WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 4,601–4,650 of 17,733 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | CubeWP | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cubewp_shortcode_taxonomy Shortcode |
≤ 1.1.26 |
CVE-2025-8615 |
Wordfence | |
| 4.4 Medium | Integrate Dynamics 365 CRM | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Field Mapping Configuration |
≤ 1.1.1 |
CVE-2026-0725 |
Wordfence | |
| 5.3 Medium | PAYGENT for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Payment Callback Manipulation No login needed |
≤ 2.4.6 |
CVE-2025-14078 |
Wordfence | |
| 5.3 Medium | CubeWP – All-in-One Dynamic Content Framework | Information Disclosure All-in-One Dynamic Content Framework <= 1.1.27 - Unauthenticated Information Exposure No login needed |
≤ 1.1.27 |
CVE-2025-12129 |
Wordfence | |
| 5.3 Medium | Spin Wheel | Other Unauthenticated Client-Side Prize Manipulation via 'prize_index' Parameter No login needed |
≤ 2.1.0 |
CVE-2026-0808 |
Wordfence | |
| 4.4 Medium | CM E-Mail Blacklist | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'black_email' Parameter |
≤ 1.6.2 |
CVE-2026-0691 |
Wordfence | |
| 6.4 Medium | Team Section Block | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Social Network Link |
≤ 2.0.0 |
CVE-2026-0833 |
Wordfence | |
| 4.9 Medium | Advanced Ads – Ad Manager & AdSense | SQL Injection Ad Manager & AdSense <= 2.0.15 - Authenticated (Admin+) SQL Injection |
≤ 2.0.15 |
CVE-2025-12984 |
Wordfence | |
| 5.3 Medium | User Registration Using Contact Form 7 | Information Disclosure Authenticated (Subscriber+) Information Exposure No login needed |
≤ 2.5 |
CVE-2025-12825 |
Wordfence | |
| 4.3 Medium | Phrase TMS Integration | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion |
≤ 4.7.5 |
CVE-2025-12168 |
Wordfence | |
| 5.3 Medium | Community Events | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Event Approval via 'eventlist' Parameter No login needed |
≤ 1.5.6 |
CVE-2025-14029 |
Wordfence | |
| 5.3 Medium | Payment Button for PayPal | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Creation No login needed |
≤ 1.2.3.41 |
CVE-2025-14463 |
Wordfence | |
| 6.5 Medium | Gutenberg Thim Blocks | Path Traversal Authenticated (Contributor+) Arbitrary File Read via 'iconSVG' Parameter |
≤ 1.0.1 |
CVE-2025-13725 |
Wordfence | |
| 4.3 Medium | RepairBuddy | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Signature Upload to Orders |
≤ 4.1116 |
CVE-2026-0820 |
Wordfence | |
| 5.9 Medium | Feeds for YouTube Pro | Path Traversal Unauthenticated Arbitrary File Read via Path Traversal No login needed |
≤ 2.6.0 |
CVE-2025-12002 |
Wordfence | |
| 4.4 Medium | Filr – Secure document library | Cross-Site Scripting Secure document library <= 1.2.11 - Authenticated (Administrator+) Stored Cross-Site Scripting via HTML Upload |
≤ 1.2.11 |
CVE-2025-14632 |
Wordfence | |
| 5.8 Medium | Quick Contact Form | Other Unauthenticated Open Mail Relay No login needed |
≤ 8.2.6 |
CVE-2025-12718 |
Wordfence | |
| 6.5 Medium | Wallet System for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation |
≤ 2.7.2 |
CVE-2025-14450 |
Wordfence | |
| 5.3 Medium | WP Hotel Booking | Information Disclosure Unauthenticated Sensitive Information Exposure via 'email' Parameter No login needed |
≤ 2.2.7 |
CVE-2025-14075 |
Wordfence | |
| 5.1 Medium | Poll, Survey & Quiz Maker Plugin by Opinion Stage | Cross-Site Scripting Poll, Survey & Quiz Maker Plugin by Opinion Stage < 19.6.25 Stored XSS |
< 19.6.25 Fixed in 19.6.25 |
CVE-2019-25297 |
VulnCheck | |
| 5.3 Medium | Cost Calculator Builder | Broken Access Control Missing Authorization to Unauthenticated Payment Status Bypass No login needed |
≤ 3.6.9 |
CVE-2025-14757 |
Wordfence | |
| 6.4 Medium | User Submitted Posts | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'usp_access' Shortcode |
≤ 20260110 |
CVE-2026-0913 |
Wordfence | |
| 5.3 Medium | Essential Addons for Elementor | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 6.5.5 |
CVE-2026-1004 |
Wordfence | |
| 4.3 Medium | GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools | Broken Access Control AI Content Writer with Keyword Research & SEO Tracking Tools <= 4.3.0 - Missing Authorization to Authenticated (Author+) Arbitrary Post Deletion |
≤ 4.3.0 |
CVE-2026-1003 |
Wordfence | |
| 6.1 Medium | RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging | Cross-Site Scripting RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className No login needed |
≤ 5.0.10 |
CVE-2025-14375 |
Wordfence | |
| 4.3 Medium | LEAV Last Email Address Validator | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.7.1 |
CVE-2025-14853 |
Wordfence | |
| 5.0 Medium | DK PDF – WordPress PDF Generator | Server-Side Request Forgery WordPress PDF Generator <= 2.3.0 - Authenticated (Author+) Server-Side Request Forgery |
≤ 2.3.0 |
CVE-2025-14793 |
Wordfence | |
| 5.3 Medium | Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit | Broken Access Control Missing Authorization to Unauthenticated Rede Order Logs Deletion No login needed |
≤ 5.1.5 |
CVE-2026-0942 |
Wordfence | |
| 5.3 Medium | Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit | Other Unauthenticated Order Status Manipulation No login needed |
≤ 5.1.2 |
CVE-2026-0939 |
Wordfence | |
| 6.4 Medium | Related Posts by Taxonomy | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'related_posts_by_tax' Shortcode |
≤ 2.7.6 |
CVE-2026-0916 |
Wordfence | |
| 4.3 Medium | All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic | Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.9.2 - Missing Authorization to Authenticated (Contributor+) AI Access Token and Credit Disclosure |
≤ 4.9.2 |
CVE-2025-14384 |
Wordfence | |
| 6.5 Medium | MailerLite - WooCommerce integration | Broken Access Control WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion |
≤ 3.1.3 |
CVE-2026-1000 |
Wordfence | |
| 4.3 Medium | Shield Security | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator |
≤ 21.0.9 |
CVE-2025-15370 |
Wordfence | |
| 5.3 Medium | Fancy Product Designer | WooCommerce | Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed |
≤ 6.4.8 |
CVE-2025-15526 |
Wordfence | |
| 6.5 Medium | Awesome Support – WordPress HelpDesk & Support | Broken Access Control WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion No login needed |
≤ 6.3.6 |
CVE-2025-12641 |
Wordfence | |
| 4.3 Medium | WP Recipe Maker | Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure |
≤ 10.2.2 |
CVE-2025-15527 |
Wordfence | |
| 4.3 Medium | Booking Calendar | Broken Access Control Missing Authorization to Sensitive Information Exposure |
≤ 10.14.11 |
CVE-2025-14982 |
Wordfence | |
| 6.4 Medium | AffiliateX | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Stored Cross-Site Scripting via save_customization_settings |
1.0.0 – 1.3.9.3 |
CVE-2025-13859 |
Wordfence | |
| 5.3 Medium | Kalium | Broken Access Control Missing Authorization to Unauthenticated Mail Relay via kalium_vc_contact_form_request No login needed |
≤ 3.29 |
CVE-2025-12895 |
Wordfence | |
| 5.4 Medium | WP-Members Membership | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Multiple Checkbox and Multiple Select User Profile Fields |
≤ 3.5.4.3 |
CVE-2025-14448 |
Wordfence | |
| 5.3 Medium | PayHere Payment Gateway Plugin for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed |
≤ 2.3.9 |
CVE-2025-15475 |
Wordfence | |
| 4.3 Medium | Stopwords for comments | Broken Access Control Missing Authorization to Cross-Site Request Forgery No login needed |
≤ 1.1 |
CVE-2025-15376 |
Wordfence | |
| 5.3 Medium | Float Payment Gateway | Broken Access Control Improper Authorization to Unauthenticated Order Status Manipulation No login needed |
≤ 1.1.9 |
CVE-2025-15513 |
Wordfence | |
| 4.3 Medium | SocialChamp with | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.3.5 |
CVE-2025-14846 |
Wordfence | |
| 5.3 Medium | Perfit WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed |
≤ 1.0.1 |
CVE-2025-14173 |
Wordfence | |
| 4.4 Medium | Electric Studio Download Counter | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Parameters |
≤ 2.4 |
CVE-2026-0741 |
Wordfence | |
| 5.3 Medium | Aplazo Payment Gateway | Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation No login needed |
≤ 1.4.3 |
CVE-2025-15512 |
Wordfence | |
| 4.4 Medium | Short Link | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Administration Settings Page |
≤ 1.0 |
CVE-2026-0813 |
Wordfence | |
| 4.4 Medium | LinkedIn SC | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Settings Page |
≤ 1.1.9 |
CVE-2026-0812 |
Wordfence | |
| 4.4 Medium | WP Allowed Hosts | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'allowed-hosts' Parameter |
≤ 1.0.8 |
CVE-2026-0734 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.