WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 284 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High User Registration & Membership Plugin user-registration Privilege Escalation User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation No login needed < 4.1.2 Fixed in 4.1.2 CVE-2025-2563 WPScan
5.3 Medium User Registration & Membership – Custom Registration Form, Login Form, and User Profile Plugin user-registration Broken Access Control Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification No login needed ≤ 4.1.3 CVE-2025-3282 Wordfence
4.3 Medium User Registration & Membership – Custom Registration Form, Login Form, and User Profile Plugin user-registration Broken Access Control Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update ≤ 4.1.3 CVE-2025-3292 Wordfence
6.5 Medium BuddyPress Members Only Plugin buddypress-members-only Cross-Site Scripting ≤ 3.5.3 Fixed in 3.6.3 CVE-2025-31812 Patchstack
6.5 Medium Team Members for Elementor Page Builder Plugin team-members-for-elementor Cross-Site Scripting ≤ 1.0.4 CVE-2025-31771 Patchstack
4.3 Medium Our Team Members Plugin our-team-members Information Disclosure Sensitive Data Exposure ≤ 2.2 Fixed in 2.3 CVE-2025-30802 Patchstack
6.5 Medium MicroPayments Plugin paid-membership Cross-Site Scripting ≤ 2.9.29 Fixed in 2.9.30 CVE-2025-31075 Patchstack
7.1 High MemberSpace Plugin memberspace Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.13 Fixed in 2.1.14 CVE-2025-26874 Patchstack
7.1 High MicroPayments Plugin paid-membership Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-26579 Patchstack
7.1 High Members page only for logged in users Plugin members-page-only-for-logged-in-users Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.2 CVE-2025-28901 Patchstack
9.8 Critical SetSail Membership Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 1.0.3 CVE-2025-1564 Wordfence
9.8 Critical Academist Membership Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 1.1.6 CVE-2025-1671 Wordfence
9.8 Critical Alloggio Membership Plugin Authentication Bypass Authentication Bypass via Social Login Account Takeover No login needed ≤ 1.1 CVE-2025-1638 Wordfence
6.1 Medium User Registration & Membership – Custom Registration Form, Login Form, and User Profile Plugin user-registration Cross-Site Scripting Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting No login needed ≤ 4.0.4 CVE-2025-1511 Wordfence
4.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.1.6 CVE-2024-13560 Wordfence
5.3 Medium SureMembers Plugin suremembers-core Information Disclosure Sensitive Information Exposure No login needed ≤ 1.10.6 CVE-2024-12434 Wordfence
6.1 Medium s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions Plugin s2member Cross-Site Scripting Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241216 - Reflected Cross-Site Scripting No login needed ≤ 241216 CVE-2024-11376 Wordfence
4.3 Medium Team – Team Members Showcase Plugin tlp-team Broken Access Control Team Members Showcase Plugin <= 4.4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 4.4.9 CVE-2024-13439 Wordfence
3.5 Low Paid Membership Plugin Cross-Site Scripting Admin+ Stored XSS < 4.15.20 Fixed in 4.15.20 CVE-2024-13121 WPScan
7.1 High Simple Membership Custom Messages Plugin simple-membership-custom-messages Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 Fixed in 2.5 CVE-2025-24660 Patchstack
5.3 Medium Membership Plugin – Restrict Content Plugin restrict-content Information Disclosure Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 3.2.13 CVE-2024-11090 Wordfence
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license) ≤ 1.3.3 CVE-2024-13370 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 1.3.4 CVE-2024-13368 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
7.1 High Explara Membership Plugin explara-membership Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.7 CVE-2025-23583 Patchstack
5.3 Medium Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member Information Disclosure User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure No login needed ≤ 2.9.1 CVE-2025-0318 Wordfence
9.8 Critical Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Authentication Bypass Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_id No login needed ≤ 2.13.7 CVE-2024-12919 Wordfence
5.3 Medium Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Information Disclosure Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.4 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.13.4 CVE-2024-11291 Wordfence
9.8 Critical Biagiotti Membership Plugin Authentication Bypass Authentication Bypass via biagiotti_membership_check_facebook_user No login needed ≤ 1.0.2 CVE-2024-12287 Wordfence
8.8 High s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions Plugin s2member Information Disclosure Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 241114 CVE-2024-8326 Wordfence
6.5 Medium YourMembership Single Sign On Plugin login-with-yourmembership Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2023-37987 Patchstack
5.3 Medium Restrict – membership, site, content and user access restrictions Plugin restricted-content Information Disclosure membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.2.8 CVE-2024-11351 Wordfence
5.3 Medium Members Plugin members Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 3.2.10 CVE-2024-11008 Wordfence
6.3 Medium ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Arbitrary Shortcode Execution Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.51 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 4.0.51 CVE-2024-10681 Wordfence
4.3 Medium WP User Manager – User Profile Builder & Membership Plugin wp-user-manager Broken Access Control User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration ≤ 2.9.11 CVE-2024-10537 Wordfence
4.3 Medium WP User Manager – User Profile Builder & Membership Plugin wp-user-manager Broken Access Control User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal ≤ 2.9.11 CVE-2024-10216 Wordfence
5.3 Medium Simple Membership Plugin simple-membership Information Disclosure Exposure of Private Personal Information to an Unauthorized Actor No login needed ≤ 4.5.5 CVE-2024-11088 Wordfence
6.1 Medium Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App Plugin peepso-core Cross-Site Scripting Social Network, Membership, Registration, User Profiles, Premium – Mobile App <=7.0.3.0 - Reflected Cross-Site Scripting No login needed ≤ 7.0.3.0 CVE-2024-11447 Wordfence
5.4 Medium ARMember Plugin armember-membership Cross-Site Request Forgery No login needed ≤ 4.0.5, < 6.7.1 Fixed in 4.0.6 CVE-2022-47424 Patchstack
7.1 High Dashing Memberships Plugin dashing-memberships Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51760 Patchstack
7.3 High Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Arbitrary Shortcode Execution Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.13.0 CVE-2024-10261 Wordfence
7.1 High Team Showcase and Slider – Team Members Builder Plugin team-showcase-ultimate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51763 Patchstack
9.8 Critical WP Membership Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6.2 CVE-2024-10547 Wordfence
7.5 High Paid Memberships Pro Plugin paid-memberships-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2024-37277 Patchstack
6.4 Medium WP-Members Plugin wp-members Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout Shortcode ≤ 3.4.9.5 CVE-2024-10374 Wordfence
4.7 Medium Simple Membership Plugin simple-membership Open Redirect No login needed ≤ 4.5.3 Fixed in 4.5.4 CVE-2024-49682 Patchstack
6.1 Medium WP-Members Membership Plugin wp-members Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.4.9.5 CVE-2024-9231 Wordfence
8.8 High RS-Members Plugin rs-members Privilege Escalation ≤ 1.0.3 CVE-2024-49219 Patchstack
8.8 High TAKETIN To WP Membership Plugin taketin-to-wp-membership PHP Object Injection ≤ 2.8.17 CVE-2024-49226 Patchstack
6.3 Medium Indeed Membership Pro Plugin Broken Access Control Missing Authorization Checks 7.3 – 8.6 CVE-2020-36833 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only