See how wordpress compares to other vendors in security performance
The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phonenumber' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shapesvalues Parameter in all versions up to, and including, 4.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The fc-call-nonce nonce required by the endpoint is exposed to all frontend visitors who view a map page via window.wpgmplocal.nonce, enabling any authenticated subscriber to read the nonce and craft a valid request; additionally, the secondary wpnonce check in the drawing handler can be bypassed by simply omitting the wpnonce parameter from the request.
The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity assertion it issues to the authorization grant being exchanged, returning instead the assertion belonging to whichever user authenticated most recently, which allows users with the Subscriber role and above to obtain a validly signed identity assertion for another user, including an administrator, and authenticate as them at any application that uses the site for single sign-on.
Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.
Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
Contributor Insecure Direct Object References (IDOR) in SiteSkite <= 2.1.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.4 versions.
Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions.
Unauthenticated Cross Site Scripting (XSS) in WPS Limit Login <= 1.5.9.3 versions.
Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.
Administrator SQL Injection in Email Log <= 2.63 versions.
Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.
Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.
Editor SQL Injection in Ultimeter <= 3.0.8 versions.
Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post-cloning action, allowing Contributor-level users and above to duplicate arbitrary posts of any type or status, including other users' private or draft content, and gain read access to the resulting copy.
Missing Authorization vulnerability in extendthemes Vireo vireo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vireo: from n/a through <= 1.0.24.
WordPress 3dady Real-Time Web Stats plugin 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by exploiting unsanitized input fields. Attackers can insert JavaScript payloads in the dadyinputtext or dady2inputtext fields via the plugin options panel to execute arbitrary code when the page is viewed.
An unauthenticated attacker can make getpagetemplate() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.
The Text Styler WordPress plugin through 1.1.1 does not sanitise and escape user-supplied styling values before outputting them within a front-end style block, and does not verify that a user may edit the target post, allowing users with contributor-level access or above to store JavaScript that executes in the browser of anyone viewing the affected post, including administrators.
The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitrary API keys (Pixabay, Unsplash, Pixels) configured by site administrators via the 'pixabayapi', 'unsplashapi', or 'pixelsapi' parameters.
The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the editmetavalue due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to delete arbitrary media attachments site-wide by supplying any numeric attachment ID in the file-field parameter alongside the corresponding delete flag, causing content loss and broken pages. Exploitation requires that the attacker's post is governed by a Custom Field Template containing at least one file-type field with the mediaRemove option not enabled, which is the default configuration for file fields.