WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–23 of 23 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | WPForms | Cross-Site Scripting Reflected Cross-Site Scripting via 'page_title' POST Parameter No login needed |
≤ 2.0.2 |
CVE-2026-88996 |
Wordfence | |
| 4.9 Medium | WPForms | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content |
≤ 2.0.0.1 |
CVE-2026-15782 |
Wordfence | |
| 5.3 Medium | WPForms | Content Injection Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name No login needed |
≤ 1.10.2 |
CVE-2026-12127 |
Wordfence | |
| 7.5 High | Contact Form by WPForms | Broken Access Control No login needed |
≤ 1.10.0.4 Fixed in 1.10.0.5 |
CVE-2026-48835 |
Patchstack | |
| 5.3 Medium | WPForms | Other Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint No login needed |
≤ 1.10.0.4 |
CVE-2026-7792 |
Wordfence | |
| 8.5 High | Views for WPForms | SQL Injection |
≤ 3.4.6 Fixed in 3.4.7 |
CVE-2026-42742 |
Patchstack | |
| 8.1 High | Contact Form by WPForms | Cross-Site Request Forgery No login needed |
≤ 1.10.0.2 Fixed in 1.10.0.3 |
CVE-2026-40764 |
Patchstack | |
| 6.5 Medium | Contact Form by WPForms | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.9.8.7 Fixed in 1.9.9.2 |
CVE-2026-25339 |
Patchstack | |
| 4.3 Medium | Contact Form by WPForms | Broken Access Control |
≤ 1.9.9.3 Fixed in 1.9.9.4 |
CVE-2026-32446 |
Patchstack | |
| 6.1 Medium | WPForms | Cross-Site Scripting No login needed |
≤ 1.7.8 |
CVE-2020-36919 |
VulnCheck | |
| 5.4 Medium | WPForms Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter |
≤ 1.9.5 |
CVE-2025-3794 |
Wordfence | |
| 6.4 Medium | WPForms Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter |
≤ 1.9.3.1 |
CVE-2024-13403 |
Wordfence | |
| 4.3 Medium | Contact Form by WPForms | Broken Access Control |
≤ 1.9.2.2 Fixed in 1.9.2.3 |
CVE-2024-56276 |
Patchstack | |
| 4.7 Medium | WPForms | Cross-Site Scripting Admin+ Stored XSS |
< 1.9.2.3 Fixed in 1.9.2.3 |
CVE-2024-11223 |
WPScan | |
| 8.5 High | WPForms | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation |
1.8.4 – 1.9.2.1 |
CVE-2024-11205 |
Wordfence | |
| 3.5 Low | WPForms | Cross-Site Scripting Admin+ Stored XSS |
< 1.9.1.6 Fixed in 1.9.1.6 |
CVE-2024-7056 |
WPScan | |
| 4.3 Medium | WPForms – Easy Form Builder | Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed |
≤ 1.9.1.6 |
CVE-2024-10593 |
Wordfence | |
| 5.3 Medium | Contact Form by WPForms – Drag & Drop Form Builder | Price Manipulation Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation No login needed |
≤ 1.8.7.2 |
CVE-2024-3649 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Cross-Site Request Forgery Cross-Site Request Forgery via save_view No login needed |
≤ 3.2.2 |
CVE-2024-0373 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Broken Access Control Missing Authorization via create_view |
≤ 3.2.2 |
CVE-2024-0371 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Broken Access Control Missing Authorization via save_view |
≤ 3.2.2 |
CVE-2024-0370 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Cross-Site Request Forgery Cross-Site Request Forgery via create_view No login needed |
≤ 3.2.2 |
CVE-2024-0374 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Broken Access Control Missing Authorization via get_form_fields |
≤ 3.2.2 |
CVE-2024-0372 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.