WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–18 of 18 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium WPForms Plugin wpforms-lite Cross-Site Scripting Reflected Cross-Site Scripting via 'page_title' POST Parameter No login needed ≤ 2.0.2 CVE-2026-88996 Wordfence
4.9 Medium WPForms Plugin wpforms-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content ≤ 2.0.0.1 CVE-2026-15782 Wordfence
5.3 Medium WPForms Plugin wpforms-lite Content Injection Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name No login needed ≤ 1.10.2 CVE-2026-12127 Wordfence
5.3 Medium WPForms Plugin wpforms-lite Other Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint No login needed ≤ 1.10.0.4 CVE-2026-7792 Wordfence
6.5 Medium Contact Form by WPForms Plugin wpforms-lite Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.8.7 Fixed in 1.9.9.2 CVE-2026-25339 Patchstack
4.3 Medium Contact Form by WPForms Plugin wpforms-lite Broken Access Control ≤ 1.9.9.3 Fixed in 1.9.9.4 CVE-2026-32446 Patchstack
6.1 Medium WPForms Plugin wpforms-lite Cross-Site Scripting No login needed ≤ 1.7.8 CVE-2020-36919 VulnCheck
5.4 Medium WPForms Lite Plugin wpforms-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter ≤ 1.9.5 CVE-2025-3794 Wordfence
6.4 Medium WPForms Lite Plugin wpforms-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter ≤ 1.9.3.1 CVE-2024-13403 Wordfence
4.3 Medium Contact Form by WPForms Plugin wpforms-lite Broken Access Control ≤ 1.9.2.2 Fixed in 1.9.2.3 CVE-2024-56276 Patchstack
4.7 Medium WPForms Plugin wpforms-lite Cross-Site Scripting Admin+ Stored XSS < 1.9.2.3 Fixed in 1.9.2.3 CVE-2024-11223 WPScan
4.3 Medium WPForms – Easy Form Builder Plugin wpforms-lite Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed ≤ 1.9.1.6 CVE-2024-10593 Wordfence
5.3 Medium Contact Form by WPForms – Drag & Drop Form Builder Plugin wpforms-lite Price Manipulation Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation No login needed ≤ 1.8.7.2 CVE-2024-3649 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Cross-Site Request Forgery Cross-Site Request Forgery via save_view No login needed ≤ 3.2.2 CVE-2024-0373 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Broken Access Control Missing Authorization via create_view ≤ 3.2.2 CVE-2024-0371 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Broken Access Control Missing Authorization via save_view ≤ 3.2.2 CVE-2024-0370 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Cross-Site Request Forgery Cross-Site Request Forgery via create_view No login needed ≤ 3.2.2 CVE-2024-0374 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Broken Access Control Missing Authorization via get_form_fields ≤ 3.2.2 CVE-2024-0372 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only