Where
-Infinity
0

Vendor Risk Score

See how wordpress compares to other vendors in security performance

View Risk Score →

Software

Severity
7.5
EPSS
0.33%
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

First published (updated )
Severity
5.3
EPSS
0.24%
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

First published (updated )
Severity
7.6
EPSS
0.29%
SQL Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Editor SQL Injection in Ultimeter <= 3.0.8 versions.

First published (updated )
Severity
6.5
EPSS
0.16%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

First published (updated )
Severity
7.1
EPSS
0.18%
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

First published (updated )
Severity
6.5
EPSS
0.34%
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

First published (updated )
Severity
5.3
EPSS
0.25%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

First published (updated )
Severity
7.6
EPSS
0.29%
SQL Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.

First published (updated )
Severity
6.5
EPSS
0.17%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.

First published (updated )
Severity
7.6
EPSS
0.29%
SQL Injection
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Administrator SQL Injection in Email Log <= 2.63 versions.

First published (updated )
Severity
6.5
EPSS
0.17%
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L

Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.

First published (updated )
Severity
5.3
EPSS
0.22%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.

First published (updated )
Severity
7.1
EPSS
0.19%
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.

First published (updated )
Severity
8.5
SQL Injection
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.

First published (updated )
Severity
7.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.

First published (updated )
Severity
3.3
EPSS
0.18%
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.

First published (updated )
Severity
9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.

First published (updated )
Severity
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated attacker can make getpagetemplate() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitrary API keys (Pixabay, Unsplash, Pixels) configured by site administrators via the 'pixabayapi', 'unsplashapi', or 'pixelsapi' parameters.

First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the editmetavalue due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary media attachments site-wide by supplying any numeric attachment ID in the file-field parameter alongside the corresponding delete flag, causing content loss and broken pages. Exploitation requires that the attacker's post is governed by a Custom Field Template containing at least one file-type field with the mediaRemove option not enabled, which is the default configuration for file fields.

First published (updated )
Severity
6.8
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.

First published (updated )
Severity
3.7
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.

First published (updated )
Severity
9.8
Malicious File Upload
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.

First published (updated )
Severity
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promoteusers capability when assigning roles during a CSV import, allowing users with only the createusers capability to create new administrator accounts or promote existing users to administrator.

First published (updated )
Severity
4.3
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.

First published (updated )
Severity
6.8
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the site's own origin and runs in the session of anyone who opens it.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203