WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 9,351–9,400 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 188 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.1 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Scripting Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS < 19.6.25 Fixed in 19.6.25 CVE-2019-25297 VulnCheck
9.3 Critical Omni Secure Files Plugin omni-secure-files Arbitrary File Upload Omni Secure Files < 0.1.14 Unauthenticated Arbitrary File Upload No login needed < 0.1.14 Fixed in 0.1.14 CVE-2012-10064 VulnCheck
8.2 High Membership Plugin – Restrict Content Plugin restrict-content Broken Access Control Restrict Content <= 3.2.16 - Missing Authentication to Insecure Direct Object Reference and Sensitive Information Exposure No login needed ≤ 3.2.16 Fixed in 3.2.17 CVE-2025-14844 Wordfence
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Missing Authorization to Unauthenticated Payment Status Bypass No login needed ≤ 3.6.9 Fixed in 3.6.10 CVE-2025-14757 Wordfence
6.4 Medium User Submitted Posts Plugin user-submitted-posts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode ≤ 20260110 CVE-2026-0913 Wordfence
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 6.5.5 CVE-2026-1004 Wordfence
4.3 Medium GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools Plugin getgenie Broken Access Control AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion ≤ 4.3.0 CVE-2026-1003 Wordfence
6.1 Medium RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Cross-Site Scripting RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2025-14375 Wordfence
4.3 Medium LEAV Last Email Address Validator Plugin last-email-address-validator Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.7.1 CVE-2025-14853 Wordfence
5.0 Medium DK PDF – WordPress PDF Generator Plugin dk-pdf Server-Side Request Forgery WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-14793 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Broken Access Control Missing Authorization to Unauthenticated Rede Order Logs Deletion No login needed ≤ 5.1.5 CVE-2026-0942 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Other Unauthenticated Order Status Manipulation No login needed ≤ 5.1.2 Fixed in 5.1.3 CVE-2026-0939 Wordfence
6.4 Medium Related Posts by Taxonomy Plugin related-posts-by-taxonomy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'related_posts_by_tax' Shortcode ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-0916 Wordfence
4.3 Medium All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Plugin all-in-one-seo-pack Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure ≤ 4.9.2 Fixed in 4.9.3 CVE-2025-14384 Wordfence
6.5 Medium MailerLite - WooCommerce integration Plugin woo-mailerlite Broken Access Control WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion ≤ 3.1.3 Fixed in 3.1.4 CVE-2026-1000 Wordfence
4.3 Medium Shield Security Plugin wp-simple-firewall Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator ≤ 21.0.9 Fixed in 21.0.10 CVE-2025-15370 Wordfence
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via VTT Upload Bypass ≤ 4.5.7 Fixed in 4.6.4 CVE-2025-12957 Wordfence
5.3 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed ≤ 6.4.8 CVE-2025-15526 Wordfence
6.5 Medium Awesome Support – WordPress HelpDesk & Support Plugin awesome-support Broken Access Control WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion No login needed ≤ 6.3.6 Fixed in 6.3.7 CVE-2025-12641 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure ≤ 10.2.2 Fixed in 10.2.3 CVE-2025-15527 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 10.14.11 Fixed in 10.14.12 CVE-2025-14982 Wordfence
9.3 Critical Uploadify Plugin Arbitrary File Upload Uploadify <= 1.0 Unauthenticated Arbitrary File Upload No login needed ≤ 1.0 CVE-2011-10041 VulnCheck
6.4 Medium AffiliateX Plugin affiliatex Broken Access Control Authenticated (Subscriber+) Missing Authorization to Stored Cross-Site Scripting via save_customization_settings 1.0.0 – 1.3.9.3 Fixed in 1.4.0 CVE-2025-13859 Wordfence
8.8 High Supreme Modules Lite Plugin supreme-modules-for-divi Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via JSON Upload Bypass ≤ 2.5.62 Fixed in 2.5.63 CVE-2025-13062 Wordfence
5.3 Medium Kalium Theme Broken Access Control Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_request No login needed ≤ 3.29 CVE-2025-12895 Wordfence
3.7 Low Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Broken Access Control Missing Authorization to Unauthenticated File Deletion No login needed ≤ 1.3.9.2 Fixed in 1.3.9.3 CVE-2025-14457 Wordfence
5.4 Medium WP-Members Membership Plugin wp-members Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields ≤ 3.5.4.3 Fixed in 3.5.4.4 CVE-2025-14448 Wordfence
7.5 High Simply Schedule Appointments Plugin simply-schedule-appointments SQL Injection Unauthenticated SQL Injection via `order` and `append_where_sql` Parameters No login needed ≤ 1.6.9.9 CVE-2025-12166 Wordfence
10.0 Critical Modular DS Plugin modular-connector Privilege Escalation No login needed ≤ 2.5.1 Fixed in 2.5.2 CVE-2026-23550 Patchstack
5.3 Medium PayHere Payment Gateway Plugin for WooCommerce Plugin payhere-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.3.9 Fixed in 2.4.0 CVE-2025-15475 Wordfence
4.3 Medium Stopwords for comments Plugin stopwords-for-comments Broken Access Control Missing Authorization to Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-15376 Wordfence
5.3 Medium Float Payment Gateway Plugin float-gateway Broken Access Control Improper Authorization to Unauthenticated Order Status Manipulation No login needed ≤ 1.1.9 Fixed in 1.1.10 CVE-2025-15513 Wordfence
4.3 Medium SocialChamp with Plugin auto-post-to-social-media-wp-to-social-champ Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.3.5 CVE-2025-14846 Wordfence
5.3 Medium Perfit WooCommerce Plugin perfit-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed ≤ 1.0.1 CVE-2025-14173 Wordfence
4.4 Medium Electric Studio Download Counter Plugin electric-studio-download-counter Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters ≤ 2.4 CVE-2026-0741 Wordfence
5.3 Medium Aplazo Payment Gateway Plugin aplazo-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation No login needed ≤ 1.4.3 Fixed in 1.5.0 CVE-2025-15512 Wordfence
4.4 Medium Short Link Plugin short-link Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Administration Settings Page ≤ 1.0 CVE-2026-0813 Wordfence
4.4 Medium LinkedIn SC Plugin linkedin-sc Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Page ≤ 1.1.9 CVE-2026-0812 Wordfence
4.4 Medium WP Allowed Hosts Plugin wp-allow-hosts Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'allowed-hosts' Parameter ≤ 1.0.8 CVE-2026-0734 Wordfence
4.4 Medium WMF Mobile Redirector Plugin wmf-mobile-redirector Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters ≤ 1.2 CVE-2026-0739 Wordfence
7.5 High Shipping Rate By Cities Plugin shipping-rate-by-cities SQL Injection Unauthenticated SQL Injection via 'city' Parameter No login needed ≤ 2.0.0 CVE-2025-14770 Wordfence
4.4 Medium Kunze Law Plugin kunze-law Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.1 CVE-2025-15486 Wordfence
9.8 Critical News and Blog Designer Bundle Plugin news-and-blog-designer-bundle Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.1 CVE-2025-14502 Wordfence
5.4 Medium WP-CRM System – Manage Clients and Projects Plugin wp-crm-system Broken Access Control Manage Clients and Projects <= 3.4.5 - Missing Authorization to Authenticated (Subscriber+) CRM Data Exposure and Task Modification ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-14854 Wordfence
7.2 High GetContentFromURL Plugin getcontentfromurl Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'url' Shortcode Attribute ≤ 1.0 CVE-2025-14613 Wordfence
6.4 Medium SpiceForms Form Builder Plugin spiceforms-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0 CVE-2025-12178 Wordfence
7.2 High GeekyBot — Generate AI Content Without Prompt, Chatbot and Lead Generation Plugin geeky-bot Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.1.8 Fixed in 1.2.7 CVE-2025-15266 Wordfence
4.4 Medium Gotham Block Extra Light Plugin gotham-block-extra-light Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.5.0 CVE-2025-15021 Wordfence
6.5 Medium Gotham Block Extra Light Plugin gotham-block-extra-light Path Traversal Authenticated (Contributor+) Arbitrary File Read via 'ghostban' Shortcode ≤ 1.5.0 CVE-2025-15020 Wordfence
5.3 Medium PDF Resume Parser Plugin pdf-resume-parser Information Disclosure Unauthenticated Sensitive Information Disclosure in SMTP Credentials No login needed ≤ 1.0 CVE-2025-14464 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only