CVE DATABASE
WordPress Plugin CVE Database
1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.
High
CVE-2026-12242
AdRotate Banner Manager [adrotate] < 5.17.8
Medium
CVE-2026-11614
Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.7.3
Critical
CVE-2026-56032
Buddyboss Platform [buddyboss-platform] < 3.0.5
High
CVE-2026-7761
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.12.0
High
CVE-2026-56031
Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin [uncanny-automator] < 7.3.1.3
Critical
CVE-2022-50972
WooCommerce [woocommerce] == 7.1.0 (unfixed)
Medium
CVE-2026-12119
Simple File List [simple-file-list] < 6.3.8
High
CVE-2026-11911
Simple File List [simple-file-list] < 6.3.8
High
CVE-2026-11912
Simple File List [simple-file-list] < 6.3.8
Medium
CVE-2026-12238
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.1.02
Medium
CVE-2026-56007
Ocean Product Sharing [ocean-product-sharing] < 2.2.3
High
CVE-2026-56012
Media Library Assistant [media-library-assistant] < 3.36
Critical
CVE-2026-8713
Fusion Builder [fusion-builder] < 3.15.4
High
CVE-2026-56008
Fusion Builder [fusion-builder] < 3.15.5
High
CVE-2026-54842
Royal MCP – Secure AI Connector for Claude, ChatGPT & Gemini [royal-mcp] < 1.4.26
High
CVE-2026-54835
Five Star Restaurant Menu and Food Ordering [food-and-drink-menu] < 2.5.3
High
CVE-2026-56006
Interactive Content – H5P [h5p] < 1.17.7
Medium
CVE-2026-11358
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.7
Critical
CVE-2026-54823
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.4
Medium
CVE-2026-11357
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.7.6
High
CVE-2026-54816
Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.22
Medium
CVE-2026-11360
Advanced Order Export For WooCommerce [woo-order-export-lite] < 4.1.0
Critical
CVE-2026-54825
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 7.4.1
High
CVE-2026-54824
Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 3.0.4
Medium
CVE-2026-12093
Simple Membership [simple-membership] < 4.7.6
High
CVE-2026-54185
Cornerstone [cornerstone] < 7.8.8 (closed)
High
CVE-2026-54193
Fusion Builder [fusion-builder] < 3.15.5
High
CVE-2026-54804
Melhor Envio [melhor-envio-cotacao] < 2.16.4
High
CVE-2026-12360
JetEngine [jet-engine] < 3.8.10.2
High
CVE-2026-54189
JetEngine [jet-engine] < 3.8.10.1
High
CVE-2026-54188
JetEngine [jet-engine] < 3.8.10.1
High
CVE-2026-54192
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.3.0
Medium
CVE-2026-54196
JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.1.1
High
CVE-2026-54195
JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.1
Medium
CVE-2026-2381
WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 10.8.0
High
CVE-2026-54191
Pods – Custom Content Types and Fields [pods] < 3.3.9
High
CVE-2026-54198
Media Library Assistant [media-library-assistant] < 3.36
Critical
CVE-2026-54194
Fusion Builder [fusion-builder] < 3.15.5
CVE
CVE-2026-8386
WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10
High
CVE-2026-8176
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2
High
CVE-2019-25746
Sliced Invoices – WordPress Invoice Plugin [sliced-invoices] <= 3.8.2 (unfixed)
Medium
CVE-2026-54197
GetGenie – AI Content Writer with Keyword Research & SEO Tracking [getgenie] < 4.4.2
High
CVE-2025-68045
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) [wp-event-solution] < 4.1.13
Critical
CVE-2026-54187
JetEngine [jet-engine] < 3.8.10.2
High
CVE-2026-52702
SEO Redirection Plugin – 301 Redirect Manager [seo-redirection] < 9.18
High
CVE-2026-5513
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.3
Medium
CVE-2026-3297
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.1.0
Medium
CVE-2026-2470
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.1.0
Critical
CVE-2026-52706
JetEngine [jet-engine] < 3.8.10.1
Medium
CVE-2026-9125
Presto Player [presto-player] < 4.2.1
Medium
CVE-2026-53740
Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)
Medium
CVE-2026-53739
Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)
High
CVE-2026-10795
UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.26.5
Medium
CVE-2026-49043
WP Migrate Lite – Migration Made Easy [wp-migrate-db] < 2.7.9
CVE
CVE-2026-9067
Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.60
CVE
CVE-2026-8071
CleanTalk Anti-Spam. Spam Firewall & Bot protection [cleantalk-spam-protect] < 6.79
CVE
CVE-2026-4986
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.0.5
Medium
CVE-2026-8853
MW WP Form [mw-wp-form] < 5.1.4
Critical
CVE-2026-52693
eCommerce Product Catalog Plugin for WordPress [ecommerce-product-catalog] < 3.5.6
Medium
CVE-2026-53675
BuddyPress [buddypress] <= 14.4.0 (unfixed)
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.