CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

High

CVE-2026-32399

Media Library Assistant [media-library-assistant] < 3.33

The Media Library Assistant plugin for WordPress contains a security flaw in versions prior to 3.33, allowing malicious users with contribu…

Medium

CVE-2026-25386

Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3

The Ally plugin for WordPress has a security flaw that allows unauthenticated users to execute unauthorized actions because the necessary c…

Medium

CVE-2026-39676

Download Manager [download-manager] < 3.3.53

A security flaw exists in the Download Manager plugin for WordPress, allowing malicious individuals without authentication to execute an un…

Medium

CVE-2026-25385

URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.12.4

The URL Shortify plugin for WordPress contains a flaw in versions prior to 1.12.4 that allows authorized users with elevated permissions to…

Medium

CVE-2026-25387

Image Optimization – Compress Images and Convert to WebP or AVIF [image-optimization] < 1.7.2

Authenticated users with access levels of at least subscriber can exploit a security flaw in the Image Optimizer by Elementor plugin for Wo…

Medium

CVE-2025-13842

Breadcrumb NavXT [breadcrumb-navxt] < 7.5.1

The Breadcrumb NavXT plugin versions 7.5.0 and earlier are susceptible to an authorization bypass vulnerability when user-controlled input …

Medium

CVE-2025-14983

Advanced Custom Fields: Font Awesome Field [advanced-custom-fields-font-awesome] < 5.0.2

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Medium

CVE-2025-12500

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.2

The Checkout Field Manager plugin for WooCommerce has a security flaw in versions 7.8.1 and earlier that allows unauthorized users to uploa…

Medium

CVE-2025-13930

Checkout Field Manager (Checkout Manager) for WooCommerce [woocommerce-checkout-manager] < 7.8.6

The WooCommerce Checkout Field Manager plugin has a security issue affecting versions up to 7.8.5, allowing unauthorized users to remove fi…

Medium

CVE-2025-12884

Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.15

The Advanced Ads – Ad Manager & AdSense plugin for WordPress contains a security flaw that allows unauthorized users to manipulate ad place…

Medium

CVE-2025-14427

Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10

A security flaw exists within the Shield Security plugin for WordPress, affecting versions up to 21.0.9. Specifically, an omission of capab…

Medium

CVE-2026-32386

Envo Extra [envo-extra] < 1.9.14

A security flaw exists in the Envo Extra plugin for WordPress, where a critical oversight in permission checks allows users with elevated r…

High

CVE-2026-0974

Orderable – Restaurant & Food Ordering System [orderable] < 1.20.1

The Orderable plugin for WordPress lacks a crucial permission check in its installation process, allowing users with minimal privileges or …

Medium

CVE-2025-13738

Easy Table of Contents [easy-table-of-contents] < 2.0.79

The Easy Table of Contents plugin for WordPress contains a security flaw that allows malicious code injection through the `ez-toc` shortcod…

Medium

CVE-2025-11185

Complianz GDPR/CCPA Cookie Consent Banner [complianz-gdpr] < 7.4.4

The Complianz plugin for WordPress has a security flaw in its cmplz-accept-link shortcode, which allows malicious users with sufficient per…

Medium

CVE-2025-12037

WP 404 Auto Redirect to Similar Post [wp-404-auto-redirect-to-similar-post] < 1.0.6

A WordPress plugin, WP 404 Auto Redirect to Similar Post, contains a security flaw that allows attackers to inject malicious code into the …

Medium

CVE-2025-14799

Brevo – Email, SMS, Web Push, Chat, and more. [mailin] < 3.3.1

A security flaw exists in the Brevo plugin for WordPress, affecting versions up to 3.3.0. The issue arises from a comparison function used …

Medium

CVE-2025-11737

VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.4

The VK All in One Expansion Unit plugin contains a security flaw affecting all versions up to 9.112.3, which allows malicious users with co…

CVE

CVE-2026-39659

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] <= 2.11.3 (unfixed)

A security flaw exists in the Ultimate Member plugin for WordPress, where insufficient permission checks allow unauthorized individuals to …

High

CVE-2026-22356

Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation [zero-bs-crm] < 6.7.1

The Jetpack CRM plugin for WordPress is susceptible to Local File Inclusion vulnerabilities up to version 6.7.0, enabling unauthenticated a…

High

CVE-2025-12062

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7

The WP Maps plugin for WordPress contains a security flaw that allows attackers with Subscriber-level access or higher to inject arbitrary …

Medium

CVE-2026-39647

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.12

The MP3 Audio Player plugin for WordPress has a security flaw that allows unauthorized users to initiate external network connections, pote…

High

CVE-2026-32358

Booking Calendar [booking] < 10.14.16

The Booking Calendar plugin for WordPress contains a security flaw in versions up to 10.14.15, allowing malicious users with at least edito…

Medium

CVE-2026-32356

Robo Gallery – Photo & Image Slider [robo-gallery] < 5.1.3

The Robo Gallery plugin for WordPress contains a security flaw in versions up to 5.1.2, allowing malicious users with contributor or higher…

High

CVE-2026-32355

JetEngine [jet-engine] < 3.8.4.1

A security flaw exists in JetEngine for WordPress versions prior to 3.8.4.1, allowing a contributor-level user and above to inject maliciou…

Medium

CVE-2026-32352

Elementor Website Builder – more than just a page builder [elementor] < 3.35.6

The Elementor Website Builder plugin for WordPress has a stored cross-site scripting vulnerability in versions 3.35.5 and earlier, caused b…

Medium

CVE-2025-14873

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.2.6

The LatePoint plugin for WordPress, used for scheduling appointments and events, has a security weakness in its routing system that affects…

Critical

CVE-2026-24956

Download Manager Addons for Elementor [wpdm-elementor] < 2.0.0

The Elementor Download Manager Addons plugin for WordPress has a security flaw in versions 1.3.0 and earlier, allowing malicious input to d…

High

CVE-2025-68495

JetEngine [jet-engine] < 3.8.1

The JetEngine plugin for WordPress contains a security flaw affecting versions 3.8.0 and earlier, which allows malicious code injection via…

Medium

CVE-2026-32343

Easy Table of Contents [easy-table-of-contents] < 2.0.81

The Easy Table of Contents plugin for WordPress contains a security flaw in versions up to 2.0.80, which allows malicious individuals to in…

Medium

CVE-2026-15286

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.6.0

A WordPress plugin called Gutenberg Blocks with AI by Kadence WP contains a security flaw that allows attackers with at least Contributor-l…

Medium

CVE-2026-39615

Download Manager [download-manager] < 3.3.54

The Download Manager plugin for WordPress contains a security flaw in versions 3.3.53 and earlier, which allows malicious users with elevat…

Medium

CVE-2026-24953

Simple File List [simple-file-list] < 6.1.16

A security flaw exists within the Simple File List plugin for WordPress, affecting versions prior to 6.1.16, allowing authorized users with…

High

CVE-2025-67994

YayCurrency – WooCommerce Multi-Currency Switcher [yaycurrency] < 3.3.1

A security flaw exists in the YayCurrency – WooCommerce Multi-Currency Switcher plugin for WordPress, allowing unauthorized access to modif…

Medium

CVE-2026-31919

Advanced Coupons for WooCommerce – BOGO Coupons, Store Credit & WooCommerce Coupon Plugin [advanced-coupons-for-woocommerce-free] < 4.7.1.1

A vulnerability exists in the Advanced Coupons for WooCommerce Coupons plugin for WordPress, where insufficient permission checks allow use…

High

CVE-2025-15386

Responsive Lightbox & Gallery [responsive-lightbox] < 2.6.1

The Responsive Lightbox & Gallery plugin for WordPress contains a security flaw affecting versions prior to 2.6.1, where inadequate filteri…

Medium

CVE-2026-24946

Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0

A security flaw exists in the Print Invoice & Delivery Notes for WooCommerce plugin, specifically in its access control mechanism, which ca…

Medium

CVE-2026-25024

ThirstyAffiliates – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin [thirstyaffiliates] < 3.11.10

The ThirstyAffiliates plugin for WordPress has a security weakness in versions up to 3.11.9, allowing malicious individuals to manipulate t…

Medium

CVE-2026-25325

rtMedia for WordPress, BuddyPress and bbPress [buddypress-media] < 4.7.9

A security flaw exists in the rtCamp rtMedia plugin for WordPress, which also supports BuddyPress and bbPress integrations. This vulnerabil…

Medium

CVE-2026-25420

MailerLite – Signup forms (official) [official-mailerlite-sign-up-forms] < 1.7.19

A security flaw exists in the MailerLite – Signup forms (official) plugin for WordPress due to inadequate permission checks on a specific f…

High

CVE-2025-67974

Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages [wplegalpages] < 3.5.5

A security flaw exists in the WP Legal Pages plugin for WordPress, affecting all versions prior to 3.5.4. The issue arises from a lack of c…

High

CVE-2026-25316

CartFlows – Funnel Builder & Checkout Plugin for WooCommerce [cartflows] < 2.2.0

The CartFlows plugin for WooCommerce has a security flaw that allows attackers with administrator-level access to inject malicious PHP obje…

Medium

CVE-2026-25313

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.15

The Fluent Forms plugin, used for creating various types of forms on WordPress sites, has a security flaw where missing capability checks i…

Medium

CVE-2026-24539

Protección de datos – RGPD [proteccion-datos-rgpd] < 0.69

A security flaw exists within the Protección de datos – RGPD plugin for WordPress, allowing malicious individuals to bypass authentication …

High

CVE-2025-68999

Happy Addons for Elementor [happy-elementor-addons] < 3.20.6

The Happy Addons for Elementor plugin has a SQL Injection vulnerability in versions 3.20.4 and earlier, caused by inadequate escaping of us…

Medium

CVE-2025-14069

Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.54.1

The Schema & Structured Data for WP & AMP plugin contains a security flaw in its handling of custom schema fields. In versions 1.54 and ear…

Medium

CVE-2025-14745

WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 5.0.11

A WordPress plugin used for aggregating news feeds has a security flaw that allows malicious users with sufficient privileges to embed exec…

High

CVE-2025-68047

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.1.4

The Eventin WordPress plugin suffers from a PHP object injection flaw affecting versions 4.1.3 and earlier due to insecure deserialization …

High

CVE-2024-11976

BuddyPress [buddypress] < 14.3.4

BuddyPress versions before 14.3.4 contain a vulnerability allowing unauthenticated attackers to execute arbitrary shortcodes. The plugin fa…

Medium

CVE-2025-15522

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 7.0.0

A security flaw exists in WordPress plugins up to version 6.10.0.2 due to inadequate filtering of certain input parameters. Specifically, t…

High

CVE-2025-15380

NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar [notificationx] < 3.2.1

The NotificationX plugin for WordPress contains a security flaw affecting all versions up to 3.2.0, allowing attackers to inject malicious …

Medium

CVE-2025-15043

The Events Calendar [the-events-calendar] < 6.15.13.1

The Events Calendar plugin for WordPress has a security flaw that allows unauthorized users with at least subscriber-level access to manipu…

Medium

CVE-2025-69315

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.17

A security flaw exists in the Appointment Booking Calendar - Simply Schedule Appointments Booking Plugin, affecting WordPress installations…

Critical

CVE-2025-67945

MailerLite – WooCommerce integration [woo-mailerlite] < 3.1.3

The MailerLite – WooCommerce integration plugin for WordPress contains a flaw in versions up to 3.1.2, allowing malicious input to be injec…

Critical

CVE-2025-14533

Advanced Custom Fields: Extended [acf-extended] < 0.9.2.2

A flaw in Advanced Custom Fields: Extended plugin for WordPress allows unauthorized users to register with elevated permissions, specifical…

Medium

CVE-2026-25453

Advanced iFrame [advanced-iframe] < 2026.0

The Advanced iFrame plugin for WordPress contains a security flaw that allows malicious users with contributor privileges or higher to embe…

Medium

CVE-2026-6742

Advanced iFrame [advanced-iframe] < 2026.2

The Advanced iFrame plugin for WordPress contains a security flaw that allows malicious users with contributor-level access or higher to in…

Medium

CVE-2026-24580

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.6

In the Ecwid Shopping Cart plugin for WordPress, a critical oversight has been discovered in versions prior to 7.0.6, where an essential se…

Critical

CVE-2025-69312

Xpro Addons — 140+ Widgets for Elementor [xpro-elementor-addons] < 1.4.20

The Xpro Addons plugin for WordPress contains a security flaw that allows authorized users with elevated permissions to bypass normal file …

Medium

CVE-2026-25308

Simple Membership [simple-membership] < 4.7.0

A flaw in the Simple Membership plugin for WordPress allows users with Subscriber-level permissions or higher to execute an illicit operati…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.