WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 9,351–9,400 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.1 Medium | Poll, Survey & Quiz Maker Plugin by Opinion Stage | Cross-Site Scripting Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS |
< 19.6.25 Fixed in 19.6.25 |
CVE-2019-25297 |
VulnCheck | |
| 9.3 Critical | Omni Secure Files | Arbitrary File Upload Omni Secure Files < 0.1.14 Unauthenticated Arbitrary File Upload No login needed |
< 0.1.14 Fixed in 0.1.14 |
CVE-2012-10064 |
VulnCheck | |
| 8.2 High | Membership Plugin – Restrict Content | Broken Access Control Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposure No login needed |
≤ 3.2.16 Fixed in 3.2.17 |
CVE-2025-14844 |
Wordfence | |
| 5.3 Medium | Cost Calculator Builder | Broken Access Control Missing Authorization to Unauthenticated Payment Status Bypass No login needed |
≤ 3.6.9 Fixed in 3.6.10 |
CVE-2025-14757 |
Wordfence | |
| 6.4 Medium | User Submitted Posts | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode |
≤ 20260110 |
CVE-2026-0913 |
Wordfence | |
| 5.3 Medium | Essential Addons for Elementor | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 6.5.5 |
CVE-2026-1004 |
Wordfence | |
| 4.3 Medium | GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools | Broken Access Control AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion |
≤ 4.3.0 |
CVE-2026-1003 |
Wordfence | |
| 6.1 Medium | RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging | Cross-Site Scripting RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className No login needed |
≤ 5.0.10 Fixed in 5.0.11 |
CVE-2025-14375 |
Wordfence | |
| 4.3 Medium | LEAV Last Email Address Validator | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.7.1 |
CVE-2025-14853 |
Wordfence | |
| 5.0 Medium | DK PDF – WordPress PDF Generator | Server-Side Request Forgery WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery |
≤ 2.3.0 Fixed in 2.3.1 |
CVE-2025-14793 |
Wordfence | |
| 5.3 Medium | Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit | Broken Access Control Missing Authorization to Unauthenticated Rede Order Logs Deletion No login needed |
≤ 5.1.5 |
CVE-2026-0942 |
Wordfence | |
| 5.3 Medium | Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit | Other Unauthenticated Order Status Manipulation No login needed |
≤ 5.1.2 Fixed in 5.1.3 |
CVE-2026-0939 |
Wordfence | |
| 6.4 Medium | Related Posts by Taxonomy | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'related_posts_by_tax' Shortcode |
≤ 2.7.6 Fixed in 2.7.7 |
CVE-2026-0916 |
Wordfence | |
| 4.3 Medium | All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic | Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure |
≤ 4.9.2 Fixed in 4.9.3 |
CVE-2025-14384 |
Wordfence | |
| 6.5 Medium | MailerLite - WooCommerce integration | Broken Access Control WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion |
≤ 3.1.3 Fixed in 3.1.4 |
CVE-2026-1000 |
Wordfence | |
| 4.3 Medium | Shield Security | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator |
≤ 21.0.9 Fixed in 21.0.10 |
CVE-2025-15370 |
Wordfence | |
| 8.8 High | All-in-One Video Gallery | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass |
≤ 4.5.7 Fixed in 4.6.4 |
CVE-2025-12957 |
Wordfence | |
| 5.3 Medium | Fancy Product Designer | WooCommerce | Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed |
≤ 6.4.8 |
CVE-2025-15526 |
Wordfence | |
| 6.5 Medium | Awesome Support – WordPress HelpDesk & Support | Broken Access Control WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion No login needed |
≤ 6.3.6 Fixed in 6.3.7 |
CVE-2025-12641 |
Wordfence | |
| 4.3 Medium | WP Recipe Maker | Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure |
≤ 10.2.2 Fixed in 10.2.3 |
CVE-2025-15527 |
Wordfence | |
| 4.3 Medium | Booking Calendar | Broken Access Control Missing Authorization to Sensitive Information Exposure |
≤ 10.14.11 Fixed in 10.14.12 |
CVE-2025-14982 |
Wordfence | |
| 9.3 Critical | Uploadify | Arbitrary File Upload Uploadify <= 1.0 Unauthenticated Arbitrary File Upload No login needed |
≤ 1.0 |
CVE-2011-10041 |
VulnCheck | |
| 6.4 Medium | AffiliateX | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Stored Cross-Site Scripting via save_customization_settings |
1.0.0 – 1.3.9.3 Fixed in 1.4.0 |
CVE-2025-13859 |
Wordfence | |
| 8.8 High | Supreme Modules Lite | Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via JSON Upload Bypass |
≤ 2.5.62 Fixed in 2.5.63 |
CVE-2025-13062 |
Wordfence | |
| 5.3 Medium | Kalium | Broken Access Control Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_request No login needed |
≤ 3.29 |
CVE-2025-12895 |
Wordfence | |
| 3.7 Low | Drag and Drop Multiple File Upload for Contact Form 7 | Broken Access Control Missing Authorization to Unauthenticated File Deletion No login needed |
≤ 1.3.9.2 Fixed in 1.3.9.3 |
CVE-2025-14457 |
Wordfence | |
| 5.4 Medium | WP-Members Membership | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields |
≤ 3.5.4.3 Fixed in 3.5.4.4 |
CVE-2025-14448 |
Wordfence | |
| 7.5 High | Simply Schedule Appointments | SQL Injection Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters No login needed |
≤ 1.6.9.9 |
CVE-2025-12166 |
Wordfence | |
| 10.0 Critical | Modular DS | Privilege Escalation No login needed |
≤ 2.5.1 Fixed in 2.5.2 |
CVE-2026-23550 |
Patchstack | |
| 5.3 Medium | PayHere Payment Gateway Plugin for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 2.3.9 Fixed in 2.4.0 |
CVE-2025-15475 |
Wordfence | |
| 4.3 Medium | Stopwords for comments | Broken Access Control Missing Authorization to Cross-Site Request Forgery No login needed |
≤ 1.1 |
CVE-2025-15376 |
Wordfence | |
| 5.3 Medium | Float Payment Gateway | Broken Access Control Improper Authorization to Unauthenticated Order Status Manipulation No login needed |
≤ 1.1.9 Fixed in 1.1.10 |
CVE-2025-15513 |
Wordfence | |
| 4.3 Medium | SocialChamp with | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.3.5 |
CVE-2025-14846 |
Wordfence | |
| 5.3 Medium | Perfit WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed |
≤ 1.0.1 |
CVE-2025-14173 |
Wordfence | |
| 4.4 Medium | Electric Studio Download Counter | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters |
≤ 2.4 |
CVE-2026-0741 |
Wordfence | |
| 5.3 Medium | Aplazo Payment Gateway | Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation No login needed |
≤ 1.4.3 Fixed in 1.5.0 |
CVE-2025-15512 |
Wordfence | |
| 4.4 Medium | Short Link | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Administration Settings Page |
≤ 1.0 |
CVE-2026-0813 |
Wordfence | |
| 4.4 Medium | LinkedIn SC | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Page |
≤ 1.1.9 |
CVE-2026-0812 |
Wordfence | |
| 4.4 Medium | WP Allowed Hosts | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'allowed-hosts' Parameter |
≤ 1.0.8 |
CVE-2026-0734 |
Wordfence | |
| 4.4 Medium | WMF Mobile Redirector | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters |
≤ 1.2 |
CVE-2026-0739 |
Wordfence | |
| 7.5 High | Shipping Rate By Cities | SQL Injection Unauthenticated SQL Injection via 'city' Parameter No login needed |
≤ 2.0.0 |
CVE-2025-14770 |
Wordfence | |
| 4.4 Medium | Kunze Law | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 2.1 |
CVE-2025-15486 |
Wordfence | |
| 9.8 Critical | News and Blog Designer Bundle | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 1.1 |
CVE-2025-14502 |
Wordfence | |
| 5.4 Medium | WP-CRM System – Manage Clients and Projects | Broken Access Control Manage Clients and Projects <= 3.4.5 - Missing Authorization to Authenticated (Subscriber+) CRM Data Exposure and Task Modification |
≤ 3.4.5 Fixed in 3.4.6 |
CVE-2025-14854 |
Wordfence | |
| 7.2 High | GetContentFromURL | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'url' Shortcode Attribute |
≤ 1.0 |
CVE-2025-14613 |
Wordfence | |
| 6.4 Medium | SpiceForms Form Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0 |
CVE-2025-12178 |
Wordfence | |
| 7.2 High | GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.1.8 Fixed in 1.2.7 |
CVE-2025-15266 |
Wordfence | |
| 4.4 Medium | Gotham Block Extra Light | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
≤ 1.5.0 |
CVE-2025-15021 |
Wordfence | |
| 6.5 Medium | Gotham Block Extra Light | Path Traversal Authenticated (Contributor+) Arbitrary File Read via 'ghostban' Shortcode |
≤ 1.5.0 |
CVE-2025-15020 |
Wordfence | |
| 5.3 Medium | PDF Resume Parser | Information Disclosure Unauthenticated Sensitive Information Disclosure in SMTP Credentials No login needed |
≤ 1.0 |
CVE-2025-14464 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.