CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2026-12902

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8

The Kadence Blocks plugin for WordPress contains a security flaw that allows unauthorized users to upload files to a website's server. Spec…

Medium

CVE-2026-12904

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8

A WordPress plugin called Kadence Blocks is vulnerable to a security issue known as Insecure Direct Object Reference. Specifically, when an…

Medium

CVE-2026-13733

Download Manager [download-manager] < 3.3.61

The Download Manager plugin for WordPress has a security flaw in versions up to 3.3.60 that allows attackers with contributor-level access …

Medium

CVE-2026-14343

Download Manager [download-manager] < 3.3.62

The Download Manager plugin for WordPress contains a vulnerability that allows an authenticated attacker with contributor-level access or h…

High

CVE-2026-57672

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 6.5.1.2

The wpDataTables Premium plugin for WordPress contains a security flaw in versions up to 6.5.1.1, allowing malicious code to be embedded in…

High

CVE-2026-57678

Slider Revolution [revslider] < 7.1.0

The Slider Revolution plugin for WordPress contains a security flaw that allows malicious code injection through unsanitized inputs, leadin…

High

CVE-2026-13228

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4

The LatePoint plugin for WordPress contains a vulnerability that allows an authenticated user with Agent-level access or higher to elevate …

Critical

CVE-2026-57623

W3 Total Cache [w3-total-cache] < 2.10.0

A critical vulnerability has been discovered in the W3 Total Cache plugin for WordPress, affecting all versions from 1.0 through 2.9.4. The…

Medium

CVE-2025-66076

Woostify Sites Library [woostify-sites-library] <= 1.6.2 (unfixed)

A security flaw has been discovered in the Woostify Sites Library plugin for WordPress, affecting versions prior to or equal to 1.6.2. The …

Medium

CVE-2026-57627

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12

The Kirki plugin, used for page building and customization in WordPress, is susceptible to Server-Side Request Forgery across all versions …

Medium

CVE-2026-13295

Page Builder by SiteOrigin [siteorigin-panels] < 2.34.4

The SiteOrigin Page Builder plugin for WordPress contains a security flaw in versions up to 2.34.3, allowing attackers with Contributor-lev…

Medium

CVE-2026-11356

Ivory Search – WordPress Search Plugin [add-search-to-menu] < 5.5.16

The Ivory Search plugin for WordPress contains a security flaw that allows malicious code injection through two specific settings: 'menu_ti…

Medium

CVE-2025-63041

Forget About Shortcode Buttons [forget-about-shortcode-buttons] <= 2.1.3 (unfixed)

A security flaw exists in the Forget About Shortcode Buttons plugin for WordPress, affecting versions up to 2.1.3. The issue stems from a l…

High

CVE-2026-57628

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.1.0

The WP All Import plugin for WordPress contains a security flaw in versions up to 4.0.1, allowing malicious users with elevated privileges …

High

CVE-2026-57317

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.4

The Simply Schedule Appointments Booking Plugin for WordPress contains a security flaw in versions up to 1.6.12.2, allowing malicious actor…

Medium

CVE-2026-13245

MaxButtons – Create buttons [maxbuttons] < 9.8.6

The MaxButtons plugin for WordPress contains a flaw in its handling of the 'view' parameter, allowing malicious actors to introduce unautho…

High

CVE-2026-57314

SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.3

The SureCart plugin for WordPress contains a security flaw that allows malicious code injection through links, which can be exploited by at…

High

CVE-2026-7655

SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.0

In versions of the SureCart plugin up to 4.2.3 for WordPress, an attacker can exploit a vulnerability allowing them to seize control of ano…

Medium

CVE-2026-57316

GetGenie – AI SEO Assistant & Content Writer with Keyword Research, AEO & GEO [getgenie] < 4.4.3

The GetGenie plugin for WordPress contains a security flaw that allows authorized users with elevated privileges to obtain confidential inf…

High

CVE-2026-57631

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.2

The Popup Box plugin for WordPress contains a vulnerability in versions up to 6.0.1 that allows malicious users with admin privileges or hi…

High

CVE-2026-57321

Interactive Content – H5P [h5p] < 1.17.8

The H5P plugin for WordPress contains a security flaw that allows authorized users with contributor privileges or higher to erase any file …

High

CVE-2026-57655

Child Theme Wizard [child-theme-wizard] < 1.5

The Child Theme Wizard plugin for WordPress contains a flaw in its security checks, allowing malicious actors to deceive administrators int…

Medium

CVE-2026-57619

Elementor Website Builder – more than just a page builder [elementor] < 4.1.4

Elementor Website Builder, a comprehensive page builder for WordPress, has a vulnerability that allows authenticated users with at least Co…

CVE

CVE-2026-12525

Redux Framework [redux-framework] < 4.5.13

The Redux Framework WordPress plugin versions prior to 4.5.13 lacks restrictions on user meta keys when saving custom profile fields. This …

Critical

CVE-2026-56070

Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search] < 1.4.5

The Advance Product Search- Voice & Ajax Search plugin for WooCommerce has a security flaw in its interaction with SQL queries, allowing un…

High

CVE-2026-56051

TablePress – Tables in WordPress made easy [tablepress] < 3.3.2

The TablePress plugin for WordPress contains a flaw allowing malicious scripts to be injected into pages through unvalidated input, which c…

High

CVE-2026-56060

Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 7.1.2

All versions of the Print Invoice & Delivery Notes for WooCommerce plugin prior to version 7.2.0 contain a vulnerability that allows unauth…

Medium

CVE-2026-57313

SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.2.3

The SureCart plugin for WordPress contains a security flaw affecting versions up to 4.2.2, allowing malicious users with subscriber-level a…

Medium

CVE-2026-56048

Payment Gateway Based Fees and Discounts for WooCommerce [checkout-fees-for-woocommerce] < 3.1.0

Authorization Bypass Through User-Controlled Key

Medium

CVE-2026-57622

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.15

The WPCafe plugin for WordPress contains a security flaw that allows users with elevated permissions to bypass intended restrictions on cer…

Medium

CVE-2026-11818

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.15

The WPCafe plugin for WordPress has an authorization flaw affecting versions up to 3.0.14. This issue arises because the plugin fails to en…

High

CVE-2026-57319

FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.9

The FOX – Currency Switcher Professional for WooCommerce plugin on WordPress contains a vulnerability allowing malicious code injection thr…

Critical

CVE-2026-56068

JetEngine [jet-engine] < 3.8.11

The JetEngine plugin for WordPress contains a security flaw in versions up to 3.8.10.2, allowing malicious input to compromise database int…

High

CVE-2026-56041

Responsive Lightbox & Gallery [responsive-lightbox] < 2.7.7

The Responsive Lightbox & Gallery plugin for WordPress contains a security flaw in versions up to 2.7.6, allowing malicious code to be embe…

CVE

CVE-2026-10753

Site Kit by Google – Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.176.0

A vulnerability exists in the Site Kit by Google plugin for WordPress prior to version 1.176, where an unintended group of users can alter …

CVE

CVE-2026-9710

Cornerstone [cornerstone] < 7.8.8 (closed)

Prior to version 7.8.8, a specific CSS-preview request handler in the Cornerstone page builder plugin failed to verify user permissions, in…

CVE

CVE-2026-9709

Cornerstone [cornerstone] < 7.8.9 (closed)

Prior to version 7.8.9, a vulnerability in the Cornerstone plugin's REST API exposed user metadata to authenticated users, including roles …

CVE

CVE-2026-10749

Post Duplicator [post-duplicator] < 3.0.15

The Post Duplicator WordPress plugin contains a vulnerability that allows attackers with contributor-level access and above to inject malic…

High

CVE-2026-56042

Advanced Order Export For WooCommerce [woo-order-export-lite] < 4.0.10

The Advanced Order Export For WooCommerce plugin on WordPress platforms is susceptible to malicious script injection due to inadequate data…

Medium

CVE-2026-10833

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.2.0

The Gutenberg Essential Blocks plugin for WordPress contains a security flaw in its handling of the 'configurablePrefix' attribute, which a…

High

CVE-2026-56071

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.53.2

The Forminator Forms plugin for WordPress contains a security flaw in versions prior to or equal to 1.53.1, allowing malicious code injecti…

High

CVE-2026-12242

AdRotate Banner Manager [adrotate] < 5.17.8

The AdRotate Banner Manager plugin for WordPress contains a security flaw that allows attackers with at least contributor privileges to inj…

Medium

CVE-2026-11614

Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.7.3

The Xpro Addons plugin for WordPress contains a security flaw in versions up to 1.7.2, allowing malicious users with elevated permissions t…

Critical

CVE-2026-56032

Buddyboss Platform [buddyboss-platform] < 3.0.5

Authenticated users with subscriber-level access and above can inject malicious PHP objects into the BuddyBoss Platform plugin for WordPres…

High

CVE-2026-7761

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0

The Ultimate Member plugin's handling of password reset links is compromised due to a series of interconnected errors. In versions up to 2.…

High

CVE-2026-56031

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 7.3.1.3

The Uncanny Automator plugin for WordPress contains a vulnerability that allows attackers to inject malicious PHP objects through untrusted…

Critical

CVE-2022-50972

WooCommerce [woocommerce] == 7.1.0 (unfixed)

WooCommerce version 7.1.0 is vulnerable to remote code execution through improper handling of the product-type parameter in the class-wc-me…

Medium

CVE-2026-12119

Simple File List [simple-file-list] < 6.3.8

The Simple File List plugin for WordPress has a security flaw affecting all versions up to 6.3.7. A contributor-level user or higher can ex…

High

CVE-2026-11911

Simple File List [simple-file-list] < 6.3.8

A vulnerability exists in the Simple File List plugin for WordPress, specifically in the eeSFL_DeleteFile function, which allows unauthenti…

High

CVE-2026-11912

Simple File List [simple-file-list] < 6.3.8

The Simple File List plugin for WordPress contains a flaw in its authorization checks, allowing unauthorized access to file modification ca…

Medium

CVE-2026-12238

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02

A security flaw exists in WP Go Maps – Most Popular Map Plugin for WordPress, affecting all versions up to 10.1.01. The issue arises from i…

Medium

CVE-2026-56007

Ocean Product Sharing [ocean-product-sharing] < 2.2.3

The Ocean Product Sharing plugin for WordPress is susceptible to stored cross-site scripting (XSS) vulnerabilities up to version 2.2.2, owi…

High

CVE-2026-56012

Media Library Assistant [media-library-assistant] < 3.36

The Media Library Assistant plugin for WordPress contains a security flaw in versions 3.35 and below that enables malicious users with cont…

Critical

CVE-2026-8713

Fusion Builder [fusion-builder] < 3.15.4

The Avada Builder plugin for WordPress has a vulnerability that allows an attacker to delete any file on the server without needing authent…

High

CVE-2026-56008

Fusion Builder [fusion-builder] < 3.15.5

The Avada (Fusion) Builder plugin for WordPress contains a security flaw that allows certain users to gain elevated permissions. Specifical…

High

CVE-2026-54842

Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.26

The Royal MCP – Secure AI Connector plugin for WordPress contains a flaw that allows attackers with elevated privileges to bypass security …

High

CVE-2026-56006

Interactive Content – H5P [h5p] < 1.17.7

The H5P plugin for WordPress contains a security flaw that allows malicious code to be injected into pages through a technique called Refle…

Medium

CVE-2026-11358

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.7

The Orbit Fox plugin, which includes features like duplicate page creation and SVG support for WordPress up to version 3.0.6, is susceptibl…

Critical

CVE-2026-54823

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.4

The Widget Options plugin for WordPress contains a critical security flaw that allows malicious users with contributor-level permissions or…

Medium

CVE-2026-11357

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.6

Authenticated users with contributor-level access or higher can access sensitive information stored in the browser's memory, including a Wo…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.