CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

High

CVE-2026-54816

Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.22

Versions of the Advanced Ads - Ad Manager & AdSense plugin prior to 2.0.22 contain a critical security flaw that enables malicious users wi…

Medium

CVE-2026-11360

Advanced Order Export For WooCommerce [woo-order-export-lite] < 4.1.0

The Advanced Order Export For WooCommerce plugin for WordPress contains a vulnerability in versions up to 4.0.10 that can be exploited by a…

Critical

CVE-2026-54825

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 7.4.1

The wpDataTables Premium plugin for WordPress contains a vulnerability in versions 7.4 and earlier, allowing malicious input to be injected…

High

CVE-2026-54824

Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 3.0.4

All versions of the Quads Ads Manager for Google AdSense plugin prior to version 3.1 are susceptible to a security flaw that allows unautho…

Medium

CVE-2026-57335

Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 3.0.4

The Quads Ads Manager for Google AdSense plugin contains a security flaw that allows users with elevated privileges to bypass intended acce…

Medium

CVE-2026-12093

Simple Membership [simple-membership] < 4.7.6

The Simple Membership plugin for WordPress has a security flaw that allows unauthorized users to deactivate any account, without needing to…

High

CVE-2026-54185

Cornerstone [cornerstone] < 7.8.8 (closed)

The Cornerstone plugin for WordPress contains a security flaw in versions up to 7.8.8, which allows malicious users with at least subscribe…

High

CVE-2026-54193

Fusion Builder [fusion-builder] < 3.15.5

The Avada Builder plugin for WordPress contains a flaw in its file path validation mechanism. This weakness allows authorized users with at…

High

CVE-2026-54804

Melhor Envio [melhor-envio-cotacao] < 2.16.4

A security flaw exists within the Melhor Envio plugin for WordPress, affecting all versions prior to 2.16.4. The issue arises from a lack o…

High

CVE-2026-12360

JetEngine [jet-engine] < 3.8.10.2

The JetEngine plugin for WordPress contains a security flaw that allows attackers to inject malicious SQL code into the database. This vuln…

High

CVE-2026-54189

JetEngine [jet-engine] < 3.8.10.1

The JetEngine plugin for WordPress contains a security flaw that allows malicious code injection through unsanitized inputs, which can lead…

High

CVE-2026-54188

JetEngine [jet-engine] < 3.8.10.1

The JetEngine plugin for WordPress contains a security flaw in versions up to 3.8.10, allowing malicious code injection through insufficien…

High

CVE-2026-54192

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.3.0

The Popup Box plugin for WordPress contains a security flaw in versions 6.2.9 and earlier, allowing malicious code injection through unsani…

Medium

CVE-2026-54196

JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.1.1

A security flaw exists within the JetFormBuilder Dynamic Blocks Form Builder plugin for WordPress, affecting all versions prior to 3.6.2. T…

High

CVE-2026-54195

JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.6.1

The JetFormBuilder plugin for WordPress contains a security flaw in versions up to 3.6.0.1, allowing malicious code injection through unsan…

Medium

CVE-2026-2381

WooCommerce Stripe Payment Gateway [woocommerce-gateway-stripe] < 10.8.0

The WooCommerce Stripe Payment Gateway plugin for WordPress contains a vulnerability that allows unauthorized modification of order data. S…

High

CVE-2026-54191

Pods – Custom Content Types and Fields [pods] < 3.3.9

The Pods plugin for WordPress contains a security flaw affecting versions prior to 3.3.9, allowing malicious users to embed executable code…

High

CVE-2026-54198

Media Library Assistant [media-library-assistant] < 3.36

The Media Library Assistant plugin for WordPress has a security flaw that allows attackers to inject malicious code into web pages. This ca…

CVE

CVE-2026-6382

File Manager [wp-file-manager] < 8.0.4

Authenticated users can exploit a vulnerability in certain WordPress plugins by manipulating an unsecured parameter that is passed to a sys…

Critical

CVE-2026-54194

Fusion Builder [fusion-builder] < 3.15.5

The Avada Builder plugin for WordPress contains a vulnerability that allows attackers with contributor-level access and above to inject mal…

CVE

CVE-2026-8386

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10

The WP Go Maps plugin prior to version 10.0.10 contains a vulnerability in its public single-marker REST endpoint, allowing unauthorized ac…

High

CVE-2026-8176

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2

The LatePoint – Calendar Booking Plugin for Appointments and Events has a security flaw in versions up to 5.5.1 that allows certain users t…

Medium

CVE-2026-54197

GetGenie – AI SEO Assistant & Content Writer with Keyword Research, AEO & GEO [getgenie] < 4.4.2

A vulnerability exists in the GetGenie plugin, allowing unauthorized individuals to access confidential user information and settings acros…

High

CVE-2025-68045

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.13

The Eventin plugin for WordPress contains a security flaw that allows unverified users to execute certain actions without proper authorizat…

Critical

CVE-2026-54187

JetEngine [jet-engine] < 3.8.10.2

The JetEngine plugin for WordPress contains a vulnerability in versions 3.8.10.1 and earlier, where user-submitted data is not properly san…

High

CVE-2026-5513

Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.3

The Bookly plugin for WordPress contains a vulnerability that allows malicious code injection through the 'bookly-customer-full-name' cooki…

Medium

CVE-2026-3297

Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.1.0

The Pagelayer plugin for WordPress contains a security flaw in versions 2.0.9 and earlier, allowing malicious users with contributor permis…

Medium

CVE-2026-2470

Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.1.0

The Pagelayer plugin for WordPress has a security flaw that allows attackers with contributor-level access and above to set up custom conta…

Critical

CVE-2026-52706

JetEngine [jet-engine] < 3.8.10.1

The JetEngine WordPress plugin contains a vulnerability that allows attackers to inject malicious PHP objects through untrusted input in ve…

Medium

CVE-2026-9125

Presto Player [presto-player] < 4.2.1

The Presto Player plugin for WordPress contains a security flaw in its handling of the link_url parameter within the [presto_player_overlay…

Medium

CVE-2026-53740

Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)

A vulnerability in Yoast Duplicate Post version 4.6 or earlier allows attackers to insert unescaped post titles and permalinks into the Cla…

Medium

CVE-2026-53739

Yoast Duplicate Post [duplicate-post] <= 4.6 (unfixed)

Yoast Duplicate Post version 4.6 and earlier is susceptible to a cross-site request forgery vulnerability in its duplicate_post_dismiss_not…

High

CVE-2026-10795

UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.26.5

A vulnerability exists in the UpdraftPlus WordPress plugin, affecting versions up to 1.26.4 (free) and 2.26.5 (premium), where an attacker …

Medium

CVE-2026-49043

WP Migrate Lite – Migration Made Easy [wp-migrate-db] < 2.7.9

The WP Migrate Lite – Migration Made Easy plugin, versions 2.7.8 and earlier, is susceptible to Cross-Site Request Forgery due to inadequat…

CVE

CVE-2026-9067

Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.60

The Schema & Structured Data for WP & AMP plugin has a security flaw in its frontend AJAX functionality. Specifically, it fails to verify u…

CVE

CVE-2026-8071

Spam protection, Honeypot, Anti-Spam by CleanTalk [cleantalk-spam-protect] < 6.79

The CleanTalk Anti-Spam plugin for WordPress contains a security flaw that allows malicious code injection via unsanitized input, which can…

CVE

CVE-2026-4986

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.0.5

Before version 1.10.0.5, the WPForms plugin for WordPress fails to authenticate incoming PayPal webhook events, enabling unauthorized users…

Medium

CVE-2026-8853

MW WP Form [mw-wp-form] < 5.1.4

A vulnerability exists in the MW WP Form plugin for WordPress, affecting versions up to 5.1.3, which allows authenticated attackers with ed…

Critical

CVE-2026-52693

eCommerce Product Catalog [ecommerce-product-catalog] < 3.5.6

The eCommerce Product Catalog Plugin for WordPress contains a vulnerability in versions 3.5.5 and earlier, where user-supplied input is not…

Medium

CVE-2026-53675

BuddyPress [buddypress] <= 14.4.0 (unfixed)

BuddyPress version 14.4.0 has a flaw in its friends REST API that lets anyone with an account access another user's entire friend list with…

High

CVE-2026-53674

BuddyPress [buddypress] <= 14.4.0 (unfixed)

BuddyPress 14.4.0 has a security flaw that lets attackers manipulate database queries by crafting mention names with special characters. Wh…

High

CVE-2026-53673

BuddyPress [buddypress] <= 14.4.0 (unfixed)

BuddyPress version 14.4.0 has a security flaw in its messages REST API that can be exploited by authenticated users. This vulnerability all…

Critical

CVE-2026-49080

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 7.4

The wpDataTables Premium plugin for WordPress contains a security flaw in versions 7.3.6 and earlier, allowing malicious individuals to inj…

Medium

CVE-2026-7542

Slider Revolution [revslider] < 7.0.11

The Slider Revolution plugin for WordPress has a vulnerability that allows attackers to access sensitive server files. This is due to a com…

Critical

CVE-2026-49772

The Events Calendar [the-events-calendar] < 6.16.3

The Events Calendar plugin for WordPress contains a security flaw in versions up to 6.16.2, where user input is not properly sanitized, all…

Critical

CVE-2026-49075

JetEngine [jet-engine] < 3.8.10

The JetEngine WordPress plugin contains a vulnerability that allows attackers with contributor-level access and above to inject malicious P…

High

CVE-2026-49074

JetEngine [jet-engine] < 3.8.10

The JetEngine WordPress plugin contains a security flaw that allows malicious code injection through unsanitized inputs, leading to the exe…

Critical

CVE-2026-49076

JetEngine [jet-engine] < 3.8.10

The JetEngine plugin for WordPress contains a security flaw in versions 3.8.9.1 and earlier, allowing malicious input to compromise databas…

Critical

CVE-2026-49084

JetEngine [jet-engine] < 3.8.9.1

The JetEngine plugin for WordPress contains a security weakness in versions up to 3.8.9.1, allowing malicious input to disrupt the normal f…

Medium

CVE-2026-7665

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.5

The Essential Addons for Elementor plugin exposes sensitive post information in WordPress versions prior to 6.6.4 due to inadequate control…

Medium

CVE-2026-9197

Smart Slider 3 [smart-slider-3] < 3.5.1.37

The Smart Slider 3 plugin for WordPress contains a security flaw in versions up to 3.5.1.36 that allows authorized users with elevated perm…

Medium

CVE-2026-7795

Click to Chat – HoliThemes [click-to-chat-for-whatsapp] < 4.40

A WordPress plugin called Click to Chat – WA Widget has a security flaw in versions 4.38 and earlier, which allows malicious code injection…

Low

CVE-2025-12656

WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.129

The WPvivid Backup & Migration plugin contains a flaw that allows authorized users with elevated privileges to erase directories at will du…

Medium

CVE-2026-7792

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.0.5

The WPForms plugin versions up to 1.10.0.1 are susceptible to a security flaw where unauthenticated attackers can forge PayPal webhook even…

High

CVE-2026-5415

Advanced Google reCAPTCHA [advanced-google-recaptcha] < 5.39

A security flaw exists in WP Captcha PRO plugin versions up to 5.38 that allows unauthorized login through a specific vulnerability. This o…

High

CVE-2026-5411

Advanced Google reCAPTCHA [advanced-google-recaptcha] < 5.39

A security flaw exists within WP Captcha PRO, a premium WordPress plugin, affecting versions up to 5.38. Specifically, a licensing module v…

Medium

CVE-2026-9280

Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.8.16

The Ad Inserter plugin has a security flaw in its handling of URL parameters when displaying ads in iframe mode. This weakness allows malic…

Medium

CVE-2026-9594

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.5

A security flaw exists within WP Maps, a WordPress plugin that integrates various mapping services, allowing attackers with administrator-l…

CVE

CVE-2026-8385

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 10.0.10

The WP Go Maps plugin for WordPress contains a flaw in its handling of unauthorized access to sensitive data through an AJAX fallback route…

Medium

CVE-2026-7796

EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.5.4

The EmbedPress plugin for WordPress contains a security flaw affecting all versions up to 4.5.3. The issue arises from inadequate filtering…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.