CVE DATABASE
WordPress Plugin CVE Database
1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.
Medium
CVE-2026-12902
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8
Medium
CVE-2026-12904
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.8
Medium
CVE-2026-13733
Download Manager [download-manager] < 3.3.61
Medium
CVE-2026-14343
Download Manager [download-manager] < 3.3.62
High
CVE-2026-57672
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 6.5.1.2
High
CVE-2026-57678
Slider Revolution [revslider] < 7.1.0
High
CVE-2026-13228
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.4
Critical
CVE-2026-57623
W3 Total Cache [w3-total-cache] < 2.10.0
Medium
CVE-2025-66076
Woostify Sites Library [woostify-sites-library] <= 1.6.2 (unfixed)
Medium
CVE-2026-57627
Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.12
Medium
CVE-2026-13295
Page Builder by SiteOrigin [siteorigin-panels] < 2.34.4
Medium
CVE-2026-11356
Ivory Search – WordPress Search Plugin [add-search-to-menu] < 5.5.16
Medium
CVE-2025-63041
Forget About Shortcode Buttons [forget-about-shortcode-buttons] <= 2.1.3 (unfixed)
High
CVE-2026-57628
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.1.0
High
CVE-2026-57317
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.12.4
Medium
CVE-2026-13245
MaxButtons – Create buttons [maxbuttons] < 9.8.6
High
CVE-2026-57314
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.3
High
CVE-2026-7655
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.3.0
Medium
CVE-2026-57316
GetGenie – AI SEO Assistant & Content Writer with Keyword Research, AEO & GEO [getgenie] < 4.4.3
High
CVE-2026-57631
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.2
High
CVE-2026-57321
Interactive Content – H5P [h5p] < 1.17.8
High
CVE-2026-57655
Child Theme Wizard [child-theme-wizard] < 1.5
Medium
CVE-2026-57619
Elementor Website Builder – more than just a page builder [elementor] < 4.1.4
CVE
CVE-2026-12525
Redux Framework [redux-framework] < 4.5.13
Critical
CVE-2026-56070
Advance Product Search- Voice & Ajax Search for WooCommerce [th-advance-product-search] < 1.4.5
High
CVE-2026-56051
TablePress – Tables in WordPress made easy [tablepress] < 3.3.2
High
CVE-2026-56060
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 7.1.2
Medium
CVE-2026-57313
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.2.3
Medium
CVE-2026-56048
Payment Gateway Based Fees and Discounts for WooCommerce [checkout-fees-for-woocommerce] < 3.1.0
Authorization Bypass Through User-Controlled Key
Medium
CVE-2026-57622
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.15
Medium
CVE-2026-11818
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.15
High
CVE-2026-57319
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.9
Critical
CVE-2026-56068
JetEngine [jet-engine] < 3.8.11
High
CVE-2026-56041
Responsive Lightbox & Gallery [responsive-lightbox] < 2.7.7
CVE
CVE-2026-10753
Site Kit by Google – Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.176.0
CVE
CVE-2026-9710
Cornerstone [cornerstone] < 7.8.8 (closed)
CVE
CVE-2026-9709
Cornerstone [cornerstone] < 7.8.9 (closed)
CVE
CVE-2026-10749
Post Duplicator [post-duplicator] < 3.0.15
High
CVE-2026-56042
Advanced Order Export For WooCommerce [woo-order-export-lite] < 4.0.10
Medium
CVE-2026-10833
Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.2.0
High
CVE-2026-56071
Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.53.2
High
CVE-2026-12242
AdRotate Banner Manager [adrotate] < 5.17.8
Medium
CVE-2026-11614
Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.7.3
Critical
CVE-2026-56032
Buddyboss Platform [buddyboss-platform] < 3.0.5
High
CVE-2026-7761
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0
High
CVE-2026-56031
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 7.3.1.3
Critical
CVE-2022-50972
WooCommerce [woocommerce] == 7.1.0 (unfixed)
Medium
CVE-2026-12119
Simple File List [simple-file-list] < 6.3.8
High
CVE-2026-11911
Simple File List [simple-file-list] < 6.3.8
High
CVE-2026-11912
Simple File List [simple-file-list] < 6.3.8
Medium
CVE-2026-12238
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02
Medium
CVE-2026-56007
Ocean Product Sharing [ocean-product-sharing] < 2.2.3
High
CVE-2026-56012
Media Library Assistant [media-library-assistant] < 3.36
Critical
CVE-2026-8713
Fusion Builder [fusion-builder] < 3.15.4
High
CVE-2026-56008
Fusion Builder [fusion-builder] < 3.15.5
High
CVE-2026-54842
Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP [royal-mcp] < 1.4.26
High
CVE-2026-56006
Interactive Content – H5P [h5p] < 1.17.7
Medium
CVE-2026-11358
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.7
Critical
CVE-2026-54823
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.4
Medium
CVE-2026-11357
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.6
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.