CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2026-9719

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.6.1

The LatePoint plugin, used in WordPress installations up to version 5.6.0, contains a security flaw that allows unauthorized access to modi…

High

CVE-2026-49083

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.2

The LatePoint – Calendar Booking Plugin for Appointments and Events on WordPress contains a security flaw affecting all plugin versions pri…

Medium

CVE-2026-8976

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.8

The Feedzy plugin for WordPress has a security flaw that allows authorized attackers with contributor-level access or higher to perform cer…

High

CVE-2026-9290

WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.18

The WP User Manager plugin for WordPress contains a flaw that allows malicious individuals to inject arbitrary server-side scripts into vul…

Critical

CVE-2026-49766

WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.17

The WP User Manager plugin for WordPress contains a critical security flaw that allows authorized users with Subscriber-level permissions o…

High

CVE-2026-49113

Cornerstone [cornerstone] < 7.8.8 (closed)

A security flaw exists within the Cornerstone plugin for WordPress, allowing malicious users who have logged in with a level of access equa…

High

CVE-2026-10586

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.1.4

The Gutenberg Essential Blocks plugin for WordPress has a weakness in its `save_ai_generated_image()` function that allows an attacker with…

Medium

CVE-2026-48969

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.10

A security flaw exists within the Really Simple Security plugin for WordPress, which allows users with elevated permissions to bypass certa…

High

CVE-2026-48970

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.10.1

The Really Simple Security – Simple and Performant Security (previously known as Really Simple SSL) plugin for WordPress has a security fla…

Medium

CVE-2026-34892

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.271.1

The Rank Math SEO plugin for WordPress contains a security flaw that allows authorized users with elevated privileges to bypass intended ac…

High

CVE-2026-49056

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.9.5

All versions of the WebToffee WooCommerce PDF Invoices plugin prior to version 5 are susceptible to a security flaw that allows unauthorize…

Medium

CVE-2026-49782

Elementor Website Builder – more than just a page builder [elementor] < 4.1.1

Authenticated users with contributor-level access or higher can exploit a vulnerability in Elementor Website Builder plugin for WordPress b…

CVE

CVE-2026-8293

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.10.1

A vulnerability exists in Really Simple Security for WordPress versions prior to 9.5.10.1, specifically affecting its two-factor authentica…

High

CVE-2026-48889

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.4

The Amelia plugin for WordPress contains a security flaw affecting all versions prior to 2.4, allowing users with Subscriber-level permissi…

Medium

CVE-2026-3722

Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) [auto-image-attributes-from-filename-with-bulk-updater] < 4.9.1

The Auto Image Attributes From Filename With Bulk Updater plugin for WordPress is susceptible to Stored Cross-Site Scripting until version …

Critical

CVE-2026-8206

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.7

The Kirki plugin, which supports page building and customization in WordPress, has a privilege escalation vulnerability from version 6.0.0 …

Medium

CVE-2026-9050

Slider Revolution [revslider] < 6.7.56

The Slider Revolution WordPress plugin has a security flaw in versions 6.0.0 through 6.7.55 and 7.0.0 through 7.0.14 that allows unauthoriz…

Medium

CVE-2026-9048

Slider Revolution [revslider] < 7.0.15

Authenticated users with contributor privileges or higher can obtain sensitive information from WordPress installations using Slider Revolu…

High

CVE-2026-48872

EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.5.3

The EmbedPress plugin for WordPress contains a security flaw that allows unauthorized access to confidential information stored within the …

High

CVE-2026-48871

MW WP Form [mw-wp-form] < 5.1.4

The MW WP Form plugin for WordPress has a security flaw in versions up to 5.1.3, allowing malicious code injection through unsanitized inpu…

Critical

CVE-2026-48866

Gravity Forms [gravityforms] < 2.10.1

A critical vulnerability exists in Gravity Forms plugin versions prior to 2.10.0.1, allowing an unauthorized user to erase any file from th…

Medium

CVE-2026-8382

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.8.2

The Advanced Custom Fields plugin for WordPress is susceptible to an authorization bypass vulnerability in all versions up to 6.8.1, as it …

Medium

CVE-2026-42752

Accept Stripe Payments [stripe-payments] < 2.0.99

The Stripe Payments Plugin for WordPress, when installed at a version prior to 2.0.99, contains an oversight that allows unauthorized acces…

High

CVE-2026-7465

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.26

The Spectra Gutenberg Blocks plugin for WordPress contains a vulnerability that allows attackers to execute arbitrary code on the server. T…

High

CVE-2026-48835

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.0.5

The WPForms plugin for WordPress contains a flaw that allows unauthorized individuals to bypass security checks, enabling them to execute c…

Critical

CVE-2026-8809

Advanced Custom Fields: Extended [acf-extended] < 0.9.2.6

The Advanced Custom Fields: Extended plugin for WordPress contains a vulnerability affecting versions up to 0.9.2.5, which allows unauthent…

Medium

CVE-2025-12714

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.271.1

The Rank Math SEO plugin for WordPress contains a security flaw that allows unauthorized access due to an oversight in the update_site_edit…

High

CVE-2026-27407

AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0

The AI Engine plugin for WordPress suffers from a privilege escalation flaw affecting all versions prior to 3.4.10, allowing users with ele…

High

CVE-2026-6075

Media Library Assistant [media-library-assistant] < 3.36

The Media Library Assistant WordPress plugin has a security flaw that allows unauthorized access to certain actions within its settings. Sp…

Medium

CVE-2026-9243

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.16

The Plus Addons for Elementor plugin's Carousel Anything widget contains a security flaw affecting versions up to 6.4.15. Specifically, the…

High

CVE-2026-39447

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.0

The Simply Schedule Appointments Booking Plugin for WordPress contains a security flaw that allows malicious code injection, specifically S…

Medium

CVE-2026-49053

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.9.7

The ElementsKit Elementor Addons plugin has a security flaw that allows unverified users to execute an unauthorized operation due to the ab…

Medium

CVE-2026-49052

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.9.7

The ElementsKit Elementor Addons plugin contains a security flaw that allows users with contributor privileges or higher to bypass intended…

High

CVE-2026-42749

Disable Comments & Delete All Comments [comments-plus] < 1.3.1

The Disable Comments for Any Post Types (Remove comments) plugin, versions up to and including 1.3.0, is susceptible to a high-priority bro…

Medium

CVE-2026-49044

Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 6.0.0

An authenticated attacker with contributor-level access or higher in a WordPress site using the Advanced Custom Fields: Font Awesome Field …

Medium

CVE-2026-49059

Meta for WooCommerce [facebook-for-woocommerce] < 3.7.1

The Meta for WooCommerce plugin for WordPress contains a vulnerability that allows unauthorized individuals to manipulate user redirects, e…

Medium

CVE-2026-7533

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.8

The Easy Digital Downloads plugin for WordPress has a security flaw that allows malicious links to be clicked by an administrator, which ca…

Medium

CVE-2026-9228

Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.17

A security flaw exists in Timetable and Event Schedule by MotoPress plugin for WordPress, affecting versions up to 2.4.16. The issue arises…

Medium

CVE-2026-7526

PDF Embedder – PDF Viewer & Embed PDF Files for WordPress [pdf-embedder] < 5.0.0

A security flaw exists in PDF Embedder plugin for WordPress, affecting all versions up to 4.9.3. This vulnerability allows authorized users…

High

CVE-2026-7797

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.9

The Simply Schedule Appointments Booking Plugin for WordPress contains a vulnerability in its SQL injection protection. Specifically, the p…

Medium

CVE-2026-6937

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.9

A vulnerability exists in the Simply Schedule Appointments Booking Plugin for WordPress, affecting all versions up to 1.6.11.8. The plugin …

Medium

CVE-2026-42744

Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 3.0.3

A functionality within the Quads Ads Manager for Google AdSense plugin has a flawed permission check that can be bypassed by individuals wi…

Medium

CVE-2026-9241

FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.7

The FOX – Currency Switcher Professional for WooCommerce plugin on WordPress suffers from an authorization bypass vulnerability in versions…

High

CVE-2026-42736

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.15.0

The Better Messages plugin for WordPress contains a security flaw affecting all versions prior to 2.14.17, allowing malicious individuals t…

Medium

CVE-2025-14481

Yoast SEO – Advanced SEO with real-time guidance and built-in AI [wordpress-seo] < 26.6

The Yoast SEO plugin for WordPress has an insecure direct object reference vulnerability in all versions up to 26.5. The issue arises becau…

High

CVE-2026-3375

LiteSpeed Cache [litespeed-cache] < 7.8

The LiteSpeed Cache plugin for WordPress contains a security flaw in its REST API endpoints for handling QUIC.cloud callback notifications.…

High

CVE-2026-8832

WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager [insert-headers-and-footers] < 2.3.6

A vulnerability exists in WordPress plugins up to version 2.3.5 that permits unauthorized code execution. This flaw arises from the registr…

Medium

CVE-2026-7493

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.7

The Simply Schedule Appointments Booking Plugin for WordPress contains a flaw in its REST API endpoint, allowing an attacker to trigger a d…

Medium

CVE-2026-24592

Auto Affiliate Links [wp-auto-affiliate-links] < 6.8.9

A security flaw exists in the Auto Affiliate Links plugin for WordPress, where insufficient permission checks allow unverified users to exe…

Medium

CVE-2026-42732

Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 3.0.3

A critical security issue affects the Quads Ads Manager for Google AdSense plugin, which is designed for WordPress installations. In versio…

High

CVE-2026-9284

WooCommerce PayPal Payments [woocommerce-paypal-payments] < 4.0.2

The WooCommerce PayPal Payments plugin for WordPress has a security flaw that allows attackers to manipulate and access sensitive order inf…

Medium

CVE-2026-7798

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.0.0

The FluentCRM plugin for WordPress contains a security flaw affecting all versions up to 2.9.87, specifically in how it handles the 'Subscr…

High

CVE-2026-57715

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 3.1.8

The FluentCRM plugin for WordPress contains a security flaw that allows malicious code injection through unsanitized input, which can be ex…

Medium

CVE-2026-15285

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.12

A stored cross-site scripting vulnerability was present in the Plus Addons for Elementor plugin for WordPress, specifically affecting versi…

Critical

CVE-2026-6279

Fusion Builder [fusion-builder] < 3.15.3

The Avada Builder plugin for WordPress contains a vulnerability that allows an attacker with no login credentials to inject and execute mal…

Medium

CVE-2026-1543

Fusion Builder [fusion-builder] < 3.15.3

The Avada Builder plugin for WordPress contains a security flaw in versions up to 3.15.2, allowing attackers with Subscriber-level access o…

CVE

CVE-2026-9065

SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.2.1

A flaw exists in SureCart's REST API endpoint for integrations, where certain parameters are not properly sanitized when passed to the quer…

Medium

CVE-2026-6566

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 4.2.1

The NextGEN Gallery plugin for WordPress contains a flaw in its REST API handling of image deletions. Specifically, the permission check fo…

Medium

CVE-2026-8096

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.7

The Kirki plugin, used for page building and customizing websites in WordPress, has an authorization bypass vulnerability affecting all ver…

High

CVE-2026-8073

Kirki – Freeform Page Builder, Website Builder & Customizer [kirki] < 6.0.7

The Kirki plugin, used for page building and customization on WordPress, has a vulnerability allowing unauthenticated users to delete any f…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.