CVE DATABASE
WordPress Plugin CVE Database
1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.
Medium
CVE-2026-32453
Fusion Core [fusion-core] < 5.15.0
Medium
CVE-2026-32454
Fusion Core [fusion-core] < 5.15.0
Low
CVE-2026-32445
Elementor Website Builder – more than just a page builder [elementor] < 3.35.6
Medium
CVE-2026-32446
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.9.4
High
CVE-2025-14675
Meta Box [meta-box] < 5.11.2
Medium
CVE-2026-40730
Starter Templates & Sites Pack by ThemeGrill [themegrill-demo-importer] < 2.0.0.7
High
CVE-2026-24963
Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0
High
CVE-2026-28039
wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin [wpdatatables] < 6.5.0.2
Critical
CVE-2026-27984
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.2.0
Medium
CVE-2026-32419
List category posts [list-category-posts] < 0.94.0
Medium
CVE-2026-39694
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin [simply-schedule-appointments] < 1.6.11.1
Medium
CVE-2025-14149
Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.25
High
CVE-2026-28134
JetEngine [jet-engine] < 3.8.1.2
Critical
CVE-2026-23802
AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.3.3
Medium
CVE-2026-32416
PDF Poster – Display PDF Files with Custom Viewer [pdf-poster] < 2.4.1
Medium
CVE-2026-32417
Pochipp [pochipp] < 1.18.9
High
CVE-2026-27370
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty [chaty] < 3.5.2
Critical
CVE-2026-27384
W3 Total Cache [w3-total-cache] < 2.9.2
Critical
CVE-2026-23693
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.7.9
Medium
CVE-2026-27411
SiteGuard WP Plugin [siteguard] <= 1.7.9 (unfixed)
Medium
CVE-2026-32409
Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.50.3
High
CVE-2026-32399
Media Library Assistant [media-library-assistant] < 3.33
Medium
CVE-2026-25386
Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3
Medium
CVE-2026-39676
Download Manager [download-manager] < 3.3.53
Medium
CVE-2026-25385
URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.12.4
Medium
CVE-2026-25387
Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.2
Medium
CVE-2025-13842
Breadcrumb NavXT [breadcrumb-navxt] < 7.5.1
Medium
CVE-2025-14983
Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 5.0.2
Medium
CVE-2025-12500
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2
Medium
CVE-2025-13930
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6
Medium
CVE-2025-12884
Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.15
Medium
CVE-2025-14427
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10
Medium
CVE-2026-32386
Envo Extra [envo-extra] < 1.9.14
High
CVE-2026-0974
Orderable – Restaurant & Food Ordering System [orderable] < 1.20.1
Medium
CVE-2025-13738
Easy Table of Contents [easy-table-of-contents] < 2.0.79
Medium
CVE-2025-11185
Complianz – GDPR/CCPA Cookie Consent [complianz-gdpr] < 7.4.4
Medium
CVE-2025-12037
WP 404 Auto Redirect to Similar Post [wp-404-auto-redirect-to-similar-post] < 1.0.6
Medium
CVE-2025-14799
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1
Medium
CVE-2025-11737
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.4
CVE
CVE-2026-39659
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] <= 2.11.3 (unfixed)
High
CVE-2026-22356
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 6.7.1
High
CVE-2025-12062
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7
Medium
CVE-2026-39647
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.12
High
CVE-2026-32358
Booking Calendar [booking] < 10.14.16
Medium
CVE-2026-32356
Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.3
High
CVE-2026-32355
JetEngine [jet-engine] < 3.8.4.1
Medium
CVE-2026-32352
Elementor Website Builder – more than just a page builder [elementor] < 3.35.6
Medium
CVE-2025-14873
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6
Medium
CVE-2019-25314
Yoast Duplicate Post [duplicate-post] < 3.2.4
Critical
CVE-2026-24956
Download Manager Addons for Elementor [wpdm-elementor] < 2.0.0
High
CVE-2025-68495
JetEngine [jet-engine] < 3.8.1
Medium
CVE-2026-32343
Easy Table of Contents [easy-table-of-contents] < 2.0.81
Medium
CVE-2026-39615
Download Manager [download-manager] < 3.3.54
Medium
CVE-2026-24953
Simple File List [simple-file-list] < 6.1.16
High
CVE-2025-67994
YayCurrency – WooCommerce Multi-Currency Switcher [yaycurrency] < 3.3.1
Medium
CVE-2026-31919
Advanced Coupons for WooCommerce Coupons & Store Credit [advanced-coupons-for-woocommerce-free] < 4.7.1.1
High
CVE-2025-15386
Responsive Lightbox & Gallery [responsive-lightbox] < 2.6.1
Medium
CVE-2026-24946
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0
Medium
CVE-2026-25024
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.11.10
Medium
CVE-2026-25325
rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.9
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.