WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–25 of 25 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Comments – wpDiscuz Plugin wpdiscuz Information Disclosure wpDiscuz < 7.6.66 - Unauthenticated Comment Disclosure via SQLi No login needed < 7.6.66 Fixed in 7.6.66 CVE-2026-19704 WPScan
6.1 Medium wpDiscuz Plugin Cross-Site Scripting Unauthenticated Stored XSS via Image URL Conversion No login needed < 7.6.60 Fixed in 7.6.60 CVE-2026-15032 WPScan
7.2 High Comments Plugin wpdiscuz Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'Website' Field No login needed ≤ 7.6.56 CVE-2026-9148 Wordfence
6.5 Medium wpDiscuz Plugin wpdiscuz Other No Rate Limiting on Subscription Endpoints with LIKE Wildcard Bypass No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22216 VulnCheck
4.3 Medium wpDiscuz Plugin wpdiscuz Cross-Site Request Forgery Missing CSRF Protection on wpdGetFollowsPage No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22215 VulnCheck
4.4 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Cross-Site Scripting via Unescaped Attachment URLs < 7.6.47 Fixed in 7.6.47 CVE-2026-22210 VulnCheck
5.5 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Cross-Site Scripting via Unescaped Custom CSS in Style Tag < 7.6.47 Fixed in 7.6.47 CVE-2026-22209 VulnCheck
3.7 Low wpDiscuz Plugin wpdiscuz Other Unsanitized Cookie Email Used as wp_mail() Recipient No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22204 VulnCheck
4.9 Medium wpDiscuz Plugin wpdiscuz Information Disclosure Options Export Leaks OAuth Secrets in Plaintext < 7.6.47 Fixed in 7.6.47 CVE-2026-22203 VulnCheck
8.1 High wpDiscuz Plugin wpdiscuz Cross-Site Request Forgery Destructive GET Action Deletes All Comments by Email No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22202 VulnCheck
5.3 Medium wpDiscuz Plugin wpdiscuz Other IP Address Spoofing in getIP() No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22201 VulnCheck
8.1 High wpDiscuz Plugin wpdiscuz SQL Injection SQL Injection in getAllSubscriptions() No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22193 VulnCheck
6.1 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Stored Cross-Site Scripting in Inline Comment Preview No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22183 VulnCheck
7.5 High wpDiscuz Plugin wpdiscuz Denial of Service Unauthenticated Email Notification Flood via wpdCheckNotificationType No login needed < 7.6.47 Fixed in 7.6.47 CVE-2026-22182 VulnCheck
5.3 Medium Comments – wpDiscuz Plugin wpdiscuz Privilege Escalation wpDiscuz < 7.6.40 - Unauthenticated Account Takeover No login needed < 7.6.40 Fixed in 7.6.40 CVE-2025-13820 WPScan
5.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 7.6.43 Fixed in 7.6.44 CVE-2025-68997 Patchstack
4.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control ≤ 7.6.33 Fixed in 7.6.34 CVE-2025-59591 Patchstack
5.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control No login needed ≤ 7.6.10 Fixed in 7.6.11 CVE-2023-46309 Patchstack
4.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control ≤ 7.6.3 Fixed in 7.6.4 CVE-2023-45760 Patchstack
9.8 Critical Comments – wpDiscuz Plugin wpdiscuz Authentication Bypass wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 7.6.24 CVE-2024-9488 Wordfence
5.3 Medium Comments – wpDiscuz Plugin wpdiscuz Content Injection wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection No login needed ≤ 7.6.21 CVE-2024-6704 Wordfence
6.5 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting ≤ 7.6.18 Fixed in 7.6.19 CVE-2024-35681 Patchstack
5.3 Medium wpDiscuz Plugin wpdiscuz Content Injection No login needed ≤ 7.6.10 Fixed in 7.6.11 CVE-2023-46310 Patchstack
6.4 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text ≤ 7.6.15 CVE-2024-2477 Wordfence
5.9 Medium Comments – wpDiscuz Plugin wpdiscuz Cross-Site Scripting WordPress wpDiscuz Plugin <= 7.6.12 is vulnerable to Cross Site Scripting (XSS) ≤ 7.6.12 Fixed in 7.6.13 CVE-2023-51691 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only