WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,051–4,100 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 82 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Checkout Field Manager (Checkout Manager) for WooCommerce Plugin woocommerce-checkout-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 7.8.5 CVE-2025-13930 Wordfence
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Missing Authentication to Unauthenticated Order Modification No login needed ≤ 4.7.8 CVE-2025-14294 Wordfence
6.4 Medium s2Member Plugin s2member Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 251005 CVE-2025-13732 Wordfence
4.3 Medium Country Blocker for AdSense Plugin country-blocker-for-adsense Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2025-13413 Wordfence
6.1 Medium xmlrpc attacks blocker Plugin xmlrpc-attacks-blocker Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' No login needed ≤ 1.0 CVE-2026-2502 Wordfence
6.5 Medium Two Factor (2FA) Authentication via Email Plugin two-factor-2fa-via-email Authentication Bypass Two-Factor Authentication Bypass via token ≤ 1.9.8 CVE-2025-13587 Wordfence
5.3 Medium Checkout Field Manager (Checkout Manager) for WooCommerce Plugin woocommerce-checkout-manager Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 7.8.1 CVE-2025-12500 Wordfence
6.4 Medium Official StatCounter Plugin official-statcounter-plugin-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Nickname ≤ 2.1.0 CVE-2025-13048 Wordfence
4.3 Medium ACF Photo Gallery Field Plugin navz-photo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Attachment Metadata Modification ≤ 3.0 CVE-2025-12081 Wordfence
5.3 Medium Web Accessibility by accessiBe Plugin accessibe Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 2.11 CVE-2025-13113 Wordfence
6.4 Medium Renden Theme renden Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 1.8.1 CVE-2025-12117 Wordfence
4.3 Medium Advanced Ads – Ad Manager & AdSense Plugin advanced-ads Broken Access Control Ad Manager & AdSense <= 2.0.14 - Missing Authorization to Authenticated (Subscriber+) Ad Placements Update ≤ 2.0.14 CVE-2025-12884 Wordfence
6.4 Medium Drift Theme drift Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title ≤ 1.5.0 CVE-2025-12116 Wordfence
5.3 Medium Popup Builder - Create highly converting, mobile friendly marketing popups. Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed ≤ 4.4.2 CVE-2025-13079 Wordfence
6.4 Medium Printful Integration for WooCommerce Plugin printful-shipping-for-woocommerce Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 2.2.11 CVE-2025-12375 Wordfence
4.4 Medium Easy SVG Support Plugin easy-svg Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.0 CVE-2025-12451 Wordfence
4.3 Medium Mailchimp List Subscribe Form Plugin mailchimp Cross-Site Request Forgery Cross-Site Request Forgery to Mailchimp List Change No login needed ≤ 2.0.0 CVE-2025-12172 Wordfence
6.1 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.0.2 CVE-2025-11706 Wordfence
6.4 Medium Smartsupp – live chat, AI shopping assistant and chatbots Plugin smartsupp-live-chat Cross-Site Scripting live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.9.1 CVE-2025-12448 Wordfence
6.5 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Broken Access Control Missing Authorization to Unauthenticated Plugin's Settings Modification No login needed ≤ 3.0.2 CVE-2025-11725 Wordfence
4.3 Medium Mesmerize Companion Plugin mesmerize-companion Broken Access Control Missing Authorization Authenticated (Subscriber+) Settings Update ≤ 1.6.158 CVE-2025-12027 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification ≤ 10.14.14 CVE-2026-2230 Wordfence
6.1 Medium Ultimate Member Plugin ultimate-member Cross-Site Scripting Reflected Cross-Site Scripting via Filter Parameters No login needed ≤ 2.11.1 CVE-2026-1404 Wordfence
6.5 Medium WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer SQL Injection Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name ≤ 7.37 CVE-2026-1317 Wordfence
4.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' ≤ 6.4.7 CVE-2026-2386 Wordfence
4.9 Medium Bookster – WordPress Appointment Booking Plugin bookster SQL Injection WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw' ≤ 2.1.1 CVE-2025-8781 Wordfence
6.5 Medium Brevo - Email, SMS, Web Push, Chat, and more. Plugin mailin Broken Access Control Email, SMS, Web Push, Chat, and more. <= 3.3.0 - Unauthenticated Authorization Bypass via Type Juggling No login needed ≤ 3.3.0 CVE-2025-14799 Wordfence
6.5 Medium WP-DownloadManager Plugin wp-downloadmanager Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter ≤ 1.69 CVE-2026-2426 Wordfence
6.5 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification ≤ 8.7.4 CVE-2026-1942 Wordfence
5.3 Medium RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Price Manipulation Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment No login needed ≤ 6.0.6.9 CVE-2025-14444 Wordfence
6.4 Medium Complianz | GDPR/CCPA Cookie Consent Plugin complianz-gdpr Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 7.4.3 CVE-2025-11185 Wordfence
5.3 Medium User Submitted Posts Plugin user-submitted-posts Broken Access Control Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter No login needed ≤ 20260113 CVE-2026-2126 Wordfence
4.4 Medium Video Share VOD Plugin video-share-vod Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Custom Field Meta Values ≤ 2.7.11 CVE-2025-13727 Wordfence
5.3 Medium Business Directory Plugin business-directory-plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Listing Modification No login needed ≤ 6.4.20 CVE-2026-1656 Wordfence
5.4 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 1.70.4 CVE-2026-2127 Wordfence
4.4 Medium Community Events Plugin community-events Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter ≤ 1.5.7 CVE-2026-1649 Wordfence
6.4 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.8.7 CVE-2026-1941 Wordfence
4.3 Medium Dam Spam Plugin dam-spam Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Pending Comment Deletion No login needed ≤ 1.0.8 CVE-2026-2112 Wordfence
4.3 Medium Kali Forms Plugin kali-forms Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure ≤ 2.4.8 CVE-2026-1860 Wordfence
4.4 Medium YayMail Plugin yaymail Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements ≤ 4.3.2 CVE-2026-1943 Wordfence
5.3 Medium YayMail Plugin yaymail Broken Access Control Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint No login needed ≤ 4.3.2 CVE-2026-1938 Wordfence
4.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter ≤ 4.2.8.4 CVE-2026-1655 Wordfence
4.3 Medium Gutenberg Blocks with AI by Kadence WP Plugin kadence-blocks Broken Access Control Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload ≤ 3.6.1 CVE-2026-2633 Wordfence
4.4 Medium Private Comment Plugin private-comment Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting ≤ 0.0.4 CVE-2026-2281 Wordfence
4.3 Medium Taskbuilder Plugin taskbuilder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation ≤ 5.0.2 CVE-2026-1640 Wordfence
6.4 Medium InteractiveCalculator Plugin interactivecalculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute ≤ 1.0.3 CVE-2026-1807 Wordfence
4.3 Medium Gutenberg Blocks with AI by Kadence WP Plugin kadence-blocks Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter ≤ 3.6.1 CVE-2026-1857 Wordfence
6.1 Medium Download Manager Plugin download-manager Cross-Site Scripting Reflected Cross-Site Scripting via 'redirect_to' Parameter No login needed ≤ 3.3.46 CVE-2026-1666 Wordfence
4.4 Medium Membership Plugin – Restrict Content Plugin restrict-content Cross-Site Scripting Restrict Content <= 3.2.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice Settings ≤ 3.2.18 CVE-2026-1304 Wordfence
4.3 Medium Tickera – WordPress Event Ticketing Plugin tickera-event-ticketing-system Broken Access Control WordPress Event Ticketing <= 3.5.6.4 - Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update ≤ 3.5.6.4 CVE-2025-12356 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only