CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2025-69300

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.64

The Premium Addons for Elementor plugin, up to version 4.11.63, is susceptible to unauthorized access because it lacks proper capability ch…

Medium

CVE-2026-24982

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.18

The Spectra Gutenberg Blocks plugin for WordPress contains a security flaw that allows unauthorized individuals to carry out certain action…

Medium

CVE-2025-12129

CubeWP Framework [cubewp-framework] < 1.1.28

The CubeWP plugin for WordPress has a security flaw that allows unauthorized access to sensitive post data. Specifically, attackers can use…

Medium

CVE-2025-12984

Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.16

The Advanced Ads – Ad Manager & AdSense plugin for WordPress has a security flaw in versions up to 2.0.15. This issue arises because user-s…

Medium

CVE-2025-12825

User Registration Using Contact Form 7 [user-registration-using-contact-form-7] < 2.6

The User Registration Using Contact Form 7 plugin has an error in its functionality. Specifically, in the 'get_cf7_form_data' function, a c…

Medium

CVE-2026-27042

NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar [notificationx] < 3.2.2

The NotificationX plugin, which includes features like FOMO notifications and WooCommerce popups, has a security flaw affecting all version…

Medium

CVE-2025-14384

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.3

A security flaw exists in All in One SEO plugin for WordPress, where a critical capability check is absent from the `/aioseo/v1/ai/credits`…

Medium

CVE-2026-25472

Fusion Builder [fusion-builder] < 3.14.2

The Avada Builder plugin for WordPress contains a security flaw affecting versions 3.14.1 and earlier, allowing malicious users with contri…

Medium

CVE-2025-14982

Booking Calendar [booking] < 10.14.12

A critical security flaw exists within the Booking Calendar plugin for WordPress, where authenticated users with minimal access privileges …

Medium

CVE-2025-15370

Shield Security – Smart Bot Blocking, Brute-Force Login Protection & File Scanning [wp-simple-firewall] < 21.0.10

A security flaw exists in Shield: Blocks Bots plugin versions prior to 21.0.9 that can be exploited by authenticated users with at least Su…

Medium

CVE-2026-24596

Related Posts Thumbnails Plugin for WordPress [related-posts-thumbnails] < 4.3.3

A security flaw exists in the Related Posts Thumbnails Plugin for WordPress, affecting versions up to 4.3.2. The issue arises from inadequa…

Medium

CVE-2025-14375

WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content [wp-rss-aggregator] < 5.0.11

The RSS Aggregator plugin for WordPress contains a security flaw affecting all versions up to 5.0.10, allowing malicious code injection thr…

High

CVE-2025-12166

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.13

The Simply Schedule Appointments Booking Plugin for WordPress contains a security flaw that allows malicious actors to inject unauthorized …

Medium

CVE-2025-69001

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.12

The Fluent Forms plugin for WordPress contains a flaw in its processing of user input, allowing malicious individuals to trigger any shortc…

Medium

CVE-2023-54332

Jetpack – WP Security, Backup, Speed, & Growth [jetpack] == 11.4

Jetpack version 11.4 has a cross-site scripting flaw in its contact form functionality that permits attackers to inject harmful code via th…

Medium

CVE-2020-36919

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] == 1.7.8

WPForms version 1.7.8 is vulnerable to cross-site scripting attacks via the slider import search functionality and tab parameter. An attack…

Medium

CVE-2026-24360

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.2

The Seriously Simple Podcasting plugin for WordPress contains a security flaw that allows malicious users with elevated permissions to init…

Medium

CVE-2026-24613

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.7

The Ecwid by Lightspeed plugin for WordPress has a security flaw in versions up to 7.0.6, which allows an attacker to access restricted fun…

Critical

CVE-2025-15030

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.15.2

The User Profile Builder plugin for WordPress contains a flaw in its authentication mechanism, allowing unauthorized users to manipulate ot…

Medium

CVE-2026-24967

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0

A security flaw has been identified in the Booking for Appointments and Events Calendar - Amelia plugin used with WordPress sites. The issu…

Medium

CVE-2025-14555

Countdown Timer – Widget Countdown [widget-countdown] < 2.7.8

The Countdown Timer – Widget Countdown plugin for WordPress contains a flaw that allows malicious users with contributor-level access or hi…

Medium

CVE-2025-13393

Featured Image from URL (FIFU) [featured-image-from-url] < 5.3.2

The Featured Image from URL plugin for WordPress contains a security flaw that allows attackers with Contributor-level access or higher to …

High

CVE-2025-14975

Custom Login Page Customizer [login-customizer] < 2.5.4

The Custom Login Page Customizer plugin in WordPress versions up to 2.5.3 is susceptible to privilege escalation through an account takeove…

Medium

CVE-2025-14720

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 2.0.0

The Amelia plugin for WordPress contains a security flaw that allows unauthorized users to bypass authentication checks when accessing cert…

Medium

CVE-2025-14146

Booking Calendar [booking] < 10.14.11

The Booking Calendar plugin for WordPress contains a vulnerability that allows unauthorized access to sensitive information. This issue aff…

High

CVE-2025-14657

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.52

The Eventin plugin for WordPress has a security flaw in all versions up to 4.0.51. This weakness allows anyone to alter the plugin's settin…

Medium

CVE-2025-14782

Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.49.2

A security flaw in the Forminator Forms plugin allows unauthorized users to bypass authentication checks and gain access to sensitive form …

Medium

CVE-2025-12640

Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.1.6

The Folders plugin for WordPress contains a security flaw that allows authorized users with elevated permissions to swap out any media file…

Medium

CVE-2025-47500

Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.6

The Stackable plugin for WordPress contains a security flaw in versions 3.19.5 and earlier, which allows malicious users with elevated perm…

Medium

CVE-2025-14275

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 3.0.2

The Jeg Elementor Kit plugin for WordPress contains a security flaw affecting all versions up to 3.0.1, which allows malicious users with a…

Medium

CVE-2025-13722

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.1.8

The Fluent Forms plugin, up to version 6.1.7, is susceptible to a missing authorization vulnerability in its `fluentform_ai_create_form` AJ…

Medium

CVE-2025-69352

The Events Calendar [the-events-calendar] < 6.15.13

The Events Calendar plugin for WordPress contains a security flaw that allows users with at least Subscriber-level privileges to execute an…

Medium

CVE-2025-69345

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.10

The Post and Page Builder by BoldGrid plugin, which includes a visual drag-and-drop editor, has a security flaw in versions up to and inclu…

Medium

CVE-2025-12067

Table Field Add-on for ACF and SCF [advanced-custom-fields-table-field] < 1.3.31

The Table Field Add-on plugin for WordPress has a security flaw affecting versions up to 1.3.30. The issue arises from inadequate handling …

High

CVE-2025-15364

Download Manager [download-manager] < 3.3.41

The Download Manager WordPress plugin has a security flaw in versions up to 3.3.40 that allows unauthorized users to modify certain account…

Medium

CVE-2025-11723

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.9.6

The Simply Schedule Appointments Booking Plugin for WordPress contains a security flaw affecting all versions up to 1.6.9.5, which allows u…

Medium

CVE-2026-24356

GetGenie – AI SEO Assistant & Content Writer with Keyword Research, AEO & GEO [getgenie] < 4.3.1

The GetGenie plugin for WordPress has a security weakness that allows users with elevated permissions to bypass intended access controls. S…

Medium

CVE-2025-14371

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.42.0

A WordPress plugin called Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI has a security flaw that allows certain users to …

Medium

CVE-2026-24636

Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform [sugar-calendar-lite] < 3.10.0

A security flaw exists within the Sugar Calendar (Lite) plugin for WordPress, where inadequate permission checks allow users with contribut…

High

CVE-2025-67923

JetEngine [jet-engine] < 3.7.8

The JetEngine plugin for WordPress contains a security flaw that allows malicious code injection through unsanitized input, which can lead …

Medium

CVE-2025-14428

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] < 2.3.4

The My Sticky Elements plugin for WordPress, specifically versions up to and including 2.3.3, is susceptible to unauthorized data loss. Aut…

Medium

CVE-2025-69092

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.4

The Essential Addons for Elementor plugin on WordPress is susceptible to Stored Cross-Site Scripting vulnerabilities up to version 6.5.3. I…

Medium

CVE-2025-14783

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.6.3

The Easy Digital Downloads plugin for WordPress contains a flaw that allows attackers to hijack redirects, compromising user security. Vers…

CVE

CVE-2025-69333

JetEngine [jet-engine] < 3.8.1.2

A security flaw exists within the JetEngine plugin for WordPress, allowing users with elevated permissions to bypass intended access contro…

High

CVE-2025-13592

Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.15

A critical security flaw has been discovered in Advanced Ads plugin for WordPress, affecting all versions up to and including 2.0.14. The i…

Medium

CVE-2025-69021

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.8

The Popup Box plugin for WordPress contains a vulnerability in versions up to 6.0.7 that allows malicious individuals to deceive administra…

High

CVE-2025-68036

CubeWP Framework [cubewp-framework] < 1.1.28

A security flaw exists within the CubeWP Framework plugin for WordPress, allowing unverified users to bypass standard access controls due t…

Medium

CVE-2025-68995

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] < 2.3.4

A security flaw exists in the My Sticky Elements plugin for WordPress, allowing users with Subscriber-level permissions or higher to execut…

Medium

CVE-2025-68997

Comments – wpDiscuz [wpdiscuz] < 7.6.44

The wpDiscuz plugin for WordPress, up to version 7.6.42, is susceptible to Insecure Direct Object Reference vulnerabilities because it lack…

Medium

CVE-2026-27368

Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode [coming-soon] < 6.19.9

The SeedProd Website Builder plugin for WordPress contains a flaw that allows unverified users to carry out an illicit operation due to the…

Medium

CVE-2025-68505

Interactive Content – H5P [h5p] < 1.16.2

A security flaw exists within the Interactive Content - H5P plugin for WordPress, where insufficient permission checks allow unverified use…

Medium

CVE-2025-68508

Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content [brave-popup-builder] < 0.8.4

A critical security flaw exists in the Brave – Create Popup plugin for WordPress, affecting all versions up to 0.8.3. The issue arises from…

Critical

CVE-2025-13773

Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.9.0

The Print Invoice & Delivery Notes for WooCommerce plugin has a security flaw that allows unauthorized access to execute arbitrary commands…

Medium

CVE-2025-15033

WooCommerce [woocommerce] < 10.4.3

A flaw in WooCommerce versions from 8.1 to 10.4.2 enables logged-in users to view order details of non-logged-in customers under specific s…

Medium

CVE-2025-14163

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.54

The Premium Addons for Elementor plugin, up to version 4.11.53, is susceptible to Cross-Site Request Forgery due to inadequate nonce valida…

Medium

CVE-2025-14155

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.11.54

The Premium Addons for Elementor plugin contains a security flaw that allows unauthorized access to sensitive data. Specifically, the 'get_…

Medium

CVE-2025-14635

Happy Addons for Elementor [happy-elementor-addons] < 3.20.4

The Happy Addons for Elementor plugin on WordPress is susceptible to Stored Cross-Site Scripting through the 'ha_page_custom_js' parameter …

Medium

CVE-2025-68589

WP Telegram Widget and Join Link [wptelegram-widget] < 2.2.13

A security flaw exists in the Telegram Widget and Join Link plugin for WordPress, where a crucial permission check is absent from certain c…

Medium

CVE-2026-24952

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.2

The Seriously Simple Podcasting plugin for WordPress contains a security flaw that allows malicious users with contributor privileges or hi…

Low

CVE-2025-12654

WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.121

The WPvivid Backup & Migration plugin for WordPress contains a flaw affecting all versions up to 0.9.120, allowing an attacker with adminis…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.