WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–100 of 242 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'elevation-track' Shortcode ≤ 4.14 CVE-2026-5451 Wordfence
5.3 Medium AnyTrack Affiliate Link Manager Plugin anytrack-affiliate-link-manager Broken Access Control No login needed ≤ 1.5.5 CVE-2026-39715 Patchstack
5.3 Medium Order Tracking Plugin order-tracking Broken Access Control No login needed ≤ 3.4.3 CVE-2026-39602 Patchstack
5.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.10.2 - Missing Authorization to Unauthenticated Conversion Tracking Data Manipulation No login needed ≤ 7.8.10.2 CVE-2026-2263 Wordfence
8.5 High Miraculous Core Plugin miraculouscore SQL Injection ≤ < 2.1.2 Fixed in 2.1.2 CVE-2026-32516 Patchstack
7.5 High Miraculous Plugin miraculous Broken Access Control No login needed ≤ < 2.1.2 Fixed in 2.1.2 CVE-2026-32515 Patchstack
5.4 Medium Gracey Theme gracey PHP Object Injection Arbitrary Object Instantiation ≤ < 1.4 Fixed in 1.4 CVE-2026-32509 Patchstack
7.5 High WPCargo Track & Trace Plugin wpcargo Broken Access Control No login needed ≤ 8.0.2 CVE-2026-25401 Patchstack
6.1 Medium iTracker360 Plugin itracker360 Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'itracker_license' Settings Field No login needed ≤ 2.2.0 CVE-2026-3572 Wordfence
6.5 Medium TeraWallet – For WooCommerce Plugin woo-wallet Other For WooCommerce plugin <= 1.5.15 - Race Condition ≤ 1.5.15 Fixed in 1.5.16 CVE-2026-32398 Patchstack
9.3 Critical WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem SQL Injection Easy Stripe & Paypal donations plugin <= 1.25 - SQL Injection No login needed ≤ 1.25 CVE-2026-28115 Patchstack
7.1 High UberSlider MouseInteraction Plugin uberslider_mouseinteraction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2026-28101 Patchstack
8.8 High Miraculous Elementor Plugin miraculous-el Authentication Bypass Broken Authentication ≤ 2.0.7 Fixed in 2.0.8 CVE-2025-67998 Patchstack
6.4 Medium InteractiveCalculator Plugin interactivecalculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.0.3 CVE-2026-1807 Wordfence
4.3 Medium MMA Call Tracking Plugin mma-call-tracking Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 2.3.15 CVE-2026-1215 Wordfence
6.4 Medium Wikiloops Track Player Plugin wikiloops-track-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.1 CVE-2026-1611 Wordfence
5.3 Medium Magic Import Document Extractor Plugin magic-import-document-extractor Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.6 CVE-2025-15508 Wordfence
5.3 Medium Magic Import Document Extractor Plugin magic-import-document-extractor Broken Access Control Missing Authorization to Unauthenticated Plugin License Status Modification No login needed ≤ 1.0.5 CVE-2025-15507 Wordfence
4.3 Medium WP Forms Signature Contract Add-On Plugin wp-forms-signature-contract-add-on Broken Access Control Broken Access Control to Notice Dismissal ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-24985 Patchstack
6.4 Medium Interactions – Create Interactive Experiences in the Block Editor Plugin Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-12709 Wordfence
5.9 Medium Affiliate Link Tracker Plugin affiliate-link-tracker Cross-Site Scripting ≤ 0.2 CVE-2025-62077 Patchstack
7.1 High Super Interactive Maps Plugin super-interactive-maps Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-49045 Patchstack
4.3 Medium GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools Plugin getgenie Broken Access Control AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion ≤ 4.3.0 CVE-2026-1003 Wordfence
7.5 High WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Broken Access Control Easy Stripe & Paypal donations plugin <= 1.25 - Arbitrary Content Deletion No login needed ≤ 1.25 CVE-2025-22715 Patchstack
6.5 Medium AdWords Conversion Tracking Code Plugin adwords-conversion-tracking-code Cross-Site Scripting ≤ 1.0 CVE-2025-62118 Patchstack
9.9 Critical MapSVG Plugin mapsvg-lite-interactive-vector-maps Arbitrary File Upload ≤ 8.7.3 Fixed in 8.7.4 CVE-2025-68562 Patchstack
7.5 High WooCommerce Recover Abandoned Cart Plugin rac Broken Access Control Arbitrary Content Deletion No login needed ≤ 24.6.0 Fixed in 24.7.0 CVE-2025-64222 Patchstack
8.1 High Gracioza Theme gracioza Local File Inclusion No login needed ≤ 1.0.15 CVE-2025-49362 Patchstack
6.5 Medium Fancy Product Designer | WooCommerce Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed ≤ 6.4.8 CVE-2025-13231 Wordfence
4.3 Medium WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.25 CVE-2025-58999 Patchstack
4.3 Medium Employee Spotlight – Team Member Showcase & Meet the Team Plugin employee-spotlight Broken Access Control Team Member Showcase & Meet the Team Plugin <= 5.1.3 - Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification ≤ 5.1.3 CVE-2025-13403 Wordfence
7.1 High HandL UTM Grabber / Tracker Plugin handl-utm-grabber Cross-Site Scripting Reflected XSS via handl_landing_page No login needed < 2.8.1 Fixed in 2.8.1 CVE-2025-13073 WPScan
7.1 High HandL UTM Grabber / Tracker Plugin handl-utm-grabber Cross-Site Scripting Reflected XSS via utm_source No login needed < 2.8.1 Fixed in 2.8.1 CVE-2025-13072 WPScan
5.3 Medium Pixel Manager for WooCommerce Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Sensitive Data Exposure No login needed ≤ 1.51.1 Fixed in 1.52.0 CVE-2025-67564 Patchstack
4.3 Medium EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control Missing Authorization to Authenticated (Subscriber+) Tracking Data Modification ≤ 2.3.1 CVE-2025-12133 Wordfence
7.5 High Modula Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via Race Condition 2.13.1 – 2.13.2 CVE-2025-13646 Wordfence
4.3 Medium Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO Plugin tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop Broken Access Control Missing Authorization to Authenticated (Subscriber+) Contract Address Update ≤ 2.4.7 CVE-2025-11773 Wordfence
8.0 High Code Snippets Plugin code-snippets Remote Code Execution Authenticated (Contributor+) PHP Code Injection via extract() and PHP Filter Chains ≤ 3.9.1 CVE-2025-13035 Wordfence
5.3 Medium Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information Exposure No login needed ≤ 1.49.2 CVE-2025-12545 Wordfence
5.3 Medium Restrictions for BuddyPress Plugin bp-restrict Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 1.5.2 CVE-2025-12391 Wordfence
5.3 Medium Cryptocurrency Payment Gateway for WooCommerce Plugin triplea-cryptocurrency-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 2.0.25 CVE-2025-12392 Wordfence
7.5 High Miraculous Plugin miraculous Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2025-58629 Patchstack
9.8 Critical Miraculous Core Plugin miraculouscore Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.0.9 Fixed in 2.0.9 CVE-2025-58627 Patchstack
6.5 Medium All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Plugin aio-time-clock-lite Broken Access Control Tracking Employee Time Has Never Been Easier <= 2.0.3 - Missing Authorization to Page Creation and Information Exposure No login needed ≤ 2.0.3 CVE-2025-11758 Wordfence
6.5 Medium MapSVG Plugin mapsvg-lite-interactive-vector-maps Cross-Site Scripting ≤ 8.7.22 Fixed in 8.7.23 CVE-2025-62930 Patchstack
4.3 Medium Referral Link Tracker Plugin referral-link-tracker Broken Access Control ≤ 1.1.4 CVE-2025-62906 Patchstack
5.3 Medium User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Plugin userfeedback-lite Broken Access Control Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure No login needed ≤ 1.8.0 CVE-2025-10694 Wordfence
5.9 Medium WP Tesseract Plugin wp-tesseract Cross-Site Scripting ≤ 1.0.2 CVE-2025-60176 Patchstack
7.1 High WP-Click-Tracker Plugin wp-click-track Cross-Site Scripting No login needed ≤ 0.7.3 CVE-2025-49954 Patchstack
7.5 High WP Abstracts Plugin wp-abstracts-manuscripts-manager Local File Inclusion No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-48338 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only