WordPress CVEs

Three-year CVE watchlist for WordPress core, plugins and themes relevant to website and hosting security.

Dedicated CVE watchlist

WordPress CVEs

Three-year CVE watchlist for WordPress core, plugins and themes relevant to website and hosting security.

Server administration
CategorySwitch between product-focused CVE watchlists.
Showsorted by operational relevance for DataHouse infrastructure
CVE-2026-63030CVSS 9.8CISA KEVCMS

CVE-2026-63030: WordPress Core Interpretation Conflict Vulnerability

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve ...

Updated: 2026-07-22
CVE-2026-60137CVSS 5.9CISA KEVCMS

CVE-2026-60137: WordPress Core SQL Injection Vulnerability

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Updated: 2026-07-22
CVE-2026-1357CVSS 9.8TLS

CVE-2026-1357

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined wi...

Updated: 2026-06-17
CVE-2024-10542CVSS 9.8Web

CVE-2024-10542: anti-spam vulnerability

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and inclu...

Updated: 2026-06-17
CVE-2023-6553CVSS 9.8Web

CVE-2023-6553: backup migration vulnerability

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subse...

Updated: 2026-06-17
CVE-2024-8856CVSS 9.8Web

CVE-2024-8856: backup and staging by wp time capsule vulnerability

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the the UploadHandler.php file and no direct file access prevention in all versions up to, and including, 1.22.21. ...

Updated: 2026-06-17
CVE-2023-6989CVSS 9.8Web

CVE-2023-6989: shield security vulnerability

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthentic...

Updated: 2026-06-17
CVE-2025-11833CVSS 9.8Web

CVE-2025-11833

The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the __construct function in all versions up to, and including, 3.6.0. T...

Updated: 2026-06-17
CVE-2026-4257CVSS 9.8Web

CVE-2026-4257

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` temp...

Updated: 2026-06-17
CVE-2026-3300CVSS 9.8Web

CVE-2026-3300

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field v...

Updated: 2026-06-17
CVE-2026-3844CVSS 9.8Web

CVE-2026-3844

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers ...

Updated: 2026-06-17
CVE-2024-8669CVSS 9.1Web

CVE-2024-8669: backuply vulnerability

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function in all versions up to, and including, 1.3.4 due to insufficient escaping on the ...

Updated: 2026-06-17
CVE-2019-25224CVSS 9.8CMS

CVE-2019-25224: wp database backup vulnerability

The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.

Updated: 2026-06-17
CVE-2024-12209CVSS 9.8Web

CVE-2024-12209

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthentic...

Updated: 2026-06-17
CVE-2026-8181CVSS 9.8Web

CVE-2026-8181

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass in versions 3.4.0 to 3.4.1.1. This is due to incorrect return-value handling in the `is_mainwp_authenticat...

Updated: 2026-06-17
CVE-2026-1056CVSS 9.8Web

CVE-2026-1056

The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated att...

Updated: 2026-06-17
CVE-2024-9047CVSS 9.8Web

CVE-2024-9047: wordpress file upload vulnerability

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally ...

Updated: 2026-06-17
CVE-2023-6875CVSS 9.8Web

CVE-2023-6875: post smtp vulnerability

The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a type juggling issue on the connect-app REST endpoint in all...

Updated: 2026-06-17
CVE-2024-1071CVSS 9.8Web

CVE-2024-1071: ultimate member vulnerability

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in versions 2.1.3 to 2.8.2 due to insufficient escaping on the...

Updated: 2026-06-17
CVE-2023-4634CVSS 9.8Web

CVE-2023-4634: media library assistant vulnerability

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter fro...

Updated: 2026-06-17
CVE-2024-10924CVSS 9.8Web

CVE-2024-10924: really simple security vulnerability

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_...

Updated: 2026-06-17
CVE-2023-5360CVSS 9.8Web

CVE-2023-5360: royal elementor addons vulnerability

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

Updated: 2026-06-17
CVE-2024-2876CVSS 9.8Web

CVE-2024-2876

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and incl...

Updated: 2026-06-17
CVE-2024-1512CVSS 9.8Web

CVE-2024-1512: masterstudy lms vulnerability

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter of the /lms/stm-lms/order/items REST route in all versions up to, and including, 3.2.5 due to in...

Updated: 2026-06-17
CVE-2024-1698CVSS 9.8Web

CVE-2024-1698: notificationx vulnerability

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escapi...

Updated: 2026-06-17
CVE-2025-2294CVSS 9.8Web

CVE-2025-2294

The Kubio AI Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.1 via thekubio_hybrid_theme_load_template function. This makes it possible for unauthenticated attackers to include and execute ar...

Updated: 2026-06-17
CVE-2025-11749CVSS 9.8Web

CVE-2025-11749

The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for...

Updated: 2026-06-17
CVE-2024-5932CVSS 10.0Web

CVE-2024-5932: givewp vulnerability

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for ...

Updated: 2026-06-17
CVE-2024-3552CVSS 9.8Web

CVE-2024-3552: web directory free vulnerability

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Bas...

Updated: 2026-06-17
CVE-2022-1609CVSS 9.8Web

CVE-2022-1609: school management vulnerability

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.

Updated: 2026-06-17
CVE-2024-8522CVSS 10.0Web

CVE-2024-8522: learnpress vulnerability

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in all versions up to, and including, 4.2.7 due to insufficient escaping on t...

Updated: 2026-06-17
CVE-2026-0740CVSS 9.8CMS

CVE-2026-0740

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possi...

Updated: 2026-06-17
CVE-2024-5084CVSS 9.8Web

CVE-2024-5084: hash form vulnerability

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenti...

Updated: 2026-06-17
CVE-2023-7002CVSS 7.2Linux

CVE-2023-7002: backup migration vulnerability

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 1.3.9 via the 'url' parameter. This vulnerability allows authenticated attackers, with administrator-level permissions and above, to execu...

Updated: 2026-06-17
CVE-2024-8672CVSS 9.9Web

CVE-2024-8672

The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due t...

Updated: 2026-06-17
CVE-2025-7441CVSS 9.8Web

CVE-2025-7441

The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42. This vulnerability occurs through the /wp-json/storychief/webhook REST-API endpoint that does not have sufficient filetype validation. ...

Updated: 2026-06-17
CVE-2024-7094CVSS 9.8Web

CVE-2024-7094

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitiza...

Updated: 2026-06-17
CVE-2024-4434CVSS 9.8Web

CVE-2024-4434: learnpress vulnerability

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, 4.2.6.5 due to insufficient escaping on the user supplied parameter and lack of sufficient pre...

Updated: 2026-06-17
CVE-2024-9932CVSS 9.8Web

CVE-2024-9932

The Wux Blog Editor plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'wuxbt_insertImageNew' function in versions up to, and including, 3.0.0. This makes it possible for unauthenticated attackers to...

Updated: 2026-06-17
CVE-2024-6220CVSS 9.8Web

CVE-2024-6220: keydatas vulnerability

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers t...

Updated: 2026-06-17
CVE-2024-10470CVSS 9.8Web

CVE-2024-10470: wordpress learning management system vulnerability

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up t...

Updated: 2026-06-17
CVE-2024-10124CVSS 9.8Web

CVE-2024-10124

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a missing capability check on the tp_install() function in all versions up to, and includin...

Updated: 2026-06-17
CVE-2024-8353CVSS 9.8Web

CVE-2024-8353: givewp vulnerability

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 via deserialization of untrusted input via several parameters like 'give_title' and 'card_address'....

Updated: 2026-06-17
CVE-2025-1128CVSS 9.8Web

CVE-2025-1128: everest forms vulnerability

The Everest Forms – Contact Forms, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary file upload, read, and deletion due to missing file type and path validation in the 'format' method of the EVF_F...

Updated: 2026-06-17
CVE-2026-1492CVSS 9.8CMS

CVE-2026-1492

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. ...

Updated: 2026-06-17
CVE-2025-6934CVSS 9.8Web

CVE-2025-6934

The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of ro...

Updated: 2026-06-17
CVE-2025-9501CVSS 9.0Web

CVE-2025-9501

The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

Updated: 2026-06-17
CVE-2026-8732CVSS 9.8CMS

CVE-2026-8732

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protec...

Updated: 2026-07-21
CVE-2025-8723CVSS 9.8Web

CVE-2025-8723

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitization within its hook_rest_pre_dispatch() method in all versions up to, and including, 1.5.6. This makes it possi...

Updated: 2026-06-17
CVE-2024-3495CVSS 9.8Web

CVE-2024-3495

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Updated: 2026-06-17
CVE-2023-4596CVSS 9.8Web

CVE-2023-4596: forminator vulnerability

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possib...

Updated: 2026-06-17
CVE-2020-36847CVSS 9.8Web

CVE-2020-36847: simple file list vulnerability

The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function which can be used to rename uploaded PHP code with a png extension to use a php extension. This allows unauthent...

Updated: 2026-06-17
CVE-2024-6028CVSS 9.8Web

CVE-2024-6028: quiz maker vulnerability

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on t...

Updated: 2026-06-17
CVE-2024-9234CVSS 9.8Web

CVE-2024-9234

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-activ...

Updated: 2026-06-17
CVE-2024-4443CVSS 9.8Web

CVE-2024-4443: business directory vulnerability

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supp...

Updated: 2026-06-17
CVE-2024-4295CVSS 9.8Web

CVE-2024-4295: email subscribers \& newsletters vulnerability

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

Updated: 2026-06-17
CVE-2016-15043CVSS 9.8Web

CVE-2016-15043: wp mobile detector vulnerability

The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in resize.php file in versions up to, and including, 3.5. This makes it possible for unauthenticated attackers to upload arbitrary files ...

Updated: 2026-06-17
CVE-2025-34077CVSS 10.0Web

CVE-2025-34077

An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting social_site=true and man...

Updated: 2026-06-17

Security newsletter

Get new CVE alerts before they become an incident

We send selected infrastructure threats in English, with practical notes for DataHouse environments.

  • DataHouse: server administration and secure cloud
  • Hostilla.pl: hosting and mail services
  • SecDNS.pl: free DNS security layer