CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2026-9656

HubSpot All-In-One Marketing – Forms, Popups, Live Chat [leadin] < 11.3.64

A WordPress plugin called HubSpot All-In-One Marketing – Forms, Popups, Live Chat contains a security flaw that affects all versions up to …

Medium

CVE-2026-14782

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.4

The Amelia plugin for WordPress contains a security flaw in its customer import feature, affecting versions up to and including 2.4.3. This…

Medium

CVE-2026-12434

List category posts [list-category-posts] < 0.96.0

A security flaw exists within the List category posts plugin, affecting all versions prior to 0.95.0. The sanitize_status function allows u…

High

CVE-2026-12753

Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search] < 1.4.5

The Advance Product Search- Voice & Ajax Search plugin for WooCommerce has a security flaw in versions up to 1.4.4, which allows malicious …

High

CVE-2026-15005

Loco Translate [loco-translate] < 2.8.6

The Loco Translate plugin for WordPress has a vulnerability in versions up to 2.8.5 that allows an attacker to execute arbitrary PHP code o…

High

CVE-2026-15008

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 7.4.0

A critical vulnerability exists in all versions of the Uncanny Automator plugin up to and including 7.3.1.4, allowing unauthenticated attac…

High

CVE-2026-12997

Gravity Forms [gravityforms] < 2.10.5

A security flaw exists in Gravity Forms for WordPress, affecting versions up to 2.10.4, where an attacker can access server files via the '…

Medium

CVE-2026-12385

Smart Slider 3 [smart-slider-3] < 3.5.1.38

The Smart Slider 3 plugin for WordPress contains a flaw in versions up to 3.5.1.37 that allows attackers with contributor access or higher …

Medium

CVE-2026-12536

Fusion Builder [fusion-builder] < 3.15.6

The Avada Builder plugin for WordPress contains a security flaw affecting all versions up to 3.15.5, which allows malicious users with at l…

Medium

CVE-2026-12141

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.85

The Premium Addons for Elementor plugin, up to version 4.11.84, is susceptible to a stored cross-site scripting (XSS) vulnerability through…

Medium

CVE-2026-11898

White Label CMS [white-label-cms] < 2.7.13

The White Label CMS plugin for WordPress is susceptible to stored cross-site scripting (XSS) attacks through admin settings across all vers…

Medium

CVE-2026-11591

Widgets for Google Reviews [wp-reviews-plugin-for-google] < 13.3.1

The Widgets for Google Reviews plugin for WordPress contains a vulnerability in its admin settings input handling, allowing attackers with …

Medium

CVE-2026-11426

Under Construction [under-construction-page] < 5.81

The UnderConstructionPage PRO WordPress plugin contains a security flaw that allows attackers with Subscriber-level access or higher to acc…

Medium

CVE-2026-13116

PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.15.0

A vulnerability exists in the PDF Invoices & Packing Slips for WooCommerce plugin due to inadequate validation of user-controlled input. Th…

High

CVE-2026-9282

W3 Total Cache [w3-total-cache] < 2.10.0

A vulnerability exists in W3 Total Cache for WordPress, affecting versions up to 2.9.4, where an attacker can access arbitrary server files…

Medium

CVE-2026-5069

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2

The Fluent Forms plugin on WordPress has a security flaw where the 'subscription_id' parameter lacks proper authorization checks up to vers…

Medium

CVE-2026-57812

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.6

A security flaw exists in the Simply Schedule Appointments Booking Plugin for WordPress, allowing malicious individuals to bypass access co…

Medium

CVE-2026-59523

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.0

A security flaw has been discovered in the Simply Schedule Appointments Booking Plugin for WordPress, affecting versions prior to 1.6.11.12…

Medium

CVE-2026-13039

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16

The Eventin plugin for WordPress contains a flaw that allows unauthorized users to complete unpaid ticket orders, effectively gaining acces…

Medium

CVE-2026-12924

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.16

The Eventin plugin for WordPress contains a security flaw affecting all versions up to 4.1.15, which allows malicious users with contributo…

Medium

CVE-2026-13710

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 3.2.7

The Jeg Kit for Elementor plugin for WordPress has a vulnerability that allows attackers to inject malicious code into web pages. This occu…

High

CVE-2026-8848

Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0

The Popup Maker plugin, up to version 1.22.0, is susceptible to an authorization bypass vulnerability that allows authenticated users with …

Medium

CVE-2026-57693

Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.8.12

The Ad Inserter plugin for WordPress contains a security flaw in versions 2.8.11 and earlier, which allows malicious users with subscriber …

Medium

CVE-2026-12002

Smash Balloon Social Photo Feed – Easy Social Feeds Plugin [instagram-feed] < 6.11.2

The Smash Balloon Social Photo Feed plugin, which enables social media feeds in WordPress sites, has been found vulnerable to CSRF attacks.…

High

CVE-2026-57713

Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.3.7

The Events Manager plugin for WordPress contains a vulnerability that can be exploited through PHP Object Injection, allowing unauthenticat…

Critical

CVE-2026-57714

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4

The LatePoint plugin for WordPress contains a security flaw in versions 5.6.3 and earlier, allowing malicious input to compromise database …

Critical

CVE-2026-57702

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4.3

The Amelia plugin for WordPress, which manages bookings and events calendars, contains a security flaw in versions up to 2.4.2. A specific …

Medium

CVE-2026-57413

Instant AI Image Generator – Create & Import Images [ai-image] < 2.1.5

The Instant AI Image Generator plugin for WordPress contains a flaw in versions 2.1.4 and earlier that allows authorized users with Subscri…

High

CVE-2026-57815

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.55.1

The Forminator Forms plugin for WordPress contains a security flaw that allows unauthorized access to server files in all versions prior to…

High

CVE-2026-57814

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.55.0.2

The Forminator Forms plugin for WordPress contains a security flaw in versions through 1.55.0.1, allowing malicious code injection via unsa…

Medium

CVE-2026-6459

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.3

The Essential Addons for Elementor is susceptible to Stored Cross-Site Scripting when using the Event Calendar widget through versions up t…

Medium

CVE-2025-14785

Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.20.3

The SeedProd Website Builder plugin for WordPress contains a security flaw affecting versions up to 6.20.2. The issue arises from inadequat…

High

CVE-2026-57382

Simple File List [simple-file-list] < 6.3.9

The Simple File List plugin for WordPress contains a security flaw in versions 6.3.8 and earlier, allowing malicious actors to inject unaut…

High

CVE-2026-5356

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.1

The LatePoint – Calendar Booking Plugin contains a flaw in its Stripe Connect integration, where it fails to properly verify user input. Sp…

High

CVE-2026-6854

My Calendar – Accessible Event Manager [my-calendar] < 3.7.9

The My Calendar plugin for WordPress contains a security flaw in versions 3.7.8 and earlier, allowing malicious input to inject unauthorize…

Critical

CVE-2026-57726

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13

The Kirki plugin, versions 6.0.12 and earlier, is susceptible to SQL Injection because it inadequately escapes user-supplied parameters in …

High

CVE-2026-57725

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

The Kirki plugin, used for WordPress website building and customization, has a stored cross-site scripting vulnerability up to version 6.0.…

Critical

CVE-2026-57724

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.13

The Kirki plugin for WordPress contains a vulnerability that allows unauthenticated attackers to inject malicious PHP objects through deser…

CVE

CVE-2026-11766

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0

Authenticated users with a minimum role of Subscriber can inject malicious JavaScript into custom textarea profile fields in Ultimate Membe…

CVE

CVE-2026-11855

Simple Membership [simple-membership] < 4.7.5

The Simple Membership plugin for WordPress prior to version 4.7.5 fails to authenticate Stripe webhook notifications when no signing key is…

Medium

CVE-2026-59520

CrawlWP SEO – Instant Search Engine Indexing & SEO Performance Monitor [mihdan-index-now] < 3.0.17

The CrawlWP SEO plugin, used in WordPress installations up to version 3.0.16, contains a security flaw that allows malicious actors to exec…

CVE

CVE-2026-11578

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.5

Fluent Forms WordPress plugin versions prior to 6.2.5 fail to adequately restrict the deletion of form submission entries for managers with…

Medium

CVE-2026-57764

Surbma | Yoast SEO Breadcrumb Shortcode [surbma-yoast-breadcrumb-shortcode] <= 1.2 (unfixed)

The Surbma | Yoast SEO Breadcrumb Shortcode plugin for WordPress versions 1.2 and earlier is susceptible to stored cross-site scripting (XS…

Medium

CVE-2026-57680

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

A security flaw exists in Kirki plugin versions up to 6.0.11, allowing unauthorized access to sensitive data by exploiting direct object re…

High

CVE-2026-9148

Comments – wpDiscuz [wpdiscuz] < 7.6.57

The wpDiscuz plugin for WordPress versions 7.6.56 and earlier is susceptible to Stored Cross-Site Scripting due to inadequate output escapi…

Medium

CVE-2026-11900

Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.8.17

Authenticated WordPress users with at least contributor privileges can exploit an insecure direct object reference vulnerability in Ad Inse…

Medium

CVE-2026-11398

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.2

The LatePoint – Calendar Booking Plugin for Appointments and Events on WordPress has a security flaw that allows unauthorized access to sen…

Medium

CVE-2026-8489

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0

The Ultimate Member plugin for WordPress contains a security flaw affecting versions 2.11.4 and earlier, which allows malicious users with …

Medium

CVE-2026-12122

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

The Kirki plugin for WordPress, versions 6.0.11 and earlier, contains a vulnerability that allows unauthorized access to sensitive informat…

Medium

CVE-2026-12472

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

An authorization flaw in Kirki plugin versions up to 6.0.11 allows unauthorized users to send malicious emails from a WordPress site's mail…

Medium

CVE-2026-12657

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.3

The LatePoint plugin for WordPress contains a flaw that allows attackers to manipulate bookings by exploiting an insecure reference to spec…

CVE

CVE-2026-10750

Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.26

The Royal MCP WordPress plugin's security has been compromised in versions prior to 1.4.26 due to inadequate access control checks followin…

High

CVE-2026-57349

WPeMatico RSS Feed Fetcher [wpematico] < 2.8.18

The WPeMatico RSS Feed Fetcher plugin for WordPress contains a security flaw that allows malicious code injection through unsanitized input…

Medium

CVE-2026-13252

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.2.2

The Feedzy plugin for WordPress contains a security flaw allowing malicious users with contributor or higher permissions to embed unauthori…

High

CVE-2026-57360

eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.5

The eCommerce Product Catalog Plugin for WordPress contains a security flaw in versions up to 3.5.4, allowing malicious code to be embedded…

Medium

CVE-2026-11896

My Calendar – Accessible Event Manager [my-calendar] < 3.7.15

The My Calendar plugin for WordPress contains a flaw in its handling of user-submitted data that can be exploited by attackers to access un…

High

CVE-2026-5821

Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.5

A WordPress plugin called Image Optimizer contains a vulnerability that allows an authenticated attacker with Author-level access or higher…

Medium

CVE-2026-13459

JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.3.1

A vulnerability exists in the JetFormBuilder plugin for WordPress, affecting versions up to 3.6.3. The issue arises from inadequate authori…

High

CVE-2026-57350

WP Debugging [wp-debugging] < 2.12.3

The WP Debugging plugin for WordPress contains a security flaw in versions up to 2.12.2, allowing malicious scripts to be embedded within t…

Medium

CVE-2026-12127

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.2.1

The WPForms plugin for WordPress contains a flaw in its handling of reply-to addresses, where it fails to properly sanitize input from text…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.