CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2026-5075

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.7.1

The All in One SEO plugin for WordPress contains a security flaw that allows unauthorized disclosure of sensitive information. In versions …

Medium

CVE-2026-6728

Slider Revolution [revslider] < 7.0.10

The Slider Revolution plugin for WordPress contains a flaw that allows unauthorized access to sensitive information in versions up to 7.0.9…

Medium

CVE-2025-15369

Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.1

The Xpro Addons plugin for WordPress has a security flaw that allows unauthorized access to its content editor feature due to inadequate pe…

Medium

CVE-2026-45442

Presto Player [presto-player] < 4.1.4

The Presto Player plugin for WordPress, in versions up to and including 4.1.3, lacks a necessary security check for a specific function, al…

CVE

CVE-2026-6381

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.3

Authenticated users with subscriber-level access or higher in WordPress installations running WP Maps plugin versions prior to 4.9.3 can ex…

High

CVE-2026-8719

AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.5.0

The WordPress plugin "AI Engine - The Chatbot, AI Framework & MCP" has a vulnerability in version 3.4.9 that allows attackers with subscrib…

Medium

CVE-2020-37233

BuddyPress [buddypress] <= 6.2.0 (unfixed)

BuddyPress version 6.2.0 and earlier contains a stored cross-site scripting flaw that enables authenticated users with moderator-level acce…

High

CVE-2026-45438

Smart Coupons For WooCommerce Coupons [wt-smart-coupons-for-woocommerce] < 2.3.0

A security flaw exists in the Smart Coupons For WooCommerce Coupons plugin, allowing malicious individuals without authentication to execut…

Medium

CVE-2026-6415

Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 6.0.0

The Advanced Custom Fields: Font Awesome plugin for WordPress contains a security flaw affecting versions up to 5.0.2. Specifically, the up…

High

CVE-2026-4094

FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6

The FOX – Currency Switcher Professional plugin for WooCommerce has a security flaw that allows unauthorized data loss. Specifically, an at…

Medium

CVE-2026-5193

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.6.0

The Essential Addons for Elementor plugin, up to version 6.5.13, is susceptible to privilege escalation due to inadequate role validation i…

High

CVE-2026-5396

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.0

A security flaw exists in versions 6.1.21 and earlier of the Fluent Forms plugin for WordPress due to inadequate validation of user-submitt…

High

CVE-2026-5395

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.1

The Fluent Forms plugin for WordPress, up to version 6.2.0, is susceptible to Insecure Direct Object Reference vulnerabilities through the …

High

CVE-2026-3718

ManageWP Worker [worker] < 4.9.32

The ManageWP Worker plugin, up to version 4.9.31, is susceptible to stored cross-site scripting (XSS) attacks through the 'MWP-Key-Name' he…

High

CVE-2026-23970

Redirection for Contact Form 7 [wpcf7-redirect] < 3.2.9

The Redirection for Contact Form 7 plugin for WordPress contains a security flaw affecting versions prior to 3.2.8, allowing malicious code…

Medium

CVE-2026-5243

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.4.12

A security flaw exists in the Plus Addons plugin for WordPress, affecting versions up to 6.4.11. The issue arises from inadequate filtering…

Medium

CVE-2026-5365

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.4.0

The LatePoint plugin for WordPress contains a security flaw that allows unauthorized individuals to exploit a vulnerability in all versions…

Medium

CVE-2026-6206

MW WP Form [mw-wp-form] < 5.1.3

The MW WP Form plugin for WordPress contains a flaw in its handling of post properties, allowing unauthorized users to retrieve sensitive i…

Medium

CVE-2020-37174

HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] <= 1.2.3 (unfixed)

The WOOF Products Filter for WooCommerce plugin through version 1.2.3 contains a stored cross-site scripting flaw that allows authenticated…

Medium

CVE-2026-7525

My Calendar – Accessible Event Manager [my-calendar] < 3.7.10

The My Calendar plugin for WordPress has an authorization flaw that affects all versions up to 3.7.9. Users with custom-level access and ab…

Medium

CVE-2020-37169

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] <= 2.1.3 (unfixed)

The Ultimate Member plugin version 2.1.3 and earlier contains a local file inclusion flaw in class-admin-upgrade.php where attackers with a…

Medium

CVE-2026-6828

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2

The Fluent Forms plugin, used for creating various forms on WordPress sites up to version 6.2.1, is susceptible to stored cross-site script…

Medium

CVE-2026-2515

Hostinger Reach – AI-Powered Email Marketing for WordPress [hostinger-reach] < 1.3.9

The Hostinger Reach email marketing plugin for WordPress contains a security flaw that allows attackers with Subscriber-level access or hig…

Medium

CVE-2025-15463

Advanced Custom Fields: Extended [acf-extended] < 0.9.2.4

The Advanced Custom Fields: Extended plugin for WordPress contains a flaw in its handling of user input, specifically in relation to execut…

High

CVE-2026-5371

MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 10.1.3

The MonsterInsights plugin for WordPress has a security flaw that allows unauthorized users with at least Subscriber privileges to access s…

Medium

CVE-2026-4782

Fusion Builder [fusion-builder] < 3.15.3

An authenticated WordPress user with at least Subscriber-level access can exploit a vulnerability in the Avada Builder plugin, specifically…

High

CVE-2026-4798

Fusion Builder [fusion-builder] < 3.15.2

The Avada Builder plugin for WordPress contains a flaw in its handling of user input, specifically in the 'product_order' parameter, which …

Critical

CVE-2026-49781

OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.28

The OttoKit: All-in-One Automation Platform WordPress plugin contains a vulnerability that allows malicious input to be deserialized as PHP…

Medium

CVE-2022-50958

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] <= 9.1 (unfixed)

Jetpack version 9.1 and earlier contains a reflected cross-site scripting flaw that enables unauthenticated attackers to execute arbitrary …

High

CVE-2026-42667

Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 27.5

All versions of the Bookly plugin prior to 27.5 contain a security flaw that allows unauthorized access to confidential user information or…

Medium

CVE-2021-47924

Ultimate Product Catalog [ultimate-product-catalogue] <= 5.8.2 (unfixed)

The Ultimate Product Catalog plugin through version 5.8.2 is vulnerable to stored cross-site scripting via the price parameter. A logged-in…

Medium

CVE-2026-7652

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1

The LatePoint plugin for WordPress has a vulnerability in its guest booking flow that allows an attacker to take over a user account. This …

CVE

CVE-2026-4935

OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.23

The OttoKit plugin, which offers automation features for WordPress sites, contains a security flaw in versions prior to 1.1.23. Specificall…

Medium

CVE-2026-25468

Happy Addons for Elementor [happy-elementor-addons] < 3.21.0

The Happy Addons for Elementor plugin on WordPress has a vulnerability that allows unauthenticated users to expose sensitive information, a…

Medium

CVE-2026-27416

PDF Poster – let visitors read PDFs without leaving the page [pdf-poster] < 2.5.0

The PDF Poster plugin for WordPress suffers from a capability oversight. In versions prior to or equal to 2.4.1, a specific function lacks …

Medium

CVE-2026-27329

YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.13.0

A security flaw exists within the YITH WooCommerce Wishlist plugin for WordPress, affecting all versions prior to 4.12.1. The issue stems f…

High

CVE-2026-7330

Auto Affiliate Links [wp-auto-affiliate-links] < 6.8.8.1

The Auto Affiliate Links plugin for WordPress contains a security flaw affecting versions up to 6.8.8. Specifically, inadequate filtering o…

High

CVE-2026-7252

WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance [wp-optimize] < 4.5.3

The WP-Optimize plugin for WordPress contains a flaw in its file handling mechanism, specifically in the unscheduled_original_file_deletion…

High

CVE-2026-6692

Slider Revolution [revslider] < 7.0.11

Authenticated users with subscriber privileges or higher can exploit a file upload weakness in Slider Revolution plugin versions between 7.…

Medium

CVE-2026-4807

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11

A WordPress plugin called Appointment Booking Calendar is flawed in its permission handling mechanism, specifically within the nonce_permis…

High

CVE-2026-42653

Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.2.7

The SliceWP Affiliates plugin for WordPress contains a security flaw that allows malicious code to be embedded into the site, which can the…

Medium

CVE-2026-6214

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.53.0.1

A capability check is absent from the listen_for_saving_export_schedule() function in class-export.php of Forminator Forms plugin for WordP…

Medium

CVE-2026-6222

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.52

A vulnerability exists in the Forminator Forms plugin for WordPress, affecting versions up to 1.51.1. The issue arises from the plugin's fa…

Medium

CVE-2026-6344

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.2.2

The Fluent Forms plugin for WordPress versions up to 6.2.1 is susceptible to an Arbitrary File Read vulnerability due to inadequate path va…

High

CVE-2026-7332

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1

The LatePoint plugin for WordPress contains a security flaw that allows attackers to inject malicious scripts into pages accessed by users.…

CVE

CVE-2026-7448

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1

The LatePoint plugin for WordPress contains a security flaw affecting versions up to 5.5.0, where the 'first_name' parameter is not properl…

Medium

CVE-2026-7457

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.5.1

A vulnerability exists in the LatePoint plugin for WordPress, specifically in versions up to 5.5.0, which allows an authenticated attacker …

Medium

CVE-2026-6672

Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.2.8

A vulnerability exists in the SliceWP Affiliates plugin for WordPress, affecting all versions up to 1.2.7. The issue arises from inadequate…

Medium

CVE-2026-4362

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.9.0

A flaw in the ElementsKit Elementor Addons plugin for WordPress allows unauthenticated attackers to modify data without authorization. This…

High

CVE-2026-25863

Conditional Fields for Contact Form 7 [cf7-conditional-fields] < 2.7.3

The Conditional Fields for Contact Form 7 WordPress plugin has a vulnerability in its Wpcf7cfMailParser class. The hide_hidden_mail_fields_…

Medium

CVE-2026-1921

Loco Translate [loco-translate] < 2.8.3

A security flaw exists in Loco Translate plugin versions up to 2.8.2, which allows attackers with Translator-level access or higher to read…

High

CVE-2026-5192

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.52.2

The Forminator Forms plugin for WordPress contains a security flaw affecting versions up to 1.52.1, allowing unauthorized access to server …

Medium

CVE-2026-2729

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.52.1

A security flaw exists within Forminator plugin versions prior to 1.52.0, allowing unauthorized users to exploit the public payment flow by…

Medium

CVE-2026-42663

Simple Membership [simple-membership] < 4.7.3

The Simple Membership plugin for WordPress contains a security flaw in versions up to 4.7.2, which allows malicious code to be embedded int…

Medium

CVE-2026-4790

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.71

The Premium Addons for Elementor plugin, versions 4.11.70 and earlier, is susceptible to stored cross-site scripting (XSS) attacks through …

High

CVE-2026-2052

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.3

The Widget Options – Advanced Conditional Visibility plugin for WordPress is susceptible to Remote Code Execution across all versions up to…

High

CVE-2026-7641

Import and export users and customers [import-users-from-csv-with-meta] < 2.0.9

A WordPress plugin for managing users and customers contains a security flaw that allows attackers to gain elevated privileges within a Mul…

Medium

CVE-2026-15026

Import and export users and customers [import-users-from-csv-with-meta] < 2.4.1

A WordPress plugin called Import and export users and customers has a flaw that allows attackers with subscriber-level access or higher to …

Medium

CVE-2026-6449

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.3

The Amelia plugin for WordPress, used for managing appointments and events, contains an authorization flaw affecting all versions up to 2.1…

Medium

CVE-2026-4658

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 6.1.0

The Essential Blocks plugin for WordPress contains a security flaw affecting all versions up to 6.0.4. The issue arises from the render_cal…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.