See how wordpress compares to other vendors in security performance
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
Editor SQL Injection in Ultimeter <= 3.0.8 versions.
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
Administrator SQL Injection in Email Log <= 2.63 versions.
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.
An unauthenticated attacker can make getpagetemplate() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitrary API keys (Pixabay, Unsplash, Pixels) configured by site administrators via the 'pixabayapi', 'unsplashapi', or 'pixelsapi' parameters.
The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the editmetavalue due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary media attachments site-wide by supplying any numeric attachment ID in the file-field parameter alongside the corresponding delete flag, causing content loss and broken pages. Exploitation requires that the attacker's post is governed by a Custom Field Template containing at least one file-type field with the mediaRemove option not enabled, which is the default configuration for file fields.
The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.
The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary published posts and taxonomy terms on the site.
The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to upload arbitrary files, including PHP ones, and run code on the server.
The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promoteusers capability when assigning roles during a CSV import, allowing users with only the createusers capability to create new administrator accounts or promote existing users to administrator.
The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.
The Kirki WordPress plugin before 6.3.1 does not sanitize uploaded SVG files while making them uploadable site-wide, allowing users with author-level access and above to upload a file containing JavaScript which is then served from the site's own origin and runs in the session of anyone who opens it.