WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 401–450 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Plugin Info Card Plugin wp-plugin-info-card Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Custom Plugin Entry Creation No login needed ≤ 6.2.0 CVE-2026-2023 Wordfence
5.0 Medium MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Server-Side Request Forgery Music Player, Podcast Player & Radio by Sonaar 5.3 - 5.10 - Authenticated (Author+) Server-Side Request Forgery 5.3 – 5.10 CVE-2026-1249 Wordfence
4.3 Medium WP Quick Contact Us Plugin wp-quick-contact-us Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1394 Wordfence
4.3 Medium MDirector Newsletter Plugin mdirector-newsletter Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 4.5.8 CVE-2025-14852 Wordfence
5.5 Medium User Language Switch Plugin user-language-switch Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via 'info_language' Parameter ≤ 1.6.10 CVE-2026-0745 Wordfence
4.3 Medium LatePoint – Calendar Booking Plugin for Appointments and Events Plugin latepoint Cross-Site Request Forgery Calendar Booking Plugin for Appointments and Events <= 5.2.5 - Cross-Site Request Forgery No login needed ≤ 5.2.5 CVE-2025-14873 Wordfence
4.3 Medium SEATT: Simple Event Attendance Plugin simple-event-attendance Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Event Deletion No login needed ≤ 1.5.0 CVE-2026-1983 Wordfence
4.8 Medium Converter for Media – Optimize images | Convert WebP & AVIF Plugin webp-converter-for-media Server-Side Request Forgery Optimize images | Convert WebP & AVIF <= 6.5.1 - Unauthenticated Server-Side Request Forgery via src No login needed ≤ 6.5.1 CVE-2026-1356 Wordfence
4.3 Medium MMA Call Tracking Plugin mma-call-tracking Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 2.3.15 CVE-2026-1215 Wordfence
5.4 Medium Fluent Forms Pro Add On Pack Plugin Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via 'saveDataSource' ≤ 6.1.12 CVE-2026-0632 Wordfence
4.3 Medium TITLE ANIMATOR Plugin title-animator Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1082 Wordfence
4.3 Medium Code Snippets Plugin code-snippets Cross-Site Request Forgery Cross-Site Request Forgery to Cloud Snippet Download/Update Actions No login needed ≤ 3.9.4 CVE-2026-1785 Wordfence
7.2 High All In One Image Viewer Block Plugin image-viewer Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via image-proxy Endpoint No login needed ≤ 1.0.2 CVE-2026-1294 Wordfence
5.4 Medium ThirstyAffiliates Plugin thirstyaffiliates Cross-Site Request Forgery No login needed ≤ 3.11.9 Fixed in 3.11.10 CVE-2026-25024 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.53 Fixed in 1.2.54 CVE-2026-25015 Patchstack
4.3 Medium Enter Addons Plugin enteraddons Cross-Site Request Forgery No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-25014 Patchstack
5.4 Medium Simple Membership WP user Import Plugin simple-membership-wp-user-import Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2026-24986 Patchstack
4.3 Medium Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2026-24966 Patchstack
4.3 Medium Sigmize Plugin sigmize Cross-Site Request Forgery No login needed ≤ 0.0.9 Fixed in 0.0.10 CVE-2026-24962 Patchstack
5.4 Medium Grand Blog Theme grandblog Server-Side Request Forgery No login needed ≤ 3.1.5 Fixed in 3.1.5 CVE-2026-24961 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2026-24942 Patchstack
5.4 Medium Mail Mint Plugin mail-mint Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.19.2 CVE-2026-1447 Wordfence
4.3 Medium Popup Box Plugin ays-popup-box Cross-Site Request Forgery Cross-Site Request Forgery to Popup Status Change No login needed ≤ 6.1.1 CVE-2026-1165 Wordfence
4.3 Medium Stop Spammers Classic Plugin stop-spammer-registrations-plugin Cross-Site Request Forgery Cross-Site Request Forgery via Email Allowlist No login needed ≤ 2026.1 CVE-2025-14795 Wordfence
4.3 Medium Change WP URL Plugin change-wp-url Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1398 Wordfence
4.3 Medium Recooty Plugin recooty Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed 1.0.1 – 1.0.6 CVE-2025-14616 Wordfence
4.3 Medium Bitcoin Donate Button Plugin bitcoin-donate-button Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2026-1380 Wordfence
4.3 Medium imwptip Plugin imwptip Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.1 CVE-2026-1377 Wordfence
7.2 High TableMaster for Elementor Plugin tablemaster-for-elementor Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via 'csv_url' Parameter No login needed ≤ 1.3.6 CVE-2025-14610 Wordfence
6.4 Medium AI Engine Plugin ai-engine Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 3.3.2 CVE-2026-0746 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Cloning No login needed ≤ 2.5.2 CVE-2025-13205 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Renaming No login needed ≤ 2.5.2 CVE-2025-13194 Wordfence
4.3 Medium Friendly Functions for Welcart Plugin friendly-functions-for-welcart Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.5 CVE-2026-1208 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Creation No login needed ≤ 2.5.2 CVE-2025-13139 Wordfence
3.7 Low MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Plugin metform Information Disclosure Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 4.1.0 - Unauthenticated Form Submission Exposure via Forgeable Cookie Value No login needed ≤ 4.1.0 CVE-2026-0633 Wordfence
4.3 Medium AdminQuickbar Plugin adminquickbar Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.9.3 CVE-2025-14630 Wordfence
4.3 Medium Moderate Selected Posts Plugin moderate-selected-posts Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.4 CVE-2025-14907 Wordfence
4.3 Medium Login Page Editor Plugin login-page-editor Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2 CVE-2026-1088 Wordfence
4.3 Medium Set Bulk Post Categories Plugin set-bulk-post-categories Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Post Category Update No login needed ≤ 1.1 CVE-2026-1081 Wordfence
4.3 Medium ZT Captcha Plugin zt-captcha Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.4 CVE-2026-1075 Wordfence
4.3 Medium Star Review Manager Plugin star-review-manager Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.2 CVE-2026-1076 Wordfence
4.3 Medium WP Youtube Video Gallery Plugin wp-youtube-video-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0 CVE-2025-14906 Wordfence
7.2 High Frontis Blocks Plugin frontis-blocks Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'url' Parameter No login needed ≤ 1.1.6 CVE-2026-0807 Wordfence
4.3 Medium Alex User Counter Plugin user-counter Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 6.0 CVE-2026-1070 Wordfence
4.3 Medium Simple Crypto Shortcodes Plugin simple-crypto-shortcodes Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0.2 CVE-2025-14903 Wordfence
4.3 Medium Related Posts Thumbnails Plugin related-posts-thumbnails Cross-Site Request Forgery No login needed ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-24596 Patchstack
4.3 Medium GeoDirectory Plugin geodirectory Cross-Site Request Forgery No login needed ≤ 2.8.149 Fixed in 2.8.150 CVE-2026-24549 Patchstack
5.4 Medium Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.91 CVE-2026-24548 Patchstack
4.3 Medium WP Term Order Plugin wp-term-order Cross-Site Request Forgery No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2026-24542 Patchstack
4.3 Medium Kama Thumbnail Plugin kama-thumbnail Cross-Site Request Forgery No login needed ≤ 3.5.1 CVE-2026-24521 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only