WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–22 of 22 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting Reflected Cross-Site Scripting via Query-String Parameter Name No login needed ≤ 3.5.1 CVE-2026-92554 Wordfence
4.9 Medium ShopLentor Plugin woolentor-addons SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 3.4.5 CVE-2026-16811 Wordfence
4.3 Medium ShopLentor Plugin woolentor-addons Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter ≤ 3.4.5 CVE-2026-16797 Wordfence
4.3 Medium ShopLentor Pro Plugin woolentor-addons-pro Broken Access Control ≤ 2.8.5 Fixed in 2.8.6 CVE-2026-61973 Patchstack
5.3 Medium ShopLentor Pro Plugin woolentor-addons-pro Broken Access Control No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2026-61972 Patchstack
5.4 Medium ShopLentor - WooCommerce Builder for Elementor & Gutenberg Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute ≤ 3.3.8 CVE-2026-6287 Wordfence
6.4 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute ≤ 3.3.5 CVE-2026-4059 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.4 CVE-2025-11823 Wordfence
6.5 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-58990 Patchstack
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
4.3 Medium ShopLentor Plugin woolentor-addons Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template ≤ 2.9.8 CVE-2024-9538 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.9.7 CVE-2024-8668 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget ≤ 2.9.0 CVE-2024-5530 Wordfence
6.5 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting ≤ 2.8.7 Fixed in 2.8.8 CVE-2024-34767 Patchstack
6.4 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode ≤ 2.8.8 CVE-2024-3345 Wordfence
5.3 Medium ShopLentor (formerly WooLentor) Plugin woolentor-addons Broken Access Control Missing Authorization via purchased_new_products No login needed ≤ 2.8.7 CVE-2023-6327 Wordfence
4.3 Medium ShopLentor Plugin woolentor-addons Broken Access Control Improper Authorization via woolentor_template_store ≤ 2.8.1 CVE-2023-7067 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id ≤ 2.8.7 CVE-2024-3991 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.1 CVE-2024-1057 Wordfence
6.4 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link ≤ 2.8.1 CVE-2024-1960 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout ≤ 2.8.3 CVE-2024-2868 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only