WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 142 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control No login needed ≤ 10.3.2 Fixed in 10.3.3 CVE-2025-63054 Patchstack
5.3 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Information Disclosure Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure No login needed ≤ 1.1.5 CVE-2025-13006 Wordfence
6.4 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Cross-Site Scripting Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.5 CVE-2025-12417 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Request Forgery Cross-Site Request Forgery to Account Disconnection No login needed ≤ 19.12.0 CVE-2025-13143 Wordfence
6.5 Medium Survey Maker Plugin survey-maker Broken Access Control ≤ 5.1.9.4 Fixed in 5.1.9.5 CVE-2025-64276 Patchstack
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 5.1.9.4 CVE-2025-12891 Wordfence
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control Missing Authorization to Unauthenticated Limited Option Update No login needed ≤ 5.1.9.4 CVE-2025-12892 Wordfence
8.1 High Modal Survey Plugin modal-survey Local File Inclusion No login needed ≤ 2.0.2.0.1 CVE-2025-39468 Patchstack
5.3 Medium User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Plugin userfeedback-lite Broken Access Control Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure No login needed ≤ 1.8.0 CVE-2025-10694 Wordfence
7.1 High Likert Survey Master Plugin likert-survey-master Cross-Site Scripting No login needed ≤ 0.8.0.1 CVE-2025-53426 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting No login needed ≤ 5.1.8.8 Fixed in 5.1.8.9 CVE-2025-48098 Patchstack
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 5.1.8.8 Fixed in 5.1.8.9 CVE-2025-48095 Patchstack
6.4 Medium SurveyAnyplace Plugin surveyanyplace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-10196 Wordfence
6.5 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read 5.1.16 – 6.1.1 CVE-2025-9260 Wordfence
7.5 High Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Local File Inclusion No login needed ≤ 19.11.0 Fixed in 19.11.1 CVE-2025-53328 Patchstack
8.5 High Quiz And Survey Master Plugin quiz-master-next SQL Injection ≤ 10.2.4 Fixed in 10.2.5 CVE-2025-55708 Patchstack
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Plugin Settings Update ≤ 19.9.0 CVE-2025-3880 Wordfence
6.1 Medium Spiritual Gifts Survey Plugin Cross-Site Request Forgery Unauthenticated CSRF to XSS No login needed ≤ 0.9.10 CVE-2025-0688 WPScan
6.1 Medium Spiritual Gifts Survey Plugin Cross-Site Request Forgery Unauthenticated CSRF to XSS No login needed ≤ 0.9.10 CVE-2025-0687 WPScan
6.4 Medium SurveyJS Plugin surveyjs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.12.32 CVE-2025-3815 Wordfence
7.1 High Modal Survey Plugin modal-survey Cross-Site Scripting No login needed ≤ 2.0.2.0.1 CVE-2025-39469 Patchstack
9.3 Critical Modal Survey Plugin modal-survey SQL Injection No login needed ≤ 2.0.2.0.1 CVE-2025-39471 Patchstack
4.9 Medium TS Poll – Survey, Versus Poll, Image Poll, Video Poll Plugin poll-wp SQL Injection Survey, Versus Poll, Image Poll, Video Poll <= 2.4.6 - Authenticated (Administrator+) SQL Injection via 's' Parameter ≤ 2.4.6 CVE-2025-3470 Wordfence
9.8 Critical Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder Plugin everest-forms PHP Object Injection Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.1.1 CVE-2025-3439 Wordfence
4.3 Medium Survey Maker Plugin survey-maker Authentication Bypass No login needed ≤ 5.1.6.3 Fixed in 5.1.6.4 CVE-2025-32275 Patchstack
5.3 Medium SurveyJS Plugin surveyjs Broken Access Control No login needed ≤ 1.12.20 Fixed in 1.12.57 CVE-2025-32256 Patchstack
6.5 Medium SurveyJS Plugin surveyjs Cross-Site Scripting ≤ 1.12.20 Fixed in 1.12.57 CVE-2025-32167 Patchstack
6.1 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Author+ Stored XSS No login needed < 9.2.1 Fixed in 9.2.1 CVE-2024-10679 WPScan
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Other Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing No login needed ≤ 5.2.12 CVE-2024-13666 Wordfence
7.2 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.0.9 CVE-2024-13497 Wordfence
5.9 Medium Awesome Surveys Plugin awesome-surveys Cross-Site Scripting ≤ 2.0.10 CVE-2025-28878 Patchstack
4.3 Medium Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics Plugin cookiebot Broken Access Control Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission ≤ 4.4.1 CVE-2025-1666 Wordfence
7.1 High RS Survey Plugin rs-survey Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23485 Patchstack
8.8 High SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile ≤ 1.12.17 CVE-2024-12544 Wordfence
6.4 Medium Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily Plugin yayforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.1 CVE-2024-12522 Wordfence
5.3 Medium WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Information Disclosure Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.0.8 CVE-2024-13829 Wordfence
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 5.1.3.5 Fixed in 5.1.3.6 CVE-2025-22664 Patchstack
6.5 Medium WordPress Survey & Poll – Quiz, Survey and Poll Plugin wp-survey-and-poll SQL Injection Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) SQL Injection ≤ 1.7.5 CVE-2024-13596 Wordfence
5.5 Medium Survey Maker Plugin survey-maker Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Survey Question ≤ 5.1.3.3 CVE-2024-13505 Wordfence
7.1 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2025-22295 Patchstack
6.4 Medium Quill Forms | Conversational Multi Step Forms, Surveys & quizzes Plugin quillforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.10.0 CVE-2024-11826 Wordfence
6.4 Medium WordPress Survey & Poll – Quiz, Survey and Poll Plugin wp-survey-and-poll Cross-Site Scripting Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.5 CVE-2024-12528 Wordfence
6.4 Medium Contact Form, Survey & Form Builder – MightyForms Plugin mightyforms Broken Access Control MightyForms plugin <= 1.3.9 - Broken Access Control ≤ 1.3.9 Fixed in 1.3.10 CVE-2024-56002 Patchstack
5.4 Medium Popup Surveys & Polls for WordPress (Mare.io) Plugin popup-surveys Broken Access Control Settings Change ≤ 1.36 CVE-2024-55998 Patchstack
7.2 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Subject No login needed ≤ 5.2.6 CVE-2024-10646 Wordfence
4.3 Medium Quiz And Survey Master Plugin quiz-master-next Broken Access Control ≤ 8.1.10 Fixed in 8.1.11 CVE-2023-37984 Patchstack
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2023-22697 Patchstack
6.4 Medium Contact Form, Survey & Form Builder – MightyForms Plugin mightyforms Cross-Site Scripting MightyForms <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.9 CVE-2024-11897 Wordfence
6.1 Medium Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Plugin formidable Cross-Site Scripting Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter No login needed ≤ 6.16.1.2 CVE-2024-11188 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only