WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 4,051–4,100 of 17,733 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Checkout Field Manager (Checkout Manager) for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed |
≤ 7.8.5 |
CVE-2025-13930 |
Wordfence | |
| 5.3 Medium | Razorpay for WooCommerce | Broken Access Control Missing Authentication to Unauthenticated Order Modification No login needed |
≤ 4.7.8 |
CVE-2025-14294 |
Wordfence | |
| 6.4 Medium | s2Member | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 251005 |
CVE-2025-13732 |
Wordfence | |
| 4.3 Medium | Country Blocker for AdSense | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0 |
CVE-2025-13413 |
Wordfence | |
| 6.1 Medium | xmlrpc attacks blocker | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'X-Forwarded-For' No login needed |
≤ 1.0 |
CVE-2026-2502 |
Wordfence | |
| 6.5 Medium | Two Factor (2FA) Authentication via Email | Authentication Bypass Two-Factor Authentication Bypass via token |
≤ 1.9.8 |
CVE-2025-13587 |
Wordfence | |
| 5.3 Medium | Checkout Field Manager (Checkout Manager) for WooCommerce | Arbitrary File Upload Unauthenticated Limited File Upload No login needed |
≤ 7.8.1 |
CVE-2025-12500 |
Wordfence | |
| 6.4 Medium | Official StatCounter | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Nickname |
≤ 2.1.0 |
CVE-2025-13048 |
Wordfence | |
| 4.3 Medium | ACF Photo Gallery Field | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Attachment Metadata Modification |
≤ 3.0 |
CVE-2025-12081 |
Wordfence | |
| 5.3 Medium | Web Accessibility by accessiBe | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 2.11 |
CVE-2025-13113 |
Wordfence | |
| 6.4 Medium | Renden | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title |
≤ 1.8.1 |
CVE-2025-12117 |
Wordfence | |
| 4.3 Medium | Advanced Ads – Ad Manager & AdSense | Broken Access Control Ad Manager & AdSense <= 2.0.14 - Missing Authorization to Authenticated (Subscriber+) Ad Placements Update |
≤ 2.0.14 |
CVE-2025-12884 |
Wordfence | |
| 6.4 Medium | Drift | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title |
≤ 1.5.0 |
CVE-2025-12116 |
Wordfence | |
| 5.3 Medium | Popup Builder - Create highly converting, mobile friendly marketing popups. | Broken Access Control Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens No login needed |
≤ 4.4.2 |
CVE-2025-13079 |
Wordfence | |
| 6.4 Medium | Printful Integration for WooCommerce | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery |
≤ 2.2.11 |
CVE-2025-12375 |
Wordfence | |
| 4.4 Medium | Easy SVG Support | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 4.0 |
CVE-2025-12451 |
Wordfence | |
| 4.3 Medium | Mailchimp List Subscribe Form | Cross-Site Request Forgery Cross-Site Request Forgery to Mailchimp List Change No login needed |
≤ 2.0.0 |
CVE-2025-12172 |
Wordfence | |
| 6.1 Medium | Aruba HiSpeed Cache | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.0.2 |
CVE-2025-11706 |
Wordfence | |
| 6.4 Medium | Smartsupp – live chat, AI shopping assistant and chatbots | Cross-Site Scripting live chat, AI shopping assistant and chatbots <= 3.9.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.9.1 |
CVE-2025-12448 |
Wordfence | |
| 6.5 Medium | Aruba HiSpeed Cache | Broken Access Control Missing Authorization to Unauthenticated Plugin's Settings Modification No login needed |
≤ 3.0.2 |
CVE-2025-11725 |
Wordfence | |
| 4.3 Medium | Mesmerize Companion | Broken Access Control Missing Authorization Authenticated (Subscriber+) Settings Update |
≤ 1.6.158 |
CVE-2025-12027 |
Wordfence | |
| 4.3 Medium | Booking Calendar | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Settings Modification |
≤ 10.14.14 |
CVE-2026-2230 |
Wordfence | |
| 6.1 Medium | Ultimate Member | Cross-Site Scripting Reflected Cross-Site Scripting via Filter Parameters No login needed |
≤ 2.11.1 |
CVE-2026-1404 |
Wordfence | |
| 6.5 Medium | WP Import – Ultimate CSV XML Importer | SQL Injection Ultimate CSV XML Importer for WordPress <= 7.37 - Authenticated (Subscriber+) SQL Injection via File Name |
≤ 7.37 |
CVE-2026-1317 |
Wordfence | |
| 4.3 Medium | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' |
≤ 6.4.7 |
CVE-2026-2386 |
Wordfence | |
| 4.9 Medium | Bookster – WordPress Appointment Booking | SQL Injection WordPress Appointment Booking Plugin <= 2.1.1 - Authenticated (Administrator+) SQL Injection via 'raw' |
≤ 2.1.1 |
CVE-2025-8781 |
Wordfence | |
| 6.5 Medium | Brevo - Email, SMS, Web Push, Chat, and more. | Broken Access Control Email, SMS, Web Push, Chat, and more. <= 3.3.0 - Unauthenticated Authorization Bypass via Type Juggling No login needed |
≤ 3.3.0 |
CVE-2025-14799 |
Wordfence | |
| 6.5 Medium | WP-DownloadManager | Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter |
≤ 1.69 |
CVE-2026-2426 |
Wordfence | |
| 6.5 Medium | Blog2Social: Social Media Auto Post & Scheduler | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification |
≤ 8.7.4 |
CVE-2026-1942 |
Wordfence | |
| 5.3 Medium | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Price Manipulation Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment No login needed |
≤ 6.0.6.9 |
CVE-2025-14444 |
Wordfence | |
| 6.4 Medium | Complianz | GDPR/CCPA Cookie Consent | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 7.4.3 |
CVE-2025-11185 |
Wordfence | |
| 5.3 Medium | User Submitted Posts | Broken Access Control Incorrect Authorization to Unauthenticated Category Restriction Bypass via 'user-submitted-category' Parameter No login needed |
≤ 20260113 |
CVE-2026-2126 |
Wordfence | |
| 4.4 Medium | Video Share VOD | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Custom Field Meta Values |
≤ 2.7.11 |
CVE-2025-13727 |
Wordfence | |
| 5.3 Medium | Business Directory | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Listing Modification No login needed |
≤ 6.4.20 |
CVE-2026-1656 |
Wordfence | |
| 5.4 Medium | SiteOrigin Widgets Bundle | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 1.70.4 |
CVE-2026-2127 |
Wordfence | |
| 4.4 Medium | Community Events | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'ce_venue_name' Parameter |
≤ 1.5.7 |
CVE-2026-1649 |
Wordfence | |
| 6.4 Medium | WP Event Aggregator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.8.7 |
CVE-2026-1941 |
Wordfence | |
| 4.3 Medium | Dam Spam | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Pending Comment Deletion No login needed |
≤ 1.0.8 |
CVE-2026-2112 |
Wordfence | |
| 4.3 Medium | Kali Forms | Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure |
≤ 2.4.8 |
CVE-2026-1860 |
Wordfence | |
| 4.4 Medium | YayMail | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Template Elements |
≤ 4.3.2 |
CVE-2026-1943 |
Wordfence | |
| 5.3 Medium | YayMail | Broken Access Control Missing Authorization to Authenticated (Shop Manager+) License Key Deletion via '/yaymail-license/v1/license/delete' Endpoint No login needed |
≤ 4.3.2 |
CVE-2026-1938 |
Wordfence | |
| 4.3 Medium | EventPrime | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Event Modification via 'event_id' Parameter |
≤ 4.2.8.4 |
CVE-2026-1655 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP | Broken Access Control Missing Authorization to Authenticated (Contributor+) Unauthorized Media Upload |
≤ 3.6.1 |
CVE-2026-2633 |
Wordfence | |
| 4.4 Medium | Private Comment | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Label Text Setting |
≤ 0.0.4 |
CVE-2026-2281 |
Wordfence | |
| 4.3 Medium | Taskbuilder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Project/Task Comment Creation |
≤ 5.0.2 |
CVE-2026-1640 |
Wordfence | |
| 6.4 Medium | InteractiveCalculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 1.0.3 |
CVE-2026-1807 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks with AI by Kadence WP | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via 'endpoint' Parameter |
≤ 3.6.1 |
CVE-2026-1857 |
Wordfence | |
| 6.1 Medium | Download Manager | Cross-Site Scripting Reflected Cross-Site Scripting via 'redirect_to' Parameter No login needed |
≤ 3.3.46 |
CVE-2026-1666 |
Wordfence | |
| 4.4 Medium | Membership Plugin – Restrict Content | Cross-Site Scripting Restrict Content <= 3.2.18 - Authenticated (Administrator+) Stored Cross-Site Scripting via Invoice Settings |
≤ 3.2.18 |
CVE-2026-1304 |
Wordfence | |
| 4.3 Medium | Tickera – WordPress Event Ticketing | Broken Access Control WordPress Event Ticketing <= 3.5.6.4 - Missing Authorization to Authenticated (Subscriber+) Event/Post Status Update |
≤ 3.5.6.4 |
CVE-2025-12356 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.