WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–26 of 26 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WP Recipe Maker Plugin wp-recipe-maker Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Comment Content No login needed < 10.8.2 Fixed in 10.8.2 CVE-2026-86601 WPScan
8.2 High WP Recipe Maker Plugin wp-recipe-maker Denial of Service Unauthenticated DoS via Unbounded User Meta Insertion No login needed 9.8.0 – < 10.8.2 Fixed in 10.8.2 CVE-2026-86608 WPScan
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Information Disclosure Subscriber+ Non-Public List Title Disclosure via wprm_search_lists < 10.8.2 Fixed in 10.8.2 CVE-2026-86603 WPScan
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Information Disclosure Subscriber+ Draft and Private Recipe Content Disclosure via wprm_shortcode_preview 10.3.0 – < 10.8.2 Fixed in 10.8.2 CVE-2026-86602 WPScan
9.1 Critical WP Recipe Maker Plugin wp-recipe-maker Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via Recipe Comment Content No login needed ≤ 10.8.1 CVE-2026-89274 Wordfence
5.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'notes' Parameter via REST Preview Endpoint ≤ 10.8.1 CVE-2026-90884 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Recipe Ownership Takeover and Unpublishing via '[wprm-recipe]' Shortcode ≤ 10.8.0 CVE-2026-75905 Wordfence
5.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary Post Metadata Modification via 'recipeId' Parameter No login needed ≤ 10.3.2 CVE-2026-1558 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 10.2.3 CVE-2025-14742 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control ≤ 10.2.4 Fixed in 10.3.0 CVE-2026-24357 Patchstack
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure ≤ 10.2.2 CVE-2025-15527 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 10.2.3 CVE-2025-14385 Wordfence
5.3 Medium WP Recipe Maker Plugin wp-recipe-maker Content Injection No login needed ≤ 10.1.0 Fixed in 10.1.0 CVE-2025-62897 Patchstack
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 9.8.0 CVE-2025-1503 Wordfence
6.5 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'tooltip' ≤ 9.6.1 CVE-2024-9650 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'group_tag' ≤ 9.1.0 CVE-2024-0383 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wprm-recipe-roundup-item Shortcode ≤ 9.3.1 CVE-2024-3490 Wordfence
4.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated Stored Cross-Site Scripting via Video Embed ≤ 9.2.1 CVE-2024-1571 Wordfence
8.8 High WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) SQL Injecton ≤ 9.1.2 CVE-2024-1206 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe Notes ≤ 9.1.0 CVE-2024-0384 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via icon_color ≤ 9.1.0 CVE-2024-0255 Wordfence
5.4 Medium WP Recipe Maker Plugin wp-recipe-maker Path Traversal Directory Traversal ≤ 9.1.0 CVE-2024-0380 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via header_tag ≤ 9.1.0 CVE-2024-0382 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' ≤ 9.1.0 CVE-2024-0381 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 9.1.0 CVE-2023-6958 Wordfence
6.1 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Reflected Cross-Site Scripting via Referer No login needed ≤ 9.1.0 CVE-2023-6970 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only