WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 4,601–4,650 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 93 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium CubeWP Plugin cubewp-framework Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode ≤ 1.1.26 CVE-2025-8615 Wordfence
4.4 Medium Integrate Dynamics 365 CRM Plugin integrate-dynamics-365-crm Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Field Mapping Configuration ≤ 1.1.1 CVE-2026-0725 Wordfence
5.3 Medium PAYGENT for WooCommerce Plugin woocommerce-for-paygent-payment-main Broken Access Control Missing Authorization to Unauthenticated Payment Callback Manipulation No login needed ≤ 2.4.6 CVE-2025-14078 Wordfence
5.3 Medium CubeWP – All-in-One Dynamic Content Framework Plugin cubewp-framework Information Disclosure All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Information Exposure No login needed ≤ 1.1.27 CVE-2025-12129 Wordfence
5.3 Medium Spin Wheel Plugin spin-wheel Other Unauthenticated Client-Side Prize Manipulation via 'prize_index' Parameter No login needed ≤ 2.1.0 CVE-2026-0808 Wordfence
4.4 Medium CM E-Mail Blacklist Plugin cm-email-blacklist Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'black_email' Parameter ≤ 1.6.2 CVE-2026-0691 Wordfence
6.4 Medium Team Section Block Plugin team-section Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Social Network Link ≤ 2.0.0 CVE-2026-0833 Wordfence
4.9 Medium Advanced Ads – Ad Manager & AdSense Plugin advanced-ads SQL Injection Ad Manager & AdSense <= 2.0.15 - Authenticated (Admin+) SQL Injection ≤ 2.0.15 CVE-2025-12984 Wordfence
5.3 Medium User Registration Using Contact Form 7 Plugin user-registration-using-contact-form-7 Information Disclosure Authenticated (Subscriber+) Information Exposure No login needed ≤ 2.5 CVE-2025-12825 Wordfence
4.3 Medium Phrase TMS Integration Plugin memsource-connector Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 4.7.5 CVE-2025-12168 Wordfence
5.3 Medium Community Events Plugin community-events Broken Access Control Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter No login needed ≤ 1.5.6 CVE-2025-14029 Wordfence
5.3 Medium Payment Button for PayPal Plugin wp-paypal Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Creation No login needed ≤ 1.2.3.41 CVE-2025-14463 Wordfence
6.5 Medium Gutenberg Thim Blocks Plugin thim-blocks Path Traversal Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Parameter ≤ 1.0.1 CVE-2025-13725 Wordfence
4.3 Medium RepairBuddy Plugin computer-repair-shop Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders ≤ 4.1116 CVE-2026-0820 Wordfence
5.9 Medium Feeds for YouTube Pro Plugin feeds-for-youtube Path Traversal Unauthenticated Arbitrary File Read via Path Traversal No login needed ≤ 2.6.0 CVE-2025-12002 Wordfence
4.4 Medium Filr – Secure document library Plugin filr-protection Cross-Site Scripting Secure document library <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML Upload ≤ 1.2.11 CVE-2025-14632 Wordfence
5.8 Medium Quick Contact Form Plugin quick-contact-form Other Unauthenticated Open Mail Relay No login needed ≤ 8.2.6 CVE-2025-12718 Wordfence
6.5 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation ≤ 2.7.2 CVE-2025-14450 Wordfence
5.3 Medium WP Hotel Booking Plugin wp-hotel-booking Information Disclosure Unauthenticated Sensitive Information Exposure via 'email' Parameter No login needed ≤ 2.2.7 CVE-2025-14075 Wordfence
5.1 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Scripting Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS < 19.6.25 Fixed in 19.6.25 CVE-2019-25297 VulnCheck
5.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Missing Authorization to Unauthenticated Payment Status Bypass No login needed ≤ 3.6.9 CVE-2025-14757 Wordfence
6.4 Medium User Submitted Posts Plugin user-submitted-posts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode ≤ 20260110 CVE-2026-0913 Wordfence
5.3 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 6.5.5 CVE-2026-1004 Wordfence
4.3 Medium GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools Plugin getgenie Broken Access Control AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion ≤ 4.3.0 CVE-2026-1003 Wordfence
6.1 Medium RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Cross-Site Scripting RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className No login needed ≤ 5.0.10 CVE-2025-14375 Wordfence
4.3 Medium LEAV Last Email Address Validator Plugin last-email-address-validator Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.7.1 CVE-2025-14853 Wordfence
5.0 Medium DK PDF – WordPress PDF Generator Plugin dk-pdf Server-Side Request Forgery WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery ≤ 2.3.0 CVE-2025-14793 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Broken Access Control Missing Authorization to Unauthenticated Rede Order Logs Deletion No login needed ≤ 5.1.5 CVE-2026-0942 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Other Unauthenticated Order Status Manipulation No login needed ≤ 5.1.2 CVE-2026-0939 Wordfence
6.4 Medium Related Posts by Taxonomy Plugin related-posts-by-taxonomy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'related_posts_by_tax' Shortcode ≤ 2.7.6 CVE-2026-0916 Wordfence
4.3 Medium All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Plugin all-in-one-seo-pack Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure ≤ 4.9.2 CVE-2025-14384 Wordfence
6.5 Medium MailerLite - WooCommerce integration Plugin woo-mailerlite Broken Access Control WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion ≤ 3.1.3 CVE-2026-1000 Wordfence
4.3 Medium Shield Security Plugin wp-simple-firewall Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator ≤ 21.0.9 CVE-2025-15370 Wordfence
5.3 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed ≤ 6.4.8 CVE-2025-15526 Wordfence
6.5 Medium Awesome Support – WordPress HelpDesk & Support Plugin awesome-support Broken Access Control WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion No login needed ≤ 6.3.6 CVE-2025-12641 Wordfence
4.3 Medium WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure ≤ 10.2.2 CVE-2025-15527 Wordfence
4.3 Medium Booking Calendar Plugin booking Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 10.14.11 CVE-2025-14982 Wordfence
6.4 Medium AffiliateX Plugin affiliatex Broken Access Control Authenticated (Subscriber+) Missing Authorization to Stored Cross-Site Scripting via save_customization_settings 1.0.0 – 1.3.9.3 CVE-2025-13859 Wordfence
5.3 Medium Kalium Theme Broken Access Control Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_request No login needed ≤ 3.29 CVE-2025-12895 Wordfence
5.4 Medium WP-Members Membership Plugin wp-members Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields ≤ 3.5.4.3 CVE-2025-14448 Wordfence
5.3 Medium PayHere Payment Gateway Plugin for WooCommerce Plugin payhere-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.3.9 CVE-2025-15475 Wordfence
4.3 Medium Stopwords for comments Plugin stopwords-for-comments Broken Access Control Missing Authorization to Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-15376 Wordfence
5.3 Medium Float Payment Gateway Plugin float-gateway Broken Access Control Improper Authorization to Unauthenticated Order Status Manipulation No login needed ≤ 1.1.9 CVE-2025-15513 Wordfence
4.3 Medium SocialChamp with Plugin auto-post-to-social-media-wp-to-social-champ Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.3.5 CVE-2025-14846 Wordfence
5.3 Medium Perfit WooCommerce Plugin perfit-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed ≤ 1.0.1 CVE-2025-14173 Wordfence
4.4 Medium Electric Studio Download Counter Plugin electric-studio-download-counter Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters ≤ 2.4 CVE-2026-0741 Wordfence
5.3 Medium Aplazo Payment Gateway Plugin aplazo-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation No login needed ≤ 1.4.3 CVE-2025-15512 Wordfence
4.4 Medium Short Link Plugin short-link Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Administration Settings Page ≤ 1.0 CVE-2026-0813 Wordfence
4.4 Medium LinkedIn SC Plugin linkedin-sc Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Page ≤ 1.1.9 CVE-2026-0812 Wordfence
4.4 Medium WP Allowed Hosts Plugin wp-allow-hosts Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'allowed-hosts' Parameter ≤ 1.0.8 CVE-2026-0734 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only