WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 4,301–4,350 of 17,733 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Popup Box | Cross-Site Request Forgery Cross-Site Request Forgery to Popup Status Change No login needed |
≤ 6.1.1 |
CVE-2026-1165 |
Wordfence | |
| 5.4 Medium | SupportCandy – Helpdesk & Customer Support Ticket System | Broken Access Control Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference |
≤ 3.4.4 |
CVE-2026-1251 |
Wordfence | |
| 6.5 Medium | SupportCandy – Helpdesk & Customer Support Ticket System | SQL Injection Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter |
≤ 3.4.4 |
CVE-2026-0683 |
Wordfence | |
| 5.3 Medium | Ajax Load More – Infinite Scroll, Lazy Load & Load More | Broken Access Control Infinite Scroll, Lazy Load & Load More <= 7.8.1 - Incorrect Authorization to Unauthenticated Private/Draft Post Title and Excerpt Exposure No login needed |
≤ 7.8.1 |
CVE-2025-15525 |
Wordfence | |
| 5.3 Medium | Booking Calendar | Broken Access Control Missing Authorization to Unauthenticated Booking Details Exposure No login needed |
≤ 10.14.13 |
CVE-2026-1431 |
Wordfence | |
| 5.3 Medium | NEX-Forms – Ultimate Forms | Broken Access Control Ultimate Forms Plugin for WordPress <= 9.1.8 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 9.1.8 |
CVE-2025-15510 |
Wordfence | |
| 5.3 Medium | WP Adminify | Information Disclosure Unauthenticated Sensitive Information Exposure via 'get-addons-list' REST API No login needed |
≤ 4.0.7.7 |
CVE-2026-1060 |
Wordfence | |
| 4.3 Medium | Stop Spammers Classic | Cross-Site Request Forgery Cross-Site Request Forgery via Email Allowlist No login needed |
≤ 2026.1 |
CVE-2025-14795 |
Wordfence | |
| 6.4 Medium | Passster – Password Protect Pages and Content | Cross-Site Scripting Password Protect Pages and Content <= 4.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 4.2.24 |
CVE-2025-14865 |
Wordfence | |
| 4.4 Medium | WP Google Ad Manager | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Admin Settings |
≤ 1.1.0 |
CVE-2026-1399 |
Wordfence | |
| 4.3 Medium | Change WP URL | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0 |
CVE-2026-1398 |
Wordfence | |
| 4.3 Medium | Recooty | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
1.0.1 – 1.0.6 |
CVE-2025-14616 |
Wordfence | |
| 6.4 Medium | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library | Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.14 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.14 |
CVE-2025-14283 |
Wordfence | |
| 6.1 Medium | SEO Links Interlinking | Cross-Site Scripting Reflected Cross-Site Scripting via 'google_error' Parameter No login needed |
≤ 1.7.9.9.1 |
CVE-2025-14063 |
Wordfence | |
| 4.3 Medium | Bitcoin Donate Button | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0 |
CVE-2026-1380 |
Wordfence | |
| 5.3 Medium | Vzaar Media Management | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 1.2 |
CVE-2026-1391 |
Wordfence | |
| 5.3 Medium | Rupantorpay | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 2.0.0 |
CVE-2025-15511 |
Wordfence | |
| 4.3 Medium | imwptip | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.1 |
CVE-2026-1377 |
Wordfence | |
| 4.4 Medium | Ivory Search | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu_gcse' and 'nothing_found_text' Parameters |
≤ 5.5.13 |
CVE-2026-1053 |
Wordfence | |
| 4.4 Medium | Order Minimum/Maximum Amount Limits for WooCommerce | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Hide Add to Cart Content Fields |
≤ 4.6.8 |
CVE-2026-1381 |
Wordfence | |
| 5.3 Medium | RegistrationMagic | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Settings Modification No login needed |
≤ 6.0.7.4 |
CVE-2026-1054 |
Wordfence | |
| 4.3 Medium | Document Embedder | Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Document Library Entry Deletion |
≤ 2.0.4 |
CVE-2026-1389 |
Wordfence | |
| 5.3 Medium | Simple calendar for Elementor | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Calendar Entry Deletion No login needed |
≤ 1.6.6 |
CVE-2026-1310 |
Wordfence | |
| 6.4 Medium | Simple Folio | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Client name' and 'Link' Meta Fields |
≤ 1.1.1 |
CVE-2025-14039 |
Wordfence | |
| 6.4 Medium | Interactions – Create Interactive Experiences in the Block Editor | Cross-Site Scripting Create Interactive Experiences in the Block Editor <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-12709 |
Wordfence | |
| 6.4 Medium | Buy Now Plus | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.2 |
CVE-2026-1295 |
Wordfence | |
| 6.4 Medium | WPBITS Addons For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.8 |
CVE-2025-9082 |
Wordfence | |
| 5.3 Medium | Database for Contact Form 7, WPforms, Elementor forms | Broken Access Control Missing Authorization to Unauthenticated Form Data Exfiltration via CSV Export No login needed |
≤ 1.4.5 |
CVE-2026-0825 |
Wordfence | |
| 6.4 Medium | Forms Bridge | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 4.2.5 |
CVE-2026-1244 |
Wordfence | |
| 5.3 Medium | User Activity Log | Broken Access Control Unauthenticated Limited Arbitrary Option Update No login needed |
≤ 2.2 |
CVE-2025-13471 |
WPScan | |
| 4.4 Medium | Appointment Hour Booking – Booking Calendar | Cross-Site Scripting Booking Calendar <= 1.5.60 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Min/Max Length' Field Configuration |
≤ 1.5.60 |
CVE-2026-1083 |
Wordfence | |
| 4.3 Medium | Easy Replace Image | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Attachment Replacement |
≤ 3.5.2 |
CVE-2026-1298 |
Wordfence | |
| 6.4 Medium | Target Video Easy Publish | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter |
≤ 3.8.8 |
CVE-2025-8072 |
Wordfence | |
| 6.4 Medium | AI Engine | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 3.3.2 |
CVE-2026-0746 |
Wordfence | |
| 5.3 Medium | Link Invoice Payment for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation No login needed |
≤ 2.8.0 |
CVE-2025-14971 |
Wordfence | |
| 6.8 Medium | Recipe Card Blocks | SQL Injection Contributor+ SQLi |
< 3.4.13 Fixed in 3.4.13 |
CVE-2025-14973 |
WPScan | |
| 4.3 Medium | CubeWP – All-in-One Dynamic Content Framework | Information Disclosure All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Post Disclosure in class-cubewp-search-ajax-hooks.php |
≤ 1.1.27 |
CVE-2025-6461 |
Wordfence | |
| 5.3 Medium | WP Go Maps (formerly WP Google Maps) | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Map Engine Setting Modification No login needed |
≤ 10.0.04 |
CVE-2026-0593 |
Wordfence | |
| 6.1 Medium | Save as PDF Plugin by PDFCrowd | Cross-Site Scripting Reflected Cross-Site Scripting via options No login needed |
≤ 4.5.5 |
CVE-2026-0862 |
Wordfence | |
| 5.3 Medium | WP Directory Kit | Information Disclosure Unauthenticated Email Exposure via wdk_public_action No login needed |
≤ 1.4.9 |
CVE-2025-13920 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed |
≤ 2.5.2 |
CVE-2025-13205 |
Wordfence | |
| 6.1 Medium | Timeline Event History | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.2 |
CVE-2026-1127 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed |
≤ 2.5.2 |
CVE-2025-13194 |
Wordfence | |
| 4.3 Medium | Friendly Functions for Welcart | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.2.5 |
CVE-2026-1208 |
Wordfence | |
| 4.4 Medium | JavaScript Notifier | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings |
≤ 1.2.8 |
CVE-2026-1191 |
Wordfence | |
| 4.4 Medium | Responsive Header | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters |
≤ 1.0 |
CVE-2026-1300 |
Wordfence | |
| 6.4 Medium | LeadBI | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_id' Shortcode Attribute |
≤ 1.7 |
CVE-2026-1189 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed |
≤ 2.5.2 |
CVE-2025-13139 |
Wordfence | |
| 6.4 Medium | CM CSS Columns | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute |
≤ 1.2.1 |
CVE-2026-1098 |
Wordfence | |
| 4.4 Medium | Meta-box GalleryMeta | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Image Caption |
≤ 3.0.1 |
CVE-2026-1302 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.