WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 313 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system SQL Injection Authenticated (Subscriber+) Time-based Blind SQL Injection via 'order' and 'orderby' Parameters ≤ 3.7.25 CVE-2026-4817 Wordfence
5.4 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.7 Fixed in 3.9.8 CVE-2026-40740 Patchstack
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Course Content Modification ≤ 3.9.7 CVE-2026-3371 Wordfence
6.5 Medium LifterLMS Plugin lifterlms SQL Injection Authenticated (Custom+) SQL Injection via 'order' Parameter ≤ 9.2.1 CVE-2026-5207 Wordfence
5.4 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Unauthorized Private Course Enrollment ≤ 3.9.7 CVE-2026-3358 Wordfence
7.5 High Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Unauthenticated Arbitrary Billing Profile Overwrite via 'order_id' Parameter No login needed ≤ 3.9.7 CVE-2026-3360 Wordfence
5.3 Medium Masteriyo LMS Plugin learning-management-system Broken Access Control Unauthenticated Authorization Bypass to Arbitrary Order Completion via Stripe Webhook Endpoint No login needed ≤ 2.1.7 CVE-2026-5167 Wordfence
8.8 High Masteriyo LMS Plugin learning-management-system Broken Access Control Missing Authorization to Authenticated (Student+) Privilege Escalation to Administrator ≤ 2.1.6 CVE-2026-4484 Wordfence
8.8 High Creator LMS Plugin creatorlms Privilege Escalation ≤ <= 1.1.18 Fixed in 1.1.19 CVE-2026-32530 Patchstack
6.5 Medium WP Courses LMS Plugin wp-courses Cross-Site Scripting ≤ <= 3.2.26 Fixed in 3.2.27 CVE-2026-31914 Patchstack
8.1 High Tutor LMS Pro Plugin tutor-pro Authentication Bypass Broken Authentication No login needed ≤ 3.9.4 CVE-2026-25406 Patchstack
6.5 Medium LearnDash LMS Plugin sfwd-lms SQL Injection Authenticated (Contributor+) SQL Injection via 'filters[orderby_order]' Parameter ≤ 5.0.3 CVE-2026-3079 Wordfence
7.1 High Website LLMs.txt Plugin website-llms-txt Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.2.6 Fixed in 8.2.7 CVE-2026-27068 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-32223 Patchstack
8.5 High Fox LMS Plugin fox-lms SQL Injection ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2026-31922 Patchstack
9.8 Critical Tutor LMS Pro Plugin Authentication Bypass Authentication Bypass via Social Login No login needed ≤ 3.9.5 CVE-2026-0953 Wordfence
9.8 Critical LMS Elementor Pro Plugin lms-elementor-pro Privilege Escalation No login needed ≤ 1.0.4 CVE-2026-27983 Patchstack
6.5 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2026-23799 Patchstack
7.5 High Tutor LMS Plugin tutor SQL Injection Unauthenticated SQL Injection via coupon_code No login needed ≤ 3.9.6 CVE-2025-13673 Wordfence
6.5 Medium Academy LMS Plugin academy Broken Access Control ≤ 3.5.3 Fixed in 3.5.4 CVE-2026-25372 Patchstack
9.8 Critical Lizza LMS Pro Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2025-13563 Wordfence
6.4 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Cross-Site Scripting for Online Courses and Education <= 3.7.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'stm_lms_courses_grid_display' Shortcode ≤ 3.7.11 CVE-2026-0559 Wordfence
8.1 High Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Course Modification and Deletion ≤ 3.9.5 CVE-2026-1375 Wordfence
5.3 Medium Tutor LMS Plugin tutor Information Disclosure Authenticated (Subscriber+) Information Disclosure in Coupon Details via 'tutor_coupon_details' AJAX Action No login needed ≤ 3.9.5 CVE-2026-1371 Wordfence
5.9 Medium Tutor LMS BunnyNet Integration Plugin tutor-lms-bunnynet-integration Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2026-24584 Patchstack
8.6 High WPLMS Plugin wplms_plugin Arbitrary File Deletion No login needed ≤ 1.9.9.5.4 CVE-2025-69097 Patchstack
3.8 Low Tutor LMS Plugin tutor Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-47555 Patchstack
9.8 Critical Academy LMS – WordPress LMS Plugin for Complete eLearning Solution Plugin academy Privilege Escalation WordPress LMS Plugin for Complete eLearning Solution <= 3.5.0 - Unauthenticated Privilege Escalation via Account Takeover No login needed ≤ 3.5.0 CVE-2025-15521 Wordfence
8.8 High Creator LMS – The LMS for Creators, Coaches, and Trainers Plugin creatorlms Broken Access Control The LMS for Creators, Coaches, and Trainers <= 1.1.12 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update ≤ 1.1.12 CVE-2025-15347 Wordfence
5.4 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.4 - Missing Authorization to Authenticated (Subscriber+) Limited Attachment Deletion ≤ 3.9.4 CVE-2026-0548 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.4 - Missing Authorization to Unauthenticated Sensitive User Information Disclosure via REST API No login needed ≤ 4.3.2.4 CVE-2025-14798 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Course Completion ≤ 3.9.2 CVE-2025-13935 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Course Enrollment Bypass ≤ 3.9.3 CVE-2025-13934 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.9.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Coupon Modification ≤ 3.9.3 CVE-2025-13628 Wordfence
6.5 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via tutor_order_details ≤ 3.9.3 CVE-2025-13679 Wordfence
5.4 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2.2 - Insecure Direct Object Reference to Authenticated (Instructor+) Teacher Material Deletion ≤ 4.3.2.1 CVE-2025-14802 Wordfence
5.3 Medium Creator LMS Plugin creatorlms Broken Access Control No login needed ≤ 1.1.12 Fixed in 1.1.13 CVE-2025-69359 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.2 - Missing Authentication to Unauthenticated Course Modification No login needed ≤ 4.3.2 CVE-2025-13964 Wordfence
5.4 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Broken Access Control for Online Courses and Education <= 3.7.6 Missing Authorization to Authenticated (Subscriber+) Posts and Media Creation, Modification and Deletion ≤ 3.7.6 CVE-2025-13766 Wordfence
5.3 Medium DesignThemes LMS Addon Plugin designthemes-lms-addon Broken Access Control No login needed ≤ 2.6 CVE-2025-68982 Patchstack
6.5 Medium Academy LMS Plugin academy Cross-Site Scripting ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-68527 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Information Disclosure LMS plugin <= 2.0.3 - Sensitive Data Exposure ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-64270 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64214 Patchstack
7.5 High MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64213 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure No login needed ≤ 4.3.1 CVE-2025-13956 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin Cross-Site Scripting WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social ≤ 4.3.1 CVE-2025-14387 Wordfence
9.8 Critical Fox LMS – WordPress LMS Plugin fox-lms Privilege Escalation WordPress LMS Plugin 1.0.4.7 - 1.0.5.1 - Unauthenticated Privilege Escalation via 'createOrder' No login needed 1.0.4.7 – 1.0.5.1 CVE-2025-14156 Wordfence
6.5 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Cross-Site Scripting ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-63042 Patchstack
6.5 Medium WPLMS Plugin wplms_plugin Cross-Site Scripting ≤ 1.9.9.5.4 CVE-2025-63035 Patchstack
9.8 Critical DesignThemes LMS Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.4 CVE-2025-13542 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only