CVE DATABASE
WordPress Plugin CVE Database
1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.
High
CVE-2026-39474
Post Duplicator [post-duplicator] < 3.0.11
Critical
CVE-2026-39492
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.9.2
Critical
CVE-2026-39493
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.9.29
Medium
CVE-2025-14732
Elementor Website Builder – more than just a page builder [elementor] < 3.35.6
Medium
CVE-2026-34903
Ocean Extra [ocean-extra] < 2.5.4
CVE
CVE-2025-15611
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 5.5.0
Medium
CVE-2026-34897
Media Library Assistant [media-library-assistant] < 3.35
High
CVE-2026-34885
Media Library Assistant [media-library-assistant] < 3.35
Medium
CVE-2025-13368
Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.21
Medium
CVE-2025-15064
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.11.2
High
CVE-2026-40764
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.0.3
High
CVE-2026-34886
Simple Membership [simple-membership] < 4.7.2
Medium
CVE-2026-1710
WooPayments: Integrated WooCommerce Payments [woocommerce-payments] < 10.6.0
High
CVE-2026-45214
Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.5.2
Medium
CVE-2026-39508
Advanced Coupons for WooCommerce Coupons & Store Credit [advanced-coupons-for-woocommerce-free] < 4.7.2
Medium
CVE-2026-39477
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.4
Medium
CVE-2026-42648
Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.23
Medium
CVE-2026-39501
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6
High
CVE-2026-39466
Broken Link Checker [broken-link-checker] < 2.4.8
High
CVE-2026-39495
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.9.29
Medium
CVE-2026-39488
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments [surecart] < 4.0.3
Medium
CVE-2026-39505
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.3
High
CVE-2026-39486
Download Monitor [download-monitor] < 5.1.9
High
CVE-2026-39487
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.1.2
Medium
CVE-2026-25339
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.9.2
Medium
CVE-2026-32533
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.7
Medium
CVE-2026-39483
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.113.4
High
CVE-2026-39497
FOX – Currency Switcher Professional for WooCommerce [woocommerce-currency-switcher] < 1.4.6
Critical
CVE-2026-32525
JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.6.2
High
CVE-2026-39479
OttoKit: All-in-One Automation Platform [suretriggers] < 1.1.21
High
CVE-2026-23807
WP Telegram Widget and Join Link [wptelegram-widget] < 2.2.14
High
CVE-2026-42646
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.45.0
High
CVE-2026-32542
Fusion Builder [fusion-builder] < 3.15.0
High
CVE-2026-32540
Online Scheduling and Appointment Booking System – Bookly [bookly-responsive-appointment-booking-tool] < 26.8
High
CVE-2026-25317
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 6.0.0
Medium
CVE-2026-32565
Contextual Related Posts [contextual-related-posts] < 4.2.2
Medium
CVE-2025-15363
Get Use APIs – JSON Content Importer [json-content-importer] < 2.0.10
Medium
CVE-2026-42643
Image Widget [image-widget] < 4.4.12
Medium
CVE-2026-39464
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.19.9
Medium
CVE-2026-32461
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.8
Medium
CVE-2026-22215
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22210
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22209
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22216
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22204
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22203
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22202
Comments – wpDiscuz [wpdiscuz] < 7.6.47
High
CVE-2026-22182
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22191
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22183
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Critical
CVE-2026-22192
Comments – wpDiscuz [wpdiscuz] < 7.6.47
High
CVE-2026-22193
Comments – wpDiscuz [wpdiscuz] < 7.6.47
High
CVE-2026-22199
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-22201
Comments – wpDiscuz [wpdiscuz] < 7.6.47
Medium
CVE-2026-39595
W3 Total Cache [w3-total-cache] < 2.9.2
Medium
CVE-2026-39469
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.9
Critical
CVE-2026-27071
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 3.0.8
Medium
CVE-2026-32456
Admin Menu Editor [admin-menu-editor] < 1.15
Medium
CVE-2026-32452
Fusion Builder [fusion-builder] < 3.15.0
Medium
CVE-2026-32451
Fusion Builder [fusion-builder] < 3.15.0
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.