WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,851–8,900 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 178 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Timeline Event History Plugin timeline-event-history Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2 CVE-2026-1127 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
4.3 Medium Friendly Functions for Welcart Plugin friendly-functions-for-welcart Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.5 CVE-2026-1208 Wordfence
4.4 Medium JavaScript Notifier Plugin javascript-notifier Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.2.8 CVE-2026-1191 Wordfence
4.4 Medium Responsive Header Plugin responsive-header Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters ≤ 1.0 CVE-2026-1300 Wordfence
6.4 Medium LeadBI Plugin leadbi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_id' Shortcode Attribute ≤ 1.7 CVE-2026-1189 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed ≤ 2.5.2 CVE-2025-13139 Wordfence
6.4 Medium CM CSS Columns Plugin cm-css-columns Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute ≤ 1.2.1 CVE-2026-1098 Wordfence
4.4 Medium Meta-box GalleryMeta Plugin meta-box-gallerymeta Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Image Caption ≤ 3.0.1 CVE-2026-1302 Wordfence
3.7 Low MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Plugin metform Information Disclosure Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value No login needed ≤ 4.1.0 CVE-2026-0633 Wordfence
4.3 Medium AdminQuickbar Plugin adminquickbar Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.9.3 CVE-2025-14630 Wordfence
4.4 Medium Postalicious Plugin postalicious Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 3.0.1 CVE-2026-1266 Wordfence
4.3 Medium Meta-box GalleryMeta Plugin meta-box-gallerymeta Broken Access Control Missing Authorization to Authenticated (Author+) Gallery Management ≤ 3.0.1 CVE-2026-0687 Wordfence
4.3 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update 4.1.0 – 4.6.4 CVE-2025-15516 Wordfence
4.3 Medium Moderate Selected Posts Plugin moderate-selected-posts Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.4 CVE-2025-14907 Wordfence
7.2 High User Submitted Posts – Enable Users to Submit Posts from the Front End Plugin user-submitted-posts Cross-Site Scripting Enable Users to Submit Posts from the Front End <= 20251210 - Unauthenticated Stored Cross-Site Scripting via Custom Field No login needed ≤ 20251210 CVE-2026-0800 Wordfence
6.4 Medium Administrative Shortcodes Plugin administrative-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'login' and 'logout' Shortcode Attributes ≤ 0.3.4 CVE-2026-1099 Wordfence
4.3 Medium Login Page Editor Plugin login-page-editor Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2 CVE-2026-1088 Wordfence
6.1 Medium JustClick registration Plugin justclick-subscriber Cross-Site Scripting Reflected Cross-Site Scripting via PHP_SELF No login needed ≤ 0.1 CVE-2025-13676 Wordfence
6.4 Medium ThemeRuby Multi Authors Plugin themeruby-multi-authors Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes ≤ 1.0.0 CVE-2026-1097 Wordfence
5.3 Medium Wise Analytics Plugin wise-analytics Broken Access Control Missing Authorization to Unauthenticated Arbitrary Analytics Database Disclosure via 'name' Parameter No login needed ≤ 1.1.9 CVE-2025-14609 Wordfence
4.4 Medium Cookie consent for developers Plugin cookie-consent-for-developers Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Multiple Settings Fields ≤ 1.7.1 CVE-2026-1084 Wordfence
6.4 Medium GZSEO Plugin gzseo Broken Access Control Authenticated (Contributor+) Authorization Bypass to Stored Cross-Site Scripting ≤ 2.0.11 CVE-2025-14941 Wordfence
5.3 Medium Wizit Gateway for WooCommerce Plugin wizit-gateway-for-woocommerce Broken Access Control Missing Authentication to Unauthenticated Arbitrary Order Cancellation No login needed ≤ 1.3.1 CVE-2025-14843 Wordfence
4.3 Medium Set Bulk Post Categories Plugin set-bulk-post-categories Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Post Category Update No login needed ≤ 1.1 CVE-2026-1081 Wordfence
4.3 Medium ZT Captcha Plugin zt-captcha Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.4 CVE-2026-1075 Wordfence
5.3 Medium Alchemist Ajax Upload Plugin alchemist-ajax-upload Broken Access Control Missing Authorization to Unauthenticated Arbitrary Media File Deletion No login needed ≤ 1.1 CVE-2025-14629 Wordfence
5.4 Medium AIKTP Plugin aiktp Broken Access Control Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions ≤ 5.0.04 CVE-2026-1103 Wordfence
6.4 Medium Alpha Blocks Plugin alpha-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'alpha_block_css' Post Meta ≤ 1.5.0 CVE-2025-14985 Wordfence
6.4 Medium Canto Testimonials Plugin canto-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'fx' Shortcode Attribute ≤ 1.0 CVE-2026-1095 Wordfence
4.9 Medium WP-ClanWars Plugin wp-clanwars SQL Injection Authenticated (Administrator+) SQL Injection via 'orderby' Parameter ≤ 2.0.1 CVE-2026-0806 Wordfence
5.4 Medium Same Category Posts Plugin same-category-posts Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Widget Title Placeholder ≤ 1.1.19 CVE-2025-14797 Wordfence
4.3 Medium Star Review Manager Plugin star-review-manager Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.2 CVE-2026-1076 Wordfence
4.3 Medium WP Youtube Video Gallery Plugin wp-youtube-video-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0 CVE-2025-14906 Wordfence
9.8 Critical Kalrav AI Agent Plugin kalrav-ai-agent Arbitrary File Upload Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action No login needed ≤ 2.3.3 CVE-2025-13374 Wordfence
7.2 High Frontis Blocks Plugin frontis-blocks Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.1.6 CVE-2026-0807 Wordfence
6.4 Medium VK Google Job Posting Manager Plugin vk-google-job-posting-manager Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Job Description Field ≤ 1.2.23 CVE-2025-12836 Wordfence
4.3 Medium Alex User Counter Plugin user-counter Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 6.0 CVE-2026-1070 Wordfence
4.3 Medium Simple Crypto Shortcodes Plugin simple-crypto-shortcodes Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0.2 CVE-2025-14903 Wordfence
7.5 High Administrative Shortcodes Plugin administrative-shortcodes Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'slug' Shortcode Attribute ≤ 0.3.4 CVE-2026-1257 Wordfence
6.5 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion No login needed ≤ 4.6.4 CVE-2025-14947 Wordfence
4.3 Medium Sugar Calendar (Lite) Plugin sugar-calendar-lite Broken Access Control ≤ 3.9.1 Fixed in 3.10.0 CVE-2026-24636 Patchstack
7.5 High EduBlink Core Plugin edublink-core Local File Inclusion ≤ 2.0.7 CVE-2026-24635 Patchstack
5.3 Medium Ultimate Reviews Plugin ultimate-reviews Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.2.16 Fixed in 3.2.17 CVE-2026-24634 Patchstack
5.3 Medium Add Expires Headers & Optimized Minify Plugin add-expires-headers Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.3.0 CVE-2026-24633 Patchstack
5.9 Medium Delay Redirects Plugin delay-redirects Cross-Site Scripting ≤ 1.0.0 CVE-2026-24632 Patchstack
5.4 Medium Rosebud Theme rosebud Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4 CVE-2026-24631 Patchstack
6.5 Medium Stylish Cost Calculator Plugin stylish-cost-calculator Cross-Site Scripting ≤ 8.2.9 CVE-2026-24630 Patchstack
5.9 Medium Web Accessibility with Max Access Plugin accessibility-toolbar Cross-Site Scripting ≤ 2.1.0 CVE-2026-24629 Patchstack
4.3 Medium Trusona Plugin trusona Broken Access Control ≤ 2.0.0 CVE-2026-24627 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only