CVE DATABASE
WordPress Plugin CVE Database
1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.
High
CVE-2026-32399
Media Library Assistant [media-library-assistant] < 3.33
Medium
CVE-2026-25386
Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3
Medium
CVE-2026-39676
Download Manager [download-manager] < 3.3.53
Medium
CVE-2026-25385
URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.12.4
Medium
CVE-2026-25387
Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.2
Medium
CVE-2025-13842
Breadcrumb NavXT [breadcrumb-navxt] < 7.5.1
Medium
CVE-2025-14983
Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 5.0.2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Medium
CVE-2025-12500
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2
Medium
CVE-2025-13930
Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6
Medium
CVE-2025-12884
Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.15
Medium
CVE-2025-14427
Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10
Medium
CVE-2026-32386
Envo Extra [envo-extra] < 1.9.14
High
CVE-2026-0974
Orderable – Restaurant & Food Ordering System [orderable] < 1.20.1
Medium
CVE-2025-13738
Easy Table of Contents [easy-table-of-contents] < 2.0.79
Medium
CVE-2025-11185
Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.4
Medium
CVE-2025-12037
WP 404 Auto Redirect to Similar Post [wp-404-auto-redirect-to-similar-post] < 1.0.6
Medium
CVE-2025-14799
Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1
Medium
CVE-2025-11737
VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.4
CVE
CVE-2026-39659
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] <= 2.11.3 (unfixed)
High
CVE-2026-22356
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 6.7.1
High
CVE-2025-12062
WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7
Medium
CVE-2026-39647
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.12
High
CVE-2026-32358
Booking Calendar [booking] < 10.14.16
Medium
CVE-2026-32356
Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.3
High
CVE-2026-32355
JetEngine [jet-engine] < 3.8.4.1
Medium
CVE-2026-32352
Elementor Website Builder – more than just a page builder [elementor] < 3.35.6
Medium
CVE-2025-14873
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6
Critical
CVE-2026-24956
Download Manager Addons for Elementor [wpdm-elementor] < 2.0.0
High
CVE-2025-68495
JetEngine [jet-engine] < 3.8.1
Medium
CVE-2026-32343
Easy Table of Contents [easy-table-of-contents] < 2.0.81
Medium
CVE-2026-15286
Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.6.0
Medium
CVE-2026-39615
Download Manager [download-manager] < 3.3.54
Medium
CVE-2026-24953
Simple File List [simple-file-list] < 6.1.16
High
CVE-2025-67994
YayCurrency – WooCommerce Multi-Currency Switcher [yaycurrency] < 3.3.1
Medium
CVE-2026-31919
Advanced Coupons for WooCommerce – BOGO Coupons, Store Credit & WooCommerce Coupon Plugin [advanced-coupons-for-woocommerce-free] < 4.7.1.1
High
CVE-2025-15386
Responsive Lightbox & Gallery [responsive-lightbox] < 2.6.1
Medium
CVE-2026-24946
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0
Medium
CVE-2026-25024
ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.11.10
Medium
CVE-2026-25325
rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.9
Medium
CVE-2026-25420
MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.19
High
CVE-2025-67974
Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages [wplegalpages] < 3.5.5
High
CVE-2026-25316
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.0
Medium
CVE-2026-25313
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.15
Medium
CVE-2026-24539
Protección de datos – RGPD [proteccion-datos-rgpd] < 0.69
High
CVE-2025-68999
Happy Addons for Elementor [happy-elementor-addons] < 3.20.6
Medium
CVE-2025-14069
Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.54.1
Medium
CVE-2025-14745
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 5.0.11
High
CVE-2025-68047
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.4
High
CVE-2024-11976
BuddyPress [buddypress] < 14.3.4
Medium
CVE-2025-15522
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 7.0.0
High
CVE-2025-15380
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar [notificationx] < 3.2.1
Medium
CVE-2025-15043
The Events Calendar [the-events-calendar] < 6.15.13.1
Medium
CVE-2025-69315
Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.17
Critical
CVE-2025-67945
MailerLite – WooCommerce integration [woo-mailerlite] < 3.1.3
Critical
CVE-2025-14533
Advanced Custom Fields: Extended [acf-extended] < 0.9.2.2
Medium
CVE-2026-25453
Advanced iFrame [advanced-iframe] < 2026.0
Medium
CVE-2026-6742
Advanced iFrame [advanced-iframe] < 2026.2
Medium
CVE-2026-24580
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.6
Critical
CVE-2025-69312
Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.20
Medium
CVE-2026-25308
Simple Membership [simple-membership] < 4.7.0
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.