CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2025-13737

Nextend Social Login and Register [nextend-facebook-connect] < 3.1.22

The Nextend Social Login and Register plugin for WordPress, up to version 3.1.21, is susceptible to Cross-Site Request Forgery due to inade…

Medium

CVE-2025-64295

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7

The All in One SEO plugin for WordPress contains a flaw that allows authorized users with at least Subscriber privileges to obtain confiden…

Medium

CVE-2025-12971

Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager [folders] < 3.1.6

The Folders – Unlimited Folders plugin for WordPress has a capability check flaw affecting the 'wcp_change_post_folder' function in version…

Medium

CVE-2025-67588

Elementor Website Builder – more than just a page builder [elementor] < 3.33.1

The Elementor Website Builder plugin for WordPress has a security flaw that allows authenticated users with Contributor-level access or hig…

High

CVE-2025-12684

URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.11.3

The URL Shortify plugin for WordPress has a security flaw in versions up to 1.11.2, allowing malicious actors to embed unauthorized code sn…

High

CVE-2025-13355

URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.11.4

The URL Shortify plugin for WordPress contains a security flaw in versions up to 1.11.3, allowing malicious actors to embed unauthorized co…

Medium

CVE-2025-12800

Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.6

The Shortcodes Ultimate plugin for WordPress contains a vulnerability that allows attackers with Administrator-level access and above to ma…

Medium

CVE-2025-11186

Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.5.9

The Cookie Notice & Compliance for GDPR / CCPA plugin, up to version 2.5.8, is susceptible to Stored Cross-Site Scripting attacks through t…

Medium

CVE-2025-66066

Envo Extra [envo-extra] < 1.9.12

The Envo Extra plugin for WordPress contains a security flaw in versions 1.9.11 and earlier, which allows malicious users with contributor …

Medium

CVE-2025-12935

FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution [fluent-crm] < 2.9.85

The FluentCRM plugin for WordPress contains a security flaw affecting all versions up to 2.9.84, where unsanitized input from users can be …

Medium

CVE-2026-23543

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.5.6

The Essential Addons for Elementor plugin, which provides popular templates and widgets for WordPress users, contains a security flaw affec…

Medium

CVE-2025-12359

Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.4

The Responsive Lightbox & Gallery plugin for WordPress contains a vulnerability in its 'get_image_size_by_url' function that allows malicio…

High

CVE-2025-13035

Code Snippets [code-snippets] < 3.9.2

The Code Snippets plugin for WordPress is vulnerable to a PHP code injection attack, affecting all versions up to and including 3.9.1. An a…

Medium

CVE-2025-12814

SiteSEO – SEO Simplified [siteseo] < 1.3.3

A security flaw exists in WordPress plugins of version 1.3.2 and earlier due to a faulty permission check within the siteseo_reset_settings…

Medium

CVE-2025-13085

SiteSEO – SEO Simplified [siteseo] < 1.3.3

The SiteSEO plugin for WordPress contains a flaw in its authorization checks that allows certain users with administrative privileges to ac…

Medium

CVE-2025-13031

WPeMatico RSS Feed Fetcher [wpematico] < 2.8.13

The WPeMatico RSS Feed Fetcher plugin for WordPress contains a security flaw affecting versions up to 2.8.12, which allows attackers with e…

Medium

CVE-2025-12777

YITH WooCommerce Wishlist [yith-woocommerce-wishlist] < 4.10.1

The YITH WooCommerce Wishlist plugin for WordPress contains a security flaw in versions prior to 4.10.1, which allows unauthorized users to…

Medium

CVE-2025-12427

YITH WooCommerce Wishlist [yith-woocommerce-wishlist] <= 4.10.0 (unfixed)

A vulnerability in YITH WooCommerce Wishlist plugin affects all versions up to 4.10.0, allowing unauthorized access to user-controlled keys…

Medium

CVE-2025-13054

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.14.9

The User Profile Builder plugin for WordPress contains a security flaw in its wppb-embed shortcode, allowing malicious users with contribut…

Medium

CVE-2025-11427

WP Migrate Lite – Migration Made Easy [wp-migrate-db] < 2.7.7

The WP Migrate Lite plugin for WordPress has a security flaw in versions 2.7.6 and earlier, allowing unauthorized users to secretly trigger…

Medium

CVE-2025-11734

Broken Link Checker by AIOSEO – Find & Fix Broken Internal, External & Video Links [broken-link-checker-seo] < 1.2.6

The Broken Link Checker plugin for WordPress, developed by AIOSEO, contains a flaw in its REST API functionality that permits unauthorized …

Medium

CVE-2025-11267

VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2

A WordPress plugin, VK All in One Expansion Unit, has a security flaw allowing malicious scripts to be embedded into webpage content when c…

Medium

CVE-2025-11265

VK All in One Expansion Unit [vk-all-in-one-expansion-unit] < 9.112.2

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

High

CVE-2025-12974

Gravity Forms [gravityforms] < 2.9.22

The Gravity Forms plugin for WordPress has a security flaw in its legacy chunked upload mechanism that allows unauthenticated attackers to …

High

CVE-2025-12482

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.36

The Amelia plugin for WordPress, which manages appointments and events, has a security flaw in its search function. In versions up to 1.2.3…

Medium

CVE-2025-12847

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.9.0

A vulnerability exists in the All in One SEO plugin for WordPress, affecting versions up to 4.8.9. The issue lies in the plugin's REST API …

Medium

CVE-2025-64381

Booking Calendar [booking] < 10.14.8

The Booking Calendar plugin for WordPress contains a security flaw that enables malicious users with contributor-level permissions or highe…

Medium

CVE-2025-64384

JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.4

A security flaw exists within the JetFormBuilder Dynamic Blocks Form Builder plugin for WordPress, affecting all versions prior to 3.5.4. T…

High

CVE-2025-12844

AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.1.9

The AI Engine WordPress plugin has a security flaw in its handling of untrusted input in certain functions. Specifically, versions up to 3.…

High

CVE-2025-12733

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 4.0.0

The WP All Import plugin for WordPress contains a security flaw in versions up to 3.9.6 that allows malicious users with administrative pri…

Low

CVE-2025-12954

Timetable and Event Schedule by MotoPress [mp-timetable] < 2.4.16

A vulnerability exists in Timetable and Event Schedule plugin versions prior to 2.4.15 that allows authorized users with contributor privil…

Medium

CVE-2025-12366

Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.6

The Pagelayer plugin for WordPress contains an authentication bypass vulnerability in versions up to 2.0.5, which allows authorized users w…

Medium

CVE-2025-66061

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.0

The Seriously Simple Podcasting plugin for WordPress contains a security flaw in versions 3.13.0 and earlier, allowing malicious actors to …

Medium

CVE-2025-66059

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.0

A WordPress plugin called Seriously Simple Podcasting has a security flaw that lets unauthorized users access sensitive data embedded withi…

Medium

CVE-2025-66060

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.0

A security flaw exists within the Seriously Simple Podcasting plugin for WordPress, affecting all versions prior to 3.14.0, where an essent…

Medium

CVE-2025-12177

Download Manager [download-manager] < 3.3.31

A security flaw exists in WordPress plugins due to a hardcoded Cron key embedded within the deleteExpired and clearTempDataCPCron functions…

Medium

CVE-2025-11972

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.40.1

A WordPress plugin called Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI has a critical security flaw in versions up to 3.…

Medium

CVE-2025-66056

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 6.10.0

A security flaw exists within the Uncanny Automator plugin for WordPress, affecting all iterations prior to version 6.10.1. Specifically, t…

Critical

CVE-2025-12352

Gravity Forms [gravityforms] < 2.9.21

A critical security flaw exists in Gravity Forms plugin versions up to 2.9.20, allowing unauthorized access to upload any type of file via …

Medium

CVE-2025-11271

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.5.3

A security flaw exists in Easy Digital Downloads plugin for WordPress, affecting versions up to 3.5.2. The issue arises from an oversight i…

Medium

CVE-2025-11745

Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.8.8

The Ad Inserter plugin for WordPress contains a security flaw that allows malicious code injection via custom fields within the 'adinserter…

Critical

CVE-2025-11749

AI Engine – The Chatbot, AI Framework & MCP for WordPress [ai-engine] < 3.1.4

The AI Engine plugin for WordPress has a security flaw that allows unauthorized users to obtain sensitive information through its REST API …

High

CVE-2025-12384

Document Embedder – let visitors read files without downloading [document-emberdder] < 2.0.1

The Document Embedder plugin for WordPress has a security flaw affecting all versions up to 2.0.0. The issue arises from the plugin's failu…

Medium

CVE-2025-12192

The Events Calendar [the-events-calendar] < 6.15.10

The Events Calendar plugin for WordPress has an issue in versions 6.15.9 and earlier where the sysinfo REST endpoint does not properly vali…

High

CVE-2025-12197

The Events Calendar [the-events-calendar] < 6.15.10

The Events Calendar plugin for WordPress contains a security flaw in versions 6.15.1.1 through 6.15.9, allowing malicious input to bypass n…

Medium

CVE-2025-11162

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.19.15

The Spectra Gutenberg Blocks plugin for WordPress contains a security flaw that allows malicious code injection through Custom CSS input fi…

Medium

CVE-2025-11917

WPeMatico RSS Feed Fetcher [wpematico] < 2.8.12

The WPeMatico RSS Feed Fetcher plugin for WordPress contains a flaw in its wpematico_test_feed() function that allows authenticated users w…

Medium

CVE-2025-12045

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.3

The Orbit Fox plugin, which includes features like duplicate page creation and custom fonts, is susceptible to stored cross-site scripting …

Medium

CVE-2025-12324

TablePress – Tables in WordPress made easy [tablepress] < 3.2.5

The TablePress plugin for WordPress contains a security flaw that allows malicious users with contributor privileges or higher to insert un…

Medium

CVE-2025-67535

WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters [wp-google-map-plugin] < 4.8.7

The Maps WordPress plugin contains a vulnerability that allows attackers with administrator-level access and above to inject malicious PHP …

Critical

CVE-2025-11833

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.6.1

The Post SMTP plugin, version 3.6.0 and earlier, is susceptible to unauthorized data access because it lacks proper capability checks in it…

Medium

CVE-2025-11377

List category posts [list-category-posts] < 0.93.0

A WordPress plugin called List category posts is flawed in its handling of the 'catlist' shortcode, allowing unauthorized users with contri…

Medium

CVE-2025-11502

Schema & Structured Data for WP & AMP [schema-and-structured-data-for-wp] < 1.52

The Schema & Structured Data for WP & AMP plugin contains a security flaw in its handling of user-submitted data within the 'saswp_tiny_mul…

High

CVE-2025-10487

Advanced Ads – Ad Manager & AdSense [advanced-ads] < 2.0.13

The Advanced Ads – Ad Manager & AdSense plugin for WordPress contains a security flaw in versions up to 2.0.12, allowing unauthorized acces…

Medium

CVE-2025-12367

SiteSEO – SEO Simplified [siteseo] < 1.3.2

The SiteSEO – SEO Simplified WordPress plugin has a security flaw in versions 1.3.1 and earlier, which allows unauthorized users with at le…

Medium

CVE-2025-11174

Document Library Lite [document-library-lite] < 1.1.7

The Document Library Lite plugin for WordPress contains a flaw in its authorization mechanism that affects all versions up to 1.1.6. Specif…

Medium

CVE-2025-11816

Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages [wplegalpages] < 3.5.2

A flaw exists in WP Legal Pages plugin for WordPress, affecting all versions up to 3.5.1, where an essential security check is absent from …

Medium

CVE-2025-64357

Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.7

The Advanced Database Cleaner plugin for WordPress contains a security flaw in versions 3.1.6 and earlier, allowing malicious individuals t…

Medium

CVE-2025-12175

The Events Calendar [the-events-calendar] < 6.15.10

The Events Calendar plugin for WordPress contains a security flaw that allows authorized users with at least Subscriber privileges to bypas…

Medium

CVE-2025-64358

Smart Coupons For WooCommerce Coupons [wt-smart-coupons-for-woocommerce] < 2.2.4

The Smart Coupons For WooCommerce Coupons plugin has a security flaw that allows authorized users with a level of access as low as Subscrib…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.