586 Patchstack
8.8 High ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities PHP Object Injection User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection ≤ 5.9.4.5 CVE-2025-0724 Wordfence
4.3 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.9.4.4 - Missing Authorinzation to Authenticated (Subscriber+) Join Group Requests Management ≤ 5.9.4.4 CVE-2025-1408 Wordfence
6.5 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities SQL Injection User Profiles, Groups and Communities <= 5.9.4.7 - Authenticated (Subscriber+) SQL Injection ≤ 5.9.4.7 CVE-2025-0723 Wordfence
8.8 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities PHP Object Injection ≤ 5.9.4.3 Fixed in 5.9.4.4 CVE-2025-26999 Patchstack
4.3 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.9.4.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Private Messages Disclosure ≤ 5.9.4.2 CVE-2024-13740 Wordfence
5.4 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery User Profiles, Groups and Communities <= 5.9.4.2 - Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 5.9.4.2 CVE-2024-13741 Wordfence
7.1 High Simple User Profile Plugin simple-user-profile Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.9 CVE-2025-25140 Patchstack
7.1 High 3D Avatar User Profile Plugin 3d-avatar-user-profile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-54358 Patchstack
6.5 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.9.3.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Deletion ≤ 5.9.3.6 CVE-2024-10900 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities plugin <= 5.8.7 - Broken Access Control ≤ 5.8.7 Fixed in 5.8.8 CVE-2024-37453 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
6.4 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting User Profiles, Groups and Communities <= 5.9.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.3.2 CVE-2024-8861 Wordfence
8.8 High ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation ≤ 5.8.9 CVE-2024-6411 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 5.8.9 CVE-2024-6410 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control ≤ 5.6.6 Fixed in 5.6.7 CVE-2023-52117 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Missing Authorization ≤ 5.8.6 CVE-2024-5453 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Other Group Members Limit Bypass ≤ 5.8.2 Fixed in 5.8.3 CVE-2024-32774 Patchstack
4.3 Medium ProfileGrid – User Profiles, Memberships, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization ≤ 5.8.3 CVE-2024-3606 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-32772 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only