CVE DATABASE
WordPress Plugin CVE Database
1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.
Medium
CVE-2025-49938
JetEngine [jet-engine] < 3.7.4
Low
CVE-2025-64352
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.3.0
Medium
CVE-2025-64351
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.253
Low
CVE-2025-64350
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.253
High
CVE-2025-10001
WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.4
Medium
CVE-2025-58805
Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed)
Medium
CVE-2025-58799
Custom WooCommerce Checkout Fields Editor [add-fields-to-checkout-page-woocommerce] <= 1.3.4 (unfixed)
Medium
CVE-2025-58593
Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.1
Medium
CVE-2025-58602
If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.9.4.1
High
CVE-2025-60077
YayPricing – WooCommerce Dynamic Pricing & Discounts [yaypricing] < 3.5.4
Medium
CVE-2026-28131
Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.14.5
Medium
CVE-2025-58195
Xpro Addons — 150+ Widgets for Elementor [xpro-elementor-addons] < 1.4.18
Medium
CVE-2025-58198
Xpro Theme Builder For Elementor – FREE [xpro-theme-builder] < 1.2.10
Medium
CVE-2025-58193
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 6.8.0
High
CVE-2025-54735
CubeWP Framework [cubewp-framework] < 1.1.25
Medium
CVE-2025-55716
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.15.2
Medium
CVE-2025-55712
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.14
Medium
CVE-2025-55710
Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.37.3
High
CVE-2025-49869
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.32
Low
CVE-2025-54940
Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3
High
CVE-2025-54007
Post Grid [post-grid] < 2.3.12
Medium
CVE-2025-49923
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.12.0
High
CVE-2025-52737
WP Store Locator [wp-store-locator] < 2.2.261
Medium
CVE-2025-54706
Magical Posts Display – Elementor Advanced Posts widgets [magical-posts-display] < 1.2.53
Medium
CVE-2025-54688
JetEngine [jet-engine] < 3.7.2
High
CVE-2025-54021
Simple File List [simple-file-list] < 6.1.15
Medium
CVE-2025-52712
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9
High
CVE-2025-24000
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0
Medium
CVE-2025-53196
JetEngine [jet-engine] < 3.7.1.1
High
CVE-2025-53990
JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.2
High
CVE-2025-53194
JetEngine [jet-engine] < 3.7.1.1
High
CVE-2025-60240
AnyComment [anycomment] <= 0.3.6 (unfixed)
CVE
CVE-2025-34085
Simple File List [simple-file-list] < 4.2.3
Medium
CVE-2025-49884
Internal Linking of Related Contents [internal-linking-of-related-contents] < 1.1.9
Medium
CVE-2024-11937
Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.70
Medium
CVE-2024-5647
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.5
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Medium
CVE-2025-53253
WP Edit [wp-edit] <= 4.0.4 (unfixed)
Medium
CVE-2025-53262
Writesonic [writesonic] < 1.0.6
Medium
CVE-2025-53195
JetEngine [jet-engine] < 3.7.1.1
Medium
CVE-2025-49321
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.29
Medium
CVE-2024-50555
Elementor Website Builder – more than just a page builder [elementor] < 3.29.1
Medium
CVE-2025-52707
Firelight Lightbox [easy-fancybox] < 2.3.17
Medium
CVE-2025-52711
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9
Medium
CVE-2025-52713
Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9
High
CVE-2025-52708
HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.1
Medium
CVE-2025-50010
Zapier for WordPress [zapier] < 1.5.3
High
CVE-2025-49331
eCommerce Product Catalog [ecommerce-product-catalog] < 3.4.4
Medium
CVE-2025-49882
CubeWP Framework [cubewp-framework] < 1.1.24
Medium
CVE-2025-49875
If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.9.3.2
Medium
CVE-2025-62882
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.0
Medium
CVE-2025-49239
Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.6.0
Medium
CVE-2025-49305
Product Catalog Simple [post-type-x] < 1.8.2
Medium
CVE-2025-49292
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.13.9
High
CVE-2025-30999
External Store for Shopify [wp-shopify] < 1.6.0
Medium
CVE-2025-49333
Simple Membership [simple-membership] < 4.6.4
Medium
CVE-2025-49262
Sina Extension for Elementor [sina-extension-for-elementor] < 3.7.0
Medium
CVE-2025-49244
Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.0
Medium
CVE-2025-49068
Ocean Extra [ocean-extra] < 2.4.9
Critical
CVE-2025-48133
Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 6.5.0
Medium
CVE-2025-49076
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.8
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.