WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 189 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.13 Fixed in 3.9.14 CVE-2026-57694 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Instructor+ Arbitrary Post Overwrite via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12274 WPScan
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Subscriber+ Arbitrary Auto-Approved Comment Creation < 3.9.13 Fixed in 3.9.13 CVE-2026-12273 WPScan
5.4 Medium Tutor LMS Plugin tutor Broken Access Control Subscriber+ Arbitrary Quiz Attempt Modification via IDOR < 3.9.13 Fixed in 3.9.13 CVE-2026-12271 WPScan
5.3 Medium Academy LMS Plugin academy Broken Access Control Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure No login needed ≤ 3.8.1 CVE-2026-5348 Wordfence
6.4 Medium Tutor LMS Plugin tutor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title ≤ 3.9.13 CVE-2026-13443 Wordfence
6.5 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Cross-Site Scripting ≤ 3.7.27 Fixed in 3.7.28 CVE-2026-57330 Patchstack
4.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Authenticated (Student+) Arbitrary Course Announcement Modification ≤ 2.2.1 CVE-2026-11773 Wordfence
4.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control ≤ 3.7.30 Fixed in 3.7.31 CVE-2026-57640 Patchstack
6.5 Medium Masteriyo LMS Plugin learning-management-system Information Disclosure Unauthenticated Course Progress Disclosure and Deletion No login needed < 2.2.1 Fixed in 2.2.1 CVE-2026-10824 WPScan
4.9 Medium Tutor LMS Plugin tutor SQL Injection Authenticated (Administrator+) SQL Injection via 'data' Parameter ≤ 3.9.11 CVE-2026-10736 Wordfence
6.5 Medium Masteriyo - LMS Plugin learning-management-system Authentication Bypass LMS plugin <= 2.1.8 - Broken Authentication No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2026-42743 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control No login needed ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-40743 Patchstack
6.5 Medium MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control No login needed < 4.7.16 Fixed in 4.7.16 CVE-2025-64215 Patchstack
6.5 Medium MasterStudy LMS Pro Plus Plugin SQL Injection Authenticated (Instructor+) SQL Injection via 'columns' Parameter ≤ 4.8.20 CVE-2026-8653 Wordfence
4.3 Medium LearnPress – WordPress LMS Plugin for Create and Sell Online Courses Plugin learnpress Price Manipulation WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authenticated (Subscriber+) Payment Bypass to Free Course Enrollment via 'quantity' Parameter ≤ 4.3.5 CVE-2026-7648 Wordfence
5.3 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter No login needed ≤ 3.9.9 CVE-2026-6965 Wordfence
4.4 Medium Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 8.2.6 CVE-2026-6712 Wordfence
6.1 Medium Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 8.2.6 CVE-2026-6711 Wordfence
5.3 Medium Tutor LMS Plugin tutor Broken Access Control Authenticated (Subscriber+) Arbitrary Course Content Manipulation via tutor_update_course_content_order No login needed ≤ 3.9.8 CVE-2026-5502 Wordfence
6.5 Medium Tutor LMS Plugin tutor SQL Injection Authenticated (Admin+) SQL Injection via 'date' Parameter ≤ 3.9.8 CVE-2026-6080 Wordfence
6.5 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters ≤ 3.7.25 CVE-2026-4817 Wordfence
5.4 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-40740 Patchstack
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification ≤ 3.9.7 CVE-2026-3371 Wordfence
6.5 Medium LifterLMS Plugin lifterlms SQL Injection Authenticated (Custom+) SQL Injection via 'order' Parameter ≤ 9.2.1 CVE-2026-5207 Wordfence
5.4 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment ≤ 3.9.7 CVE-2026-3358 Wordfence
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint No login needed ≤ 2.1.7 CVE-2026-5167 Wordfence
6.5 Medium WP Courses LMS Plugin wp-courses Cross-Site Scripting ≤ <= 3.2.26 Fixed in 3.2.27 CVE-2026-31914 Patchstack
6.5 Medium LearnDash LMS Plugin sfwd-lms SQL Injection Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter ≤ 5.0.3 CVE-2026-3079 Wordfence
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-32223 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2026-23799 Patchstack
6.5 Medium Academy LMS Plugin academy Broken Access Control ≤ 3.5.3 Fixed in 3.5.4 CVE-2026-25372 Patchstack
6.4 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Cross-Site Scripting for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode ≤ 3.7.11 CVE-2026-0559 Wordfence
5.3 Medium Tutor LMS Plugin tutor Information Disclosure Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action No login needed ≤ 3.9.5 CVE-2026-1371 Wordfence
5.9 Medium Tutor LMS BunnyNet Integration Plugin tutor-lms-bunnynet-integration Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2026-24584 Patchstack
5.4 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion ≤ 3.9.4 CVE-2026-0548 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API No login needed ≤ 4.3.2.4 CVE-2025-14798 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion ≤ 3.9.2 CVE-2025-13935 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass ≤ 3.9.3 CVE-2025-13934 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification ≤ 3.9.3 CVE-2025-13628 Wordfence
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details ≤ 3.9.3 CVE-2025-13679 Wordfence
5.4 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion ≤ 4.3.2.1 CVE-2025-14802 Wordfence
5.3 Medium Creator LMS Plugin creatorlms Broken Access Control No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2025-69359 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification No login needed ≤ 4.3.2 CVE-2025-13964 Wordfence
5.4 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Broken Access Control for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion ≤ 3.7.6 CVE-2025-13766 Wordfence
5.3 Medium DesignThemes LMS Addon Plugin designthemes-lms-addon Broken Access Control No login needed ≤ 2.6 CVE-2025-68982 Patchstack
6.5 Medium Academy LMS Plugin academy Cross-Site Scripting ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-68527 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Information Disclosure LMS plugin <= 2.0.3 - Sensitive Data Exposure ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-64270 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure No login needed ≤ 4.3.1 CVE-2025-13956 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin Cross-Site Scripting WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social ≤ 4.3.1 CVE-2025-14387 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only