WordPress Exploited Vulnerabilities
Wordpress vulnerabilities known to be exploited. Over the past 365 days, sorted by exploit discovery date.
Vulnerability Published:
🗓️ Published
- Anytime
Sort By:
🗓️ Published Date
- Descending
Stored Cross-Site Scripting in IndieWeb Plugin for WordPress
CVE-2025-14893WordPressIndieweb👾🟡6.4MEDIUMStored Cross-Site Scripting in Contact List Plugin for WordPress
CVE-2026-3516WordPressContact List – Online ...👾🟡6.4MEDIUMInsecure Direct Object References in Tutor LMS Plugin for WordPress
CVE-2026-1375WordPressTutor Lms – Elearning ...👾🟡8.1HIGHAuthorization Flaw in MyRewards Loyalty Points Plugin for WooCommerce
CVE-2025-15260WordPressMyrewards👾🟡6.5MEDIUMImproper Access Control in ActivityPub Plugin for WordPress
CVE-2026-4338WordPressActivitypub👾🟡7.5HIGHReflected Cross-Site Scripting Vulnerability in Gravity Forms Plugin for WordPress
CVE-2026-4406WordPressGravity Forms👾🟡4.7MEDIUMUnauthenticated Settings Update Vulnerability in Link Whisper Free Plugin by WordPress
CVE-2026-1900WordPressLink Whisper Free👾🟡6.5MEDIUMSQL Injection Vulnerability in SQL Chart Builder Plugin by WordPress
CVE-2026-4079WordPressSql Chart Builder👾🟡6.5MEDIUMCross-Site Request Forgery Vulnerability in Popup Box Plugin for WordPress
CVE-2025-15611WordPressPopup Box👾🟡5.4MEDIUMPrivilege Escalation Vulnerability in Service Finder Booking by Aonetheme
CVE-2025-23970WordPressService Finder Booking👾🟡9.8CRITICALRemote Code Execution in Spam Protect for Contact Form 7 Plugin by WordPress
CVE-2026-1540WordPressSpam Protect For Conta...👾🟡7.2HIGHSecurity Flaw in Export All URLs Plugin for WordPress
CVE-2026-2696WordPressExport All Urls👾🟡5.3MEDIUMAuthentication Bypass in Order Notification for WooCommerce Plugin by WordPress
CVE-2025-15484WordPressOrder Notification For...👾🟡9.1CRITICALSecurity Flaw in Performance Monitor Plugin for WordPress
CVE-2026-3881WordPressPerformance Monitor👾🟡5.8MEDIUMUnauthorized Image File Upload in EventPrime Plugin for WordPress
CVE-2026-1657WordPressEventprime – Events Ca...👾🟡5.3MEDIUMPrivilege Escalation in Restaurant Cafeteria Theme by WordPress
CVE-2025-15445WordPressRestaurant Cafeteria👾🟡5.4MEDIUMSQL Injection Vulnerability in Business Directory Plugin for WordPress
CVE-2026-2576WordPressBusiness Directory Plu...👾🟡7.5HIGHStored Cross-Site Scripting in WP Lightbox 2 Plugin by WordPress
CVE-2026-1430WordPressWP Lightbox 2👾🟡4.8MEDIUMUnauthorized Data Modification in LeadConnector Plugin by LeadConnector
CVE-2026-1890WordPressLeadconnector👾🟡5.3MEDIUMArbitrary Shortcode Execution in Responsive Plus Plugin for WordPress
CVE-2025-15488WordPressResponsive Plus👾🟡6.5MEDIUMPath Traversal Vulnerability in Shared Files Plugin by WordPress
CVE-2025-15433WordPressShared Files👾🟡6.8MEDIUMRemote Code Execution Vulnerability in Kali Forms Plugin for WordPress
CVE-2026-3584WordPressKali Forms — Contact F...👾🟡9.8CRITICALInformation Disclosure Vulnerability in PeproDev Ultimate Invoice Plugin for WordPress
CVE-2026-2343WordPressPeprodev Ultimate Invoice👾🟡5.3MEDIUMFile Upload Vulnerability in trx_addons Plugin by WordPress
CVE-2026-1969WordPressTrx Addons👾🟡5.3MEDIUMStored Cross-Site Scripting Vulnerability in Meta-box GalleryMeta Plugin for WordPress
CVE-2026-1302WordPressMeta-box Gallerymeta👾🟡4.4MEDIUM