CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

CVE

CVE-2025-49042

WooCommerce [woocommerce] < 10.0.3

The WooCommerce plugin for WordPress is susceptible to stored cross-site scripting (XSS) attacks in versions from the earliest up to 10.0.2…

CVE

CVE-2025-64296

Meta for WooCommerce [facebook-for-woocommerce] < 3.5.8

The Facebook for WooCommerce plugin, versions 3.5.7 and earlier, lacks proper capability checks in certain functions, allowing unauthentica…

Medium

CVE-2025-11632

Call Now Button – The Free Click to Call Button for WordPress [call-now-button] < 1.5.5

A security flaw exists within the Call Now Button plugin for WordPress, allowing authenticated users with a Subscriber-level access or high…

Medium

CVE-2025-10008

Translate WordPress with Weglot – Multilingual AI Translation [weglot] < 5.2

A security flaw exists in Weglot's WordPress translation plugin, where an essential permission check is absent from its "clean_options" fun…

Medium

CVE-2025-12450

LiteSpeed Cache [litespeed-cache] < 7.6

The LiteSpeed Cache plugin for WordPress, up to version 7.5.0.1, is susceptible to Reflected Cross-Site Scripting through URLs due to inade…

Medium

CVE-2025-11587

Call Now Button – The Free Click to Call Button for WordPress [call-now-button] < 1.5.4

The Call Now Button plugin for WordPress, up to version 1.5.3, is susceptible to unauthorized data modification because it lacks proper cap…

High

CVE-2025-64353

Polylang [polylang] < 3.7.4

Authenticated users with Contributor-level access and above can inject malicious PHP objects into Polylang versions up to 3.7.3 by exploiti…

High

CVE-2025-11735

HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.2

The HUSKY – Products Filter Professional plugin for WooCommerce has a security flaw in its handling of user input, specifically the `phrase…

High

CVE-2025-64198

Easy Social Share Buttons [easy-social-share-buttons3] < 10.7.1

The Easy Social Share Buttons plugin for WordPress contains a security flaw in versions prior to 10.7.2, allowing malicious code to be embe…

Medium

CVE-2025-64354

Gutenberg [gutenberg] < 21.9.0

The Gutenberg plugin for WordPress contains a security flaw in versions 21.8.2 and earlier, allowing malicious users with at least contribu…

Medium

CVE-2025-10580

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.1.3

The Widget Options plugin, a popular choice for managing widgets and blocks on WordPress sites up to version 4.1.2, is susceptible to store…

Medium

CVE-2025-11497

Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance [advanced-database-cleaner] < 3.1.7

The Advanced Database Cleaner plugin for WordPress contains a security weakness in all versions prior to 3.1.6, specifically within the aDB…

Medium

CVE-2025-10637

Social Feed Gallery [insta-gallery] < 4.9.3

The Social Feed Gallery WordPress plugin has a security flaw in versions up to 4.9.2, allowing unauthorized access to sensitive information…

Medium

CVE-2025-11128

RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator [feedzy-rss-feeds] < 5.1.1

The Feedzy plugin for WordPress contains a flaw in its feed sanitization mechanism that allows authorized users with a certain level of acc…

Medium

CVE-2025-67554

Cookie Compliance for WordPress – Cookie Consent, GDPR & CCPA [cookie-notice] < 2.5.9

The Cookie Notice & Compliance plugin for WordPress contains a security flaw affecting versions 2.5.8 and below. The issue arises from inad…

Medium

CVE-2025-12033

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.1.0

The Simple Banner plugin, used for adding banners or notifications on WordPress websites up to version 3.0.10, is susceptible to stored cro…

Medium

CVE-2025-48086

Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.13.4

The Ajax Search Lite plugin for WordPress versions 4.13.3 and earlier is susceptible to PHP Object Injection due to improper handling of de…

High

CVE-2025-11307

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.48

The Google Maps plugin for WordPress contains a security flaw in versions up to 9.0.47, allowing malicious code injection through inadequat…

Medium

CVE-2026-28044

WP Rocket [wp-rocket] < 3.20.0.2

Authenticated users with author-level privileges or higher can inject malicious code into certain WordPress pages by exploiting a weakness …

Medium

CVE-2025-11738

Media Library Assistant [media-library-assistant] < 3.30

A vulnerability has been discovered in Media Library Assistant plugin versions prior to 3.30 that allows unauthorized users to access and v…

Medium

CVE-2025-11510

FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.5.0

The FileBird WordPress Media Library Folders & File Manager plugin has a security flaw that allows authorized users with elevated permissio…

Medium

CVE-2025-11703

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.49

The WP Go Maps plugin for WordPress has a security flaw in versions up to 9.0.48, where it doesn't properly validate data coming from users…

Medium

CVE-2025-11270

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.7.2

The Gutenberg Essential Blocks plugin contains a security flaw in its handling of the 'titleTag' attribute, allowing malicious users with c…

Medium

CVE-2025-11361

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.7.2

The Gutenberg Essential Blocks plugin for WordPress has a security flaw in versions up to 5.7.1 that allows authorized users with author pr…

High

CVE-2025-62059

SureRank SEO – Meta Tags, Social Preview, XML Sitemap, Schema & Open Graph [surerank] < 1.4.0

The SureRank plugin for WordPress is susceptible to stored cross-site scripting (XSS) attacks in versions 1.3.2 and earlier, owing to inade…

Medium

CVE-2025-62048

SmartCrawl SEO checker, analyzer & optimizer [smartcrawl-seo] < 3.14.4

A flaw exists in the SmartCrawl SEO plugin for WordPress, allowing users with Contributor privileges or higher to bypass intended security …

High

CVE-2025-62015

Advanced Coupons for WooCommerce Coupons & Store Credit [advanced-coupons-for-woocommerce-free] < 4.6.9

The Advanced Coupons for WooCommerce Coupons plugin contains a security flaw in versions 4.6.8 and earlier, where user-input data is not pr…

Medium

CVE-2025-62061

Product Catalog Simple [post-type-x] < 1.8.5

The Product Catalog Simple plugin for WordPress contains a flaw in its security checks, allowing malicious individuals to execute unintende…

Medium

CVE-2025-10700

Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.8.1

The Ally – Web Accessibility & Usability plugin for WordPress, up to version 3.8.0, is susceptible to Cross-Site Request Forgery due to ina…

Medium

CVE-2025-62951

Interactive Content – H5P [h5p] < 1.16.1

The H5P plugin for WordPress has a security flaw that allows attackers with contributor-level access or higher to inject malicious code int…

Medium

CVE-2025-58595

All In One Login — Login Page Security and Customization for WordPress with Google reCAPTCHA, Social Login, Temporary Login, 2FA, and more. [change-wp-admin-login] < 2.0.9

The All In One Login plugin, version 2.0.8, is susceptible to IP Address Spoofing because it inadequately validates IP addresses and relies…

Medium

CVE-2025-49937

Smash Balloon Social Post Feed – Simple Social Feeds for WordPress [custom-facebook-feed] < 4.3.3

The Smash Balloon Social Post Feed plugin for WordPress contains a security flaw that allows users with certain permissions to bypass inten…

Medium

CVE-2025-63065

Media Library Assistant [media-library-assistant] < 3.30

A security flaw exists in the Media Library Assistant plugin, where an attacker can bypass access controls by manipulating a user-controlle…

High

CVE-2025-48091

AnyComment [anycomment] <= 0.3.6 (unfixed)

The AnyComment plugin for WordPress is susceptible to SQL Injection in versions 0.3.6 and earlier because user input is not properly escape…

Medium

CVE-2025-10249

Slider Revolution [revslider] < 6.7.38

A security flaw exists within the Slider Revolution plugin for WordPress, affecting all versions prior to 6.7.38. Specifically, several fun…

Medium

CVE-2025-11166

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.47

The WP Go Maps plugin for WordPress has a security flaw that lets hackers trick administrators into making changes they didn't intend. This…

Medium

CVE-2026-28080

Rank Math SEO PRO [seo-by-rank-math-pro] < 3.0.97

A security flaw exists in the Rank Math SEO PRO plugin for WordPress, affecting versions prior to 3.0.97, where a critical permission check…

Medium

CVE-2025-48099

Search & Filter [search-filter] < 1.2.18

The Search & Filter plugin for WordPress contains a security flaw that allows malicious individuals to deceive administrators into carrying…

Medium

CVE-2025-63072

Cornerstone [cornerstone] <= 7.7.3 (unfixed + closed)

Authenticated users with contributor-level access or higher can inject malicious code into the Cornerstone plugin's pages by exploiting a w…

High

CVE-2025-62924

Post Grid [post-grid] < 2.3.18

In the Post Grid and Gutenberg Blocks plugin for WordPress, a critical flaw exists in certain versions that allows malicious users with ele…

CVE

CVE-2025-66058

Post Grid [post-grid] < 2.3.18

A security flaw exists in the Post Grid plugin for WordPress, affecting all versions prior to 2.3.18. The issue arises from a lack of capab…

Medium

CVE-2025-60448

Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 2.5.0

A security flaw has been identified in Emlog Pro version 2.5.19, specifically within its media management system. The issue arises from ina…

Medium

CVE-2025-10874

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.2

The Orbit Fox plugin, which includes features like duplicate page creation and SVG support, is susceptible to Server-Side Request Forgery i…

Medium

CVE-2025-60452

Responsive Lightbox & Gallery [responsive-lightbox] < 2.5.3

A security flaw has been found in MetInfo CMS version 8.0's download management system, where a malicious SVG file can be uploaded into the…

Medium

CVE-2025-49940

Fusion Builder [fusion-builder] < 3.13.3

The Fusion Builder plugin for WordPress contains a security flaw that allows malicious users with at least contributor privileges to insert…

Medium

CVE-2025-63070

Download Manager [download-manager] < 3.3.33

Authenticated users with a minimum of subscriber permissions can potentially retrieve confidential information from the Download Manager pl…

Medium

CVE-2025-11163

SmartCrawl SEO checker, analyzer & optimizer [smartcrawl-seo] < 3.14.4

The SmartCrawl SEO plugin for WordPress contains a flaw that allows authenticated users with at least Subscriber privileges to modify setti…

Medium

CVE-2025-63069

Ivory Search – WordPress Search Plugin [add-search-to-menu] < 5.5.13

A security flaw exists within the Ivory Search plugin for WordPress, where insufficient permission checks allow malicious actors to bypass …

High

CVE-2025-62022

BuddyPress [buddypress] < 14.4.0

A security flaw exists in the BuddyPress plugin for WordPress, where an essential permission verification is absent from one of its functio…

Medium

CVE-2025-60098

Theme My Login [theme-my-login] < 7.1.13

A flaw exists in the Theme My Login plugin for WordPress, allowing unverified users to bypass security checks and execute an illicit operat…

Medium

CVE-2025-60093

Download Manager [download-manager] < 3.3.25

The Download Manager plugin for WordPress contains a security flaw in versions 3.3.24 and earlier, which allows malicious actors to exploit…

Medium

CVE-2025-60092

Download Manager [download-manager] < 3.3.26

The Download Manager plugin for WordPress contains a flaw that allows unauthorized individuals to access confidential information without r…

Medium

CVE-2025-60095

Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.0

Authenticated users with contributor privileges or higher can obtain sensitive information from the Stackable – Page Builder Gutenberg Bloc…

Medium

CVE-2025-60094

Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.19.0

Authenticated users with contributor privileges or higher can exploit a security flaw in the Stackable plugin for WordPress, which affects …

Medium

CVE-2025-10037

Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8

The Featured Image from URL plugin for WordPress contains a security flaw in its get_posts_with_internal_featured_image function, affecting…

Medium

CVE-2025-10036

Featured Image from URL (FIFU) [featured-image-from-url] < 5.2.8

The Featured Image from URL plugin for WordPress contains a security flaw in its get_all_urls function, which fails to properly sanitize us…

High

CVE-2025-58592

TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.10.3

The TranslatePress plugin for WordPress contains a vulnerability in versions up to 2.10.2 that can be exploited through PHP Object Injectio…

Medium

CVE-2025-58031

Nextend Social Login and Register [nextend-facebook-connect] < 3.1.20

The Nextend Facebook Connect plugin for WordPress contains a security flaw in versions 3.1.19 and earlier, where input data is not properly…

Medium

CVE-2025-58650

All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) [all-in-one-seo-pack] < 4.8.7.2

A security flaw exists in the All In One SEO Pack plugin for WordPress due to inadequate permission checks on a specific function within ve…

Medium

CVE-2025-53459

Quads Ads Manager for Google AdSense [quick-adsense-reloaded] <= 2.0.92

A security flaw exists within the Ads by WPQuads plugin, which can be exploited to inject malicious scripts into web pages, compromising us…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.