CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

High

CVE-2025-14800

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.8

The Redirection for Contact Form 7 plugin for WordPress contains a security flaw in its handling of file uploads, specifically in the move_…

Medium

CVE-2025-13220

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1

The Ultimate Member plugin for WordPress contains a security flaw affecting all versions up to 2.11.0, allowing malicious users with at lea…

Medium

CVE-2025-14298

FiboSearch – Ajax Search for WooCommerce [ajax-search-for-woocommerce] < 1.32.1

A WordPress plugin called FiboSearch is vulnerable to a type of attack called Stored Cross-Site Scripting. This occurs when the plugin does…

Medium

CVE-2025-12492

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1

A security flaw exists in WordPress plugins up to version 2.11.0, specifically within the Ultimate Member plugin's handling of member direc…

Medium

CVE-2025-13754

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.17

The Appointment Booking Calendar plugin has a security flaw in all versions up to 1.6.9.16 that allows unauthorized access to confidential …

High

CVE-2025-13641

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.0.0

The NextGEN Gallery plugin for WordPress contains a flaw that enables attackers with Contributor-level access or higher to inject and run m…

Medium

CVE-2025-14719

Relevanssi – A Better Search [relevanssi] < 4.26.0

The Relevanssi Premium plugin for WordPress is susceptible to SQL Injection in versions up to 4.26.0 (Free) and 2.29.0 (Premium). This vuln…

Medium

CVE-2025-13498

Download Manager [download-manager] < 3.3.33

The WordPress Download Manager plugin contains a security flaw that allows authorized users with minimal permissions to gain access to sens…

Medium

CVE-2025-12976

Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.3

The Events Manager plugin for WordPress contains a security flaw affecting all versions up to 7.2.2.1, where user-submitted data is not pro…

Medium

CVE-2025-13110

HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.4

A security flaw exists in all versions of the HUSKY – Products Filter Professional for WooCommerce plugin up to 1.3.7.3, which can be explo…

Medium

CVE-2025-13977

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.4

The Essential Addons for Elementor plugin, up to version 6.5.3, is susceptible to stored cross-site scripting (XSS) attacks through the Eve…

Medium

CVE-2025-11369

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.7.3

The Gutenberg Essential Blocks plugin has a security flaw that allows authorized users with elevated permissions to potentially access sens…

Medium

CVE-2025-13217

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1

The Ultimate Member plugin for WordPress contains a security flaw in its handling of YouTube video URLs. Specifically, versions up to 2.11.…

Medium

CVE-2025-14081

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.1

A vulnerability exists in the Ultimate Member plugin for WordPress, affecting versions up to 2.11.0. Specifically, an authenticated attacke…

Medium

CVE-2025-13750

Converter for Media – Optimize images | Convert WebP & AVIF [webp-converter-for-media] < 6.4.0

A security flaw exists in the Converter for Media plugin, affecting WordPress installations that utilize version 6.3.2 or earlier. The vuln…

Medium

CVE-2025-14154

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.10.3

The Better Messages plugin for WordPress contains a security flaw where guest display names are not properly sanitized, allowing malicious …

Medium

CVE-2025-11220

Elementor Website Builder – more than just a page builder [elementor] < 3.33.4

The Elementor plugin on WordPress is susceptible to stored cross-site scripting (XSS) attacks through its Text Path widget in versions up t…

High

CVE-2025-67999

Newsletter – Send awesome emails from WordPress [newsletter] < 9.1.0

The Newsletter plugin for WordPress versions 9.0.9 and earlier is susceptible to SQL Injection attacks because user-supplied parameters are…

Medium

CVE-2025-12900

FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.2

A security flaw exists in versions 1 through 6.5.1 of the FileBird plugin, allowing authorized users with at least author-level access to m…

Medium

CVE-2025-67986

Document Library Lite [document-library-lite] < 1.2.0

The Document Library Lite plugin for WordPress contains a security flaw in versions 1.1.7 and earlier, allowing malicious users with admin-…

Medium

CVE-2025-67985

Document Library Lite [document-library-lite] < 1.2.0

A security flaw exists in the Document Library Lite plugin, which enables attackers to sidestep access control measures by manipulating a u…

High

CVE-2025-14383

Booking Calendar [booking] < 10.14.9

The Booking Calendar plugin for WordPress contains a security flaw in its handling of user-submitted dates, which allows malicious input to…

Medium

CVE-2025-11991

JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.4

The JetFormBuilder plugin for WordPress has a security flaw that allows unauthorized users to manipulate data because the run_callback func…

Medium

CVE-2025-66129

Pochipp [pochipp] < 1.18.1

A security flaw exists within the Pochipp plugin for WordPress, affecting versions prior to or equal to 1.18.0. The issue arises from a lac…

Medium

CVE-2025-12537

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.14.4

The Addon Elements for Elementor plugin has a security flaw affecting all versions up to 1.14.3, which allows malicious users with contribu…

Medium

CVE-2025-14056

Custom Post Type UI [custom-post-type-ui] < 1.18.2

The Custom Post Type UI plugin for WordPress contains a security flaw in all versions up to 1.18.1, allowing an attacker with Administrator…

Medium

CVE-2025-14477

404 Solution [404-solution] < 3.1.1

The 404 Solution WordPress plugin contains a vulnerability in its handling of user-supplied input, specifically the `filterText` parameter …

Medium

CVE-2025-13820

Comments – wpDiscuz [wpdiscuz] < 7.6.40

The Comments – wpDiscuz plugin for WordPress, up to version 7.6.39, is susceptible to an authentication bypass vulnerability because it fai…

Medium

CVE-2025-12407

Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3

The Events Manager plugin, which offers calendar and booking features among others for WordPress sites, contains a security flaw that allow…

Medium

CVE-2025-12408

Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 7.2.2.3

The Events Manager plugin for WordPress contains a flaw in versions up through 7.2.2.2. Specifically, the 'get_location' action lacks suffi…

Medium

CVE-2025-13993

MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.17

The MailerLite Signup forms plugin for WordPress contains a security flaw in versions 1.7.16 and earlier, which allows malicious users with…

Medium

CVE-2025-12965

Magical Posts Display – Elementor Advanced Posts widgets [magical-posts-display] < 1.2.55

A vulnerability exists in the Magical Posts Display plugin for WordPress, specifically in the Magical Posts Accordion widget, where user-su…

Medium

CVE-2025-13320

WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13

The WP User Manager plugin for WordPress contains a vulnerability that allows an authenticated attacker, with at least Subscriber-level acc…

Medium

CVE-2025-10163

List category posts [list-category-posts] < 0.92.0

A WordPress plugin called List category posts is susceptible to a specific type of attack due to inadequate handling of user input in its s…

Medium

CVE-2025-11467

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.2

The Feedzy plugin for WordPress contains a flaw in its feed processing mechanism, allowing unauthorized users to initiate server-side reque…

Medium

CVE-2025-67563

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.2

A missing authorization flaw exists in the Saad Iqbal Post SMTP plugin, version 3.6.1 and earlier, allowing incorrect access control. This …

High

CVE-2025-67962

Broken Link Checker by AIOSEO – Find & Fix Broken Internal, External & Video Links [broken-link-checker-seo] < 1.2.7

The Broken Link Checker plugin for WordPress contains a security flaw in versions up to 1.2.6, allowing malicious users with elevated privi…

Medium

CVE-2025-67537

ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.11.9

The ThirstyAffiliates plugin for WordPress contains a security flaw in versions 3.11.8 and earlier, allowing malicious users with contribut…

Medium

CVE-2025-67592

My Calendar – Accessible Event Manager [my-calendar] < 3.6.17

The My Calendar – Accessible Event Manager plugin for WordPress contains a security flaw that allows certain users to bypass intended restr…

Medium

CVE-2025-67589

PDF Invoices & Packing Slips for WooCommerce [woocommerce-pdf-invoices-packing-slips] < 5.0.0

A security flaw exists within the PDF Invoices & Packing Slips plugin for WordPress, where insufficient permission checks allow users with …

High

CVE-2025-67950

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.1.1

The All In One SEO Pack plugin for WordPress contains a security flaw in versions up to 4.9.1, allowing malicious users with contributor-le…

Medium

CVE-2025-63044

Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.20

The Xpro Elementor Addons plugin for WordPress contains a security flaw that allows malicious users with contributor-level permissions or h…

High

CVE-2025-13065

Starter Templates – AI-Powered Templates for Elementor & Gutenberg [astra-sites] < 4.4.42

The Starter Templates plugin for WordPress is susceptible to arbitrary file uploads in all versions from 1.0 through 4.4.41 due to inadequa…

Medium

CVE-2025-13748

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8

The Fluent Forms plugin, up to version 6.1.7, is susceptible to Insecure Direct Object Reference vulnerabilities through the 'submission_id…

High

CVE-2025-12510

Widgets for Google Reviews [wp-reviews-plugin-for-google] < 13.2.5

The Widgets for Google Reviews plugin for WordPress contains a security flaw that allows attackers to inject malicious code into the admin …

Medium

CVE-2025-13922

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0

The Tag, Category, and Taxonomy Manager plugin's interaction with OpenAI has a critical flaw in its handling of user-supplied input for the…

Medium

CVE-2025-68494

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.54

The Premium Addons for Elementor plugin, which includes templates and widgets for WordPress, has a vulnerability that allows unauthenticate…

Medium

CVE-2025-63077

Happy Addons for Elementor [happy-elementor-addons] < 3.20.4

The Happy Addons for Elementor plugin, up to version 3.20.3, is susceptible to unauthorized access because it lacks proper capability check…

Medium

CVE-2025-12804

Booking Calendar [booking] < 10.14.7

The Booking Calendar plugin for WordPress contains a security flaw that allows malicious code injection through the 'bookingcalendar' short…

Medium

CVE-2025-12887

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.2

The Post SMTP plugin for WordPress has an authorization bypass vulnerability in versions up to 3.6.1, caused by insufficient verification o…

Medium

CVE-2025-12826

Custom Post Type UI [custom-post-type-ui] < 1.18.1

The Custom Post Type UI plugin for WordPress is susceptible to an authorization bypass vulnerability affecting all versions up to 1.18.0. T…

Medium

CVE-2025-13401

Autoptimize [autoptimize] < 3.1.14

The Autoptimize plugin for WordPress has a security flaw affecting all versions up to 3.1.13, which allows malicious users with contributor…

Medium

CVE-2025-11379

WebP Express [webp-express] < 0.25.11

The WebP Express WordPress plugin contains a security flaw that allows unauthorized individuals to obtain sensitive information from its co…

Medium

CVE-2025-13109

HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.3

The HUSKY – Products Filter Professional plugin for WooCommerce has a security flaw in all versions up to 1.3.7.2 that allows an attacker w…

Medium

CVE-2025-13359

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0

The Tag, Category, and Taxonomy Manager plugin for WordPress contains a vulnerability in its "getTermsForAjax" function, allowing authentic…

Medium

CVE-2025-13354

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.41.0

A WordPress plugin for managing taxonomy terms and categories, which integrates with OpenAI's AI capabilities, has a security flaw that all…

Medium

CVE-2025-13407

Gravity Forms [gravityforms] < 2.9.23.1

The Gravity Forms plugin for WordPress suffers from a critical flaw that enables unauthorized uploads of any file type, without proper scru…

Critical

CVE-2025-13486

Advanced Custom Fields: Extended [acf-extended] < 0.9.2

The Advanced Custom Fields: Extended plugin for WordPress contains a vulnerability that allows attackers to execute arbitrary code on the s…

Medium

CVE-2025-66121

Security Optimizer – The All-In-One Protection Plugin [sg-security] < 1.5.9

A security flaw exists in the SiteGround Security plugin for WordPress, where a critical oversight has been identified in the authorization…

Medium

CVE-2025-66120

CatFolders – WordPress Media Library Folders & Categories [catfolders] < 2.5.4

A security flaw exists within the CatFolders plugin for WordPress, where insufficient permission checks allow malicious individuals to bypa…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.