WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 8,801–8,850 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | SupportCandy – Helpdesk & Customer Support Ticket System | SQL Injection Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter |
≤ 3.4.4 |
CVE-2026-0683 |
Wordfence | |
| 5.3 Medium | Ajax Load More – Infinite Scroll, Lazy Load & Load More | Broken Access Control Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure No login needed |
≤ 7.8.1 |
CVE-2025-15525 |
Wordfence | |
| 5.3 Medium | Booking Calendar | Broken Access Control Missing Authorization to Unauthenticated Booking Details Exposure No login needed |
≤ 10.14.13 |
CVE-2026-1431 |
Wordfence | |
| 5.3 Medium | NEX-Forms – Ultimate Forms | Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 9.1.8 |
CVE-2025-15510 |
Wordfence | |
| 8.1 High | Custom Login Page Customizer | Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed |
2.1.1 – < 2.5.4 Fixed in 2.5.4 |
CVE-2025-14975 |
WPScan | |
| 5.3 Medium | WP Adminify | Information Disclosure Unauthenticated Sensitive Information Exposure via 'get-addons-list' REST API No login needed |
≤ 4.0.7.7 |
CVE-2026-1060 |
Wordfence | |
| 4.3 Medium | Stop Spammers Classic | Cross-Site Request Forgery Cross-Site Request Forgery via Email Allowlist No login needed |
≤ 2026.1 |
CVE-2025-14795 |
Wordfence | |
| 6.4 Medium | Passster – Password Protect Pages and Content | Cross-Site Scripting Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 4.2.24 |
CVE-2025-14865 |
Wordfence | |
| 9.8 Critical | Snow Monkey Forms | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion via Path Traversal No login needed |
≤ 12.0.3 |
CVE-2026-1056 |
Wordfence | |
| 4.4 Medium | WP Google Ad Manager | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings |
≤ 1.1.0 |
CVE-2026-1399 |
Wordfence | |
| 4.3 Medium | Change WP URL | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0 |
CVE-2026-1398 |
Wordfence | |
| 7.5 High | Frontend File Manager | Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Sharing via 'file_id' Parameter No login needed |
≤ 23.5 |
CVE-2026-1280 |
Wordfence | |
| 4.3 Medium | Recooty | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
1.0.1 – 1.0.6 |
CVE-2025-14616 |
Wordfence | |
| 6.4 Medium | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library | Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.14 |
CVE-2025-14283 |
Wordfence | |
| 6.1 Medium | SEO Links Interlinking | Cross-Site Scripting Reflected Cross-Site Scripting via 'google_error' Parameter No login needed |
≤ 1.7.9.9.1 |
CVE-2025-14063 |
Wordfence | |
| 4.3 Medium | Bitcoin Donate Button | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0 |
CVE-2026-1380 |
Wordfence | |
| 8.8 High | Simple User Registration | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via profile_save_field |
≤ 6.7 |
CVE-2026-0844 |
Wordfence | |
| 8.8 High | Search Atlas SEO – Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization | Broken Access Control Premier SEO Plugin for One-Click WP Publishing & Integrated AI Optimization 2.4.4 - 2.5.12 - Missing Authorization to Authenticated (Subscriber+) Authentication Bypass via Account Takeover |
2.4.4 – 2.5.12 |
CVE-2025-14386 |
Wordfence | |
| 5.3 Medium | Vzaar Media Management | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 1.2 |
CVE-2026-1391 |
Wordfence | |
| 5.3 Medium | Rupantorpay | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 2.0.0 |
CVE-2025-15511 |
Wordfence | |
| 4.3 Medium | imwptip | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.1 |
CVE-2026-1377 |
Wordfence | |
| 7.2 High | AI Engine | Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint |
≤ 3.3.2 |
CVE-2026-1400 |
Wordfence | |
| 4.4 Medium | Ivory Search | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters |
≤ 5.5.13 |
CVE-2026-1053 |
Wordfence | |
| 7.5 High | VidShop – Shoppable Videos for WooCommerce | SQL Injection Shoppable Videos for WooCommerce <= 1.1.4 - Unauthenticated Time-Based SQL Injection via 'fields' No login needed |
≤ 1.1.4 |
CVE-2026-0702 |
Wordfence | |
| 4.4 Medium | Order Minimum/Maximum Amount Limits for WooCommerce | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Hide Add to Cart Content Fields |
≤ 4.6.8 |
CVE-2026-1381 |
Wordfence | |
| 5.3 Medium | RegistrationMagic | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Settings Modification No login needed |
≤ 6.0.7.4 |
CVE-2026-1054 |
Wordfence | |
| 4.3 Medium | Document Embedder | Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry Deletion |
≤ 2.0.4 |
CVE-2026-1389 |
Wordfence | |
| 5.3 Medium | Simple calendar for Elementor | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion No login needed |
≤ 1.6.6 |
CVE-2026-1310 |
Wordfence | |
| 7.3 High | New User Approve | Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Approval, Denial, and Information Disclosure No login needed |
≤ 3.2.2 |
CVE-2026-0832 |
Wordfence | |
| 6.4 Medium | Simple Folio | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Client name' and 'Link' Meta Fields |
≤ 1.1.1 |
CVE-2025-14039 |
Wordfence | |
| 6.4 Medium | Interactions – Create Interactive Experiences in the Block Editor | Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-12709 |
Wordfence | |
| 6.4 Medium | Buy Now Plus | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.2 |
CVE-2026-1295 |
Wordfence | |
| 6.4 Medium | WPBITS Addons For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.8 |
CVE-2025-9082 |
Wordfence | |
| 5.3 Medium | Database for Contact Form 7, WPforms, Elementor forms | Broken Access Control Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export No login needed |
≤ 1.4.5 |
CVE-2026-0825 |
Wordfence | |
| 6.4 Medium | Forms Bridge | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 4.2.5 |
CVE-2026-1244 |
Wordfence | |
| 5.3 Medium | User Activity Log | Broken Access Control Unauthenticated Limited Arbitrary Option Update No login needed |
≤ 2.2 |
CVE-2025-13471 |
WPScan | |
| 4.4 Medium | Appointment Hour Booking – Booking Calendar | Cross-Site Scripting Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration |
≤ 1.5.60 |
CVE-2026-1083 |
Wordfence | |
| 7.2 High | TableMaster for Elementor | Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter No login needed |
≤ 1.3.6 |
CVE-2025-14610 |
Wordfence | |
| 4.3 Medium | Easy Replace Image | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement |
≤ 3.5.2 |
CVE-2026-1298 |
Wordfence | |
| 6.4 Medium | Target Video Easy Publish | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter |
≤ 3.8.8 |
CVE-2025-8072 |
Wordfence | |
| 6.4 Medium | AI Engine | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 3.3.2 |
CVE-2026-0746 |
Wordfence | |
| 5.3 Medium | Link Invoice Payment for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation No login needed |
≤ 2.8.0 |
CVE-2025-14971 |
Wordfence | |
| 6.8 Medium | Recipe Card Blocks | SQL Injection Contributor+ SQLi |
< 3.4.13 Fixed in 3.4.13 |
CVE-2025-14973 |
WPScan | |
| 7.1 High | AhaChat Messenger Marketing | Cross-Site Scripting Reflected XSS No login needed |
≤ 1.1 |
CVE-2025-14316 |
WPScan | |
| 4.3 Medium | CubeWP – All-in-One Dynamic Content Framework | Information Disclosure All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php |
≤ 1.1.27 |
CVE-2025-6461 |
Wordfence | |
| 5.3 Medium | WP Go Maps (formerly WP Google Maps) | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification No login needed |
≤ 10.0.04 |
CVE-2026-0593 |
Wordfence | |
| 6.1 Medium | Save as PDF Plugin by PDFCrowd | Cross-Site Scripting Reflected Cross-Site Scripting via options No login needed |
≤ 4.5.5 |
CVE-2026-0862 |
Wordfence | |
| 7.5 High | Hustle | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upoload via Module Import |
≤ 7.8.9.2 |
CVE-2026-0911 |
Wordfence | |
| 5.3 Medium | WP Directory Kit | Information Disclosure Unauthenticated Email Exposure via wdk_public_action No login needed |
≤ 1.4.9 |
CVE-2025-13920 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed |
≤ 2.5.2 |
CVE-2025-13205 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.