CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2026-39488

SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.0.3

A security flaw exists in the SureCart plugin for WordPress, affecting versions prior to 4.0.3. The issue arises from a failure to verify u…

Medium

CVE-2026-39505

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.3

A security flaw exists in the Seriously Simple Podcasting plugin for WordPress, allowing malicious actors to bypass authentication checks w…

High

CVE-2026-39486

Download Monitor [download-monitor] < 5.1.9

The Download Monitor plugin for WordPress contains a vulnerability that allows attackers to inject malicious SQL code into the application'…

High

CVE-2026-39487

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.2

The Amelia plugin for WordPress contains a security flaw in versions up to 2.1.1 that allows malicious users with elevated permissions to i…

Medium

CVE-2026-25339

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.9.2

The WPForms plugin, used for creating various forms on WordPress sites, has a vulnerability that allows unauthenticated users to access sen…

Medium

CVE-2026-32533

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.7

The LatePoint – Calendar Booking Plugin for Appointments and Events has a security flaw in its handling of user-controlled keys, which affe…

Medium

CVE-2026-39483

VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.113.4

A WordPress plugin called VK All in One Expansion Unit has a security flaw that allows attackers to inject malicious code into website page…

High

CVE-2026-39497

FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6

The FOX plugin for WordPress contains a security flaw in versions 1.4.5 and earlier, where user input is not properly sanitized, allowing m…

Critical

CVE-2026-32525

JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.6.2

A vulnerability exists in JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress that allows malicious users with at least Contr…

High

CVE-2026-39479

OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.21

The OttoKit plugin for WordPress contains a security flaw in versions up to 1.1.20, allowing malicious users with elevated privileges to in…

High

CVE-2026-23807

WP Telegram Widget and Join Link [wptelegram-widget] < 2.2.14

A vulnerability exists in the WP Telegram Widget and Join Link plugin, allowing malicious actors to inject unwanted code onto vulnerable Wo…

High

CVE-2026-42646

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.45.0

The TaxoPress plugin for WordPress contains a security flaw in versions up to 3.44.0, allowing malicious users with elevated privileges to …

High

CVE-2026-32542

Fusion Builder [fusion-builder] < 3.15.0

The Avada Builder plugin, used with WordPress, contains a flaw in versions prior to 3.15.0 where input is not properly cleaned before being…

High

CVE-2026-32540

Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 26.8

The Bookly plugin for WordPress contains a security flaw that allows malicious code injection through URLs, putting users at risk of cross-…

High

CVE-2026-25317

Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 6.0.0

A security flaw exists in the Print Invoice & Delivery Notes for WooCommerce plugin, specifically due to a lack of proper authorization che…

Medium

CVE-2026-32565

Contextual Related Posts [contextual-related-posts] < 4.2.2

A security flaw exists within the Contextual Related Posts plugin, allowing malicious individuals to bypass authentication checks and execu…

Medium

CVE-2025-15363

Get Use APIs – JSON Content Importer [json-content-importer] < 2.0.10

The JSON Content Importer plugin for WordPress contains a security flaw that allows malicious users with contributor or higher permissions …

Medium

CVE-2026-42643

Image Widget [image-widget] < 4.4.12

The Image Widget plugin for WordPress is susceptible to stored cross-site scripting (XSS) attacks in versions 4.4.11 and earlier. Authentic…

Medium

CVE-2026-39464

Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.19.9

The SeedProd plugin for WordPress contains a flaw that allows malicious users with elevated permissions to trick the website into making un…

Medium

CVE-2026-32461

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.8

A security flaw exists in Really Simple Security – Simple and Performant Security plugin for WordPress, which allows users with a minimum o…

Medium

CVE-2026-22215

Comments – wpDiscuz [wpdiscuz] < 7.6.47

wpDiscuz versions prior to 7.6.47 are susceptible to a cross-site request forgery vulnerability within the getFollowsPage() function, allow…

Medium

CVE-2026-22210

Comments – wpDiscuz [wpdiscuz] < 7.6.47

A vulnerability exists in wpDiscuz versions prior to 7.6.47, which permits attackers to introduce malicious scripts via unfiltered attachme…

Medium

CVE-2026-22216

Comments – wpDiscuz [wpdiscuz] < 7.6.47

A missing security check in WordPress plugin wpDiscuz prior to version 7.6.47 enables unverified individuals to register any email address …

Medium

CVE-2026-22204

Comments – wpDiscuz [wpdiscuz] < 7.6.47

wpDiscuz versions prior to 7.6.47 are susceptible to an email header injection vulnerability. Malicious data inserted into the comment_auth…

Medium

CVE-2026-22203

Comments – wpDiscuz [wpdiscuz] < 7.6.47

A critical security flaw exists in wpDiscuz versions prior to 7.6.47, where administrators can unknowingly leak sensitive OAuth information…

Medium

CVE-2026-22202

Comments – wpDiscuz [wpdiscuz] < 7.6.47

wpDiscuz versions prior to 7.6.47 are susceptible to cross-site request forgery, enabling attackers to delete all comments linked to an ema…

High

CVE-2026-22182

Comments – wpDiscuz [wpdiscuz] < 7.6.47

A flaw in wpDiscuz versions prior to 7.6.47 allows unauthenticated users to cause a denial of service by triggering excessive notification …

Medium

CVE-2026-22191

Comments – wpDiscuz [wpdiscuz] < 7.6.47

Beghelli Sicuro24 SicuroWeb is vulnerable to a template injection flaw that lets attackers inject malicious AngularJS expressions by exploi…

Medium

CVE-2026-22183

Comments – wpDiscuz [wpdiscuz] < 7.6.47

A stored cross-site scripting vulnerability exists within the inline comment preview functionality of wpDiscuz, a plugin that allows authen…

Critical

CVE-2026-22192

Comments – wpDiscuz [wpdiscuz] < 7.6.47

Version 1.1 of the Voltronic Power SNMP Web Pro plugin has a flaw that enables unauthenticated users to exploit an authentication bypass vu…

High

CVE-2026-22193

Comments – wpDiscuz [wpdiscuz] < 7.6.47

A critical security flaw exists in earlier versions of wpDiscuz, specifically in the way it handles certain function calls. The getAllSubsc…

High

CVE-2026-22199

Comments – wpDiscuz [wpdiscuz] < 7.6.47

Voltronic Power SNMP Web Pro 1.1 has a security flaw where unauthenticated users can traverse paths via the params parameter in the upload.…

Medium

CVE-2026-22201

Comments – wpDiscuz [wpdiscuz] < 7.6.47

A flaw in wpDiscuz versions prior to 7.6.47 allows malicious users to manipulate their apparent IP address, thereby evading rate limiting m…

Medium

CVE-2026-39595

W3 Total Cache [w3-total-cache] < 2.9.2

A flaw exists in W3 Total Cache plugin for WordPress, specifically affecting versions prior to or equal to 2.9.1. In these affected iterati…

Medium

CVE-2026-39469

Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.9

The Pagelayer page builder plugin for WordPress contains a security flaw that allows authorized users with contributor privileges or higher…

Critical

CVE-2026-27071

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.8

The WPCafe plugin for WordPress has a security flaw that allows unauthorized users to bypass certain restrictions, enabling them to execute…

Medium

CVE-2026-32456

Admin Menu Editor [admin-menu-editor] < 1.15

The Admin Menu Editor plugin for WordPress, up to and including version 1.14.1, is susceptible to Cross-Site Request Forgery due to inadequ…

Medium

CVE-2026-32452

Fusion Builder [fusion-builder] < 3.15.0

A security flaw exists within the Avada Builder plugin, which allows unverified users to carry out an illicit operation without being prope…

Medium

CVE-2026-32451

Fusion Builder [fusion-builder] < 3.15.0

A security flaw exists within the Avada Builder plugin for WordPress, specifically affecting versions prior to 3.15.1. The issue stems from…

Medium

CVE-2026-32453

Fusion Core [fusion-core] < 5.15.0

A flaw exists in the Avada Core plugin, enabling unverified individuals to bypass security checks and execute an illicit operation. The iss…

Medium

CVE-2026-32454

Fusion Core [fusion-core] < 5.15.0

The Avada Core plugin for WordPress contains a security flaw affecting versions prior to 5.15.0, allowing malicious users with at least con…

Low

CVE-2026-32445

Elementor Website Builder – more than just a page builder [elementor] < 3.35.6

A security flaw exists in the Elementor Website Builder plugin for WordPress, allowing malicious users with elevated permissions to bypass …

Medium

CVE-2026-32446

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.9.4

The Contact Form by WPForms plugin has a security flaw that allows certain users with elevated permissions to bypass intended access contro…

High

CVE-2025-14675

Meta Box [meta-box] < 5.11.2

Authenticated users with contributor level permissions or higher in WordPress installations using Meta Box plugin versions 5.11.1 and earli…

Medium

CVE-2026-40730

Starter Templates & Sites Pack by ThemeGrill [themegrill-demo-importer] < 2.0.0.7

A security flaw has been identified in the ThemeGrill Demo Importer plugin for WordPress, affecting versions prior to 2.0.1. The issue stem…

High

CVE-2026-24963

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0

The Amelia plugin for WordPress, used for scheduling appointments and events, contains a vulnerability that allows authorized users with el…

High

CVE-2026-28039

wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 6.5.0.2

The wpDataTables Premium plugin for WordPress contains a security flaw that enables unverified users to inject arbitrary server-side files …

Critical

CVE-2026-27984

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.0

The Widget Options plugin has a critical vulnerability that allows malicious users with contributor or higher permissions to inject arbitra…

Medium

CVE-2026-32419

List category posts [list-category-posts] < 0.94.0

The List category posts plugin for WordPress contains a vulnerability affecting versions prior to 0.93.1, where inadequate filtering of inp…

Medium

CVE-2026-39694

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.11.1

A security flaw exists in the Simply Schedule Appointments plugin for WordPress, allowing unverified users to execute an unauthorized opera…

Medium

CVE-2025-14149

Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.25

The Xpro Addons plugin for WordPress contains a security flaw affecting all versions up to 1.4.24. Specifically, the Image Scroller widget …

High

CVE-2026-28134

JetEngine [jet-engine] < 3.8.1.2

A security flaw exists within the JetEngine plugin for WordPress, allowing malicious users with elevated permissions to inject arbitrary co…

Critical

CVE-2026-23802

AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.3.3

The AI Engine plugin for WordPress has a security flaw that allows authorized users with elevated permissions to upload any type of file wi…

Medium

CVE-2026-32416

PDF Poster – let visitors read PDFs without leaving the page [pdf-poster] < 2.4.1

A flaw exists in the PDF Poster plugin for WordPress, allowing users with contributor or higher permissions to bypass necessary security ch…

Medium

CVE-2026-32417

Pochipp [pochipp] < 1.18.9

A security flaw exists in the Pochipp plugin for WordPress, affecting users with elevated permissions. In versions prior to 1.19, a critica…

High

CVE-2026-27370

Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.5.2

The Chaty plugin for WordPress contains a flaw that allows unauthorized access to confidential user information across multiple chat platfo…

Critical

CVE-2026-27384

W3 Total Cache [w3-total-cache] < 2.9.2

A flaw exists in the input validation mechanism of BoldGrid's W3 Total Cache plugin, specifically concerning the handling of specified quan…

Critical

CVE-2026-23693

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.7.9

The ElementsKit Elementor Addons plugin for versions before 3.7.9 allows unauthenticated access to its REST endpoint /wp-json/elementskit/v…

Medium

CVE-2026-27411

SiteGuard WP Plugin [siteguard] <= 1.7.9 (unfixed)

The SiteGuard WP Plugin, up to version 1.7.9, lacks proper capability checks in certain functions, allowing unauthenticated users to execut…

Medium

CVE-2026-32409

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.50.3

A security flaw exists within the Forminator plugin for WordPress, where insufficient permission checks allow malicious individuals to exec…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.