CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2025-49938

JetEngine [jet-engine] < 3.7.4

The JetEngine plugin for WordPress contains a security flaw affecting versions 3.7.3 and earlier, which allows authorized users with at lea…

Low

CVE-2025-64352

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.3.0

The Essential Addons for Elementor plugin, which includes popular Elementor templates and widgets, has a security flaw affecting all versio…

Medium

CVE-2025-64351

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.253

A security flaw exists within the Rank Math SEO plugin for WordPress, affecting all versions prior to 1.0.252.2, allowing authorized users …

Low

CVE-2025-64350

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.253

A security flaw exists in Rank Math SEO plugin for WordPress, where a critical oversight in capability checks has been identified within th…

High

CVE-2025-10001

WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets [wp-all-import] < 3.9.4

The Import any XML, CSV or Excel File plugin for WordPress has a security flaw in its import feature that allows malicious users with admin…

Medium

CVE-2025-58805

Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed)

A vulnerability exists in the Widgetize Pages Light plugin for WordPress, affecting versions up to 3.0, where insufficient input validation…

Medium

CVE-2025-58799

Custom WooCommerce Checkout Fields Editor [add-fields-to-checkout-page-woocommerce] <= 1.3.4 (unfixed)

The Custom WooCommerce Checkout Fields Editor plugin for WordPress contains a vulnerability that allows an attacker to trick an administrat…

Medium

CVE-2025-58593

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 3.0.1

The Orbit Fox plugin by ThemeIsle, versions up to 3.0.0, is susceptible to stored cross-site scripting (XSS) due to inadequate input saniti…

Medium

CVE-2025-58602

If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.9.4.1

The If-So Dynamic Content Personalization plugin for WordPress contains a security flaw that allows malicious users with contributor-level …

High

CVE-2025-60077

YayPricing – WooCommerce Dynamic Pricing & Discounts [yaypricing] < 3.5.4

A security flaw exists in the YayPricing plugin for WordPress, allowing malicious individuals to bypass authentication checks when accessin…

Medium

CVE-2026-28131

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.14.5

Authenticated users with contributor privileges or higher can obtain confidential user information or plugin settings from the Addon Elemen…

Medium

CVE-2025-58195

Xpro Addons — 150+ Widgets for Elementor [xpro-elementor-addons] < 1.4.18

The Xpro Elementor Addons plugin for WordPress contains a security flaw in versions up to 1.4.17, allowing malicious users with sufficient …

Medium

CVE-2025-58198

Xpro Theme Builder For Elementor – FREE [xpro-theme-builder] < 1.2.10

The Xpro Theme Builder For Elementor – FREE plugin has a security flaw that allows certain users to bypass standard permissions in WordPres…

Medium

CVE-2025-58193

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 6.8.0

A flaw exists in the Uncanny Automator plugin for WordPress, allowing users with Subscriber-level access or higher to execute a specific fu…

High

CVE-2025-54735

CubeWP Framework [cubewp-framework] < 1.1.25

The CubeWP – All-in-One Dynamic Content Framework WordPress plugin contains a security flaw in versions 1.1.24 and earlier, allowing malici…

Medium

CVE-2025-55716

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.15.2

An issue has been discovered in WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin for WordPress that affects plugin functi…

Medium

CVE-2025-55712

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.3.14

The Elementor Addons plugin has a security flaw that allows users with at least Contributor permissions to bypass intended restrictions on …

Medium

CVE-2025-55710

Tag, Category, and Taxonomy Manager – Autotagger Automatically Add Terms [simple-tags] < 3.37.3

The Tag, Category, and Taxonomy Manager – AI Autotagger plugin for WordPress has a flaw that allows unauthorized access to sensitive user i…

High

CVE-2025-49869

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.32

The Eventin WordPress plugin contains a vulnerability that allows attackers with contributor-level access and above to inject malicious PHP…

Low

CVE-2025-54940

Advanced Custom Fields (ACF®) [advanced-custom-fields] < 6.4.3

The Advanced Custom Fields (ACF) plugin for WordPress has a vulnerability that allows HTML injection in all versions up to 6.4.2. Due to in…

High

CVE-2025-54007

Post Grid [post-grid] < 2.3.12

The Post Grid and Gutenberg Blocks WordPress plugin contains a vulnerability that allows authenticated users with contributor-level access …

Medium

CVE-2025-49923

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.12.0

The Seriously Simple Podcasting plugin for WordPress contains a security flaw in versions up to 3.11.1, which can be exploited by authorize…

High

CVE-2025-52737

WP Store Locator [wp-store-locator] < 2.2.261

A vulnerability exists in WordPress plugins utilizing the Store Locator functionality. Specifically, versions 2.2.260 and below are suscept…

Medium

CVE-2025-54706

Magical Posts Display – Elementor Advanced Posts widgets [magical-posts-display] < 1.2.53

The Magical Posts Display plugin for WordPress contains a security flaw affecting versions 1.2.52 and earlier, where inadequate filtering o…

Medium

CVE-2025-54688

JetEngine [jet-engine] < 3.7.2

The JetEngine plugin for WordPress contains a security flaw in versions 3.7.1.2 and earlier, allowing malicious users with at least contrib…

High

CVE-2025-54021

Simple File List [simple-file-list] < 6.1.15

A security flaw has been identified in Simple File List plugin for WordPress, affecting all versions prior to 6.1.15. The issue allows unau…

Medium

CVE-2025-52712

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9

The Post and Page Builder by BoldGrid plugin, which includes a visual drag-and-drop editor for WordPress, is susceptible to path traversal …

High

CVE-2025-24000

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.3.0

The Post SMTP plugin, version 3.2.0 and earlier, is susceptible to privilege escalation through account takeover due to insufficient capabi…

Medium

CVE-2025-53196

JetEngine [jet-engine] < 3.7.1.1

Authenticated users with at least Subscriber privileges can extract confidential information from JetEngine plugin settings across all affe…

High

CVE-2025-53990

JetFormBuilder — Dynamic Blocks Form Builder [jetformbuilder] < 3.5.2

The JetFormBuilder WordPress plugin has a security flaw that allows attackers with admin access and higher to inject malicious PHP objects …

High

CVE-2025-53194

JetEngine [jet-engine] < 3.7.1.1

A security flaw exists in JetEngine, a WordPress plugin, where Server-Side Template Injection (SSTI) can be exploited by users with contrib…

High

CVE-2025-60240

AnyComment [anycomment] <= 0.3.6 (unfixed)

The AnyComment plugin for WordPress is susceptible to Local File Inclusion vulnerabilities up to version 0.3.6. Attackers without authentic…

CVE

CVE-2025-34085

Simple File List [simple-file-list] < 4.2.3

The vulnerability report with the identifier CVE-2025-34085 was cancelled due to duplication, being an exact match for another identified i…

Medium

CVE-2025-49884

Internal Linking of Related Contents [internal-linking-of-related-contents] < 1.1.9

A security flaw exists within the Internal Linking of Related Contents plugin for WordPress, where a critical oversight has been made in th…

Medium

CVE-2024-11937

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.70

The Premium Addons for Elementor plugin is susceptible to stored cross-site scripting through the linkURL parameter in its Mobile Menu elem…

Medium

CVE-2024-5647

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Medium

CVE-2025-53253

WP Edit [wp-edit] <= 4.0.4 (unfixed)

The WP Edit plugin for WordPress contains a security flaw that allows malicious code injection through authenticated administrators on affe…

Medium

CVE-2025-53262

Writesonic [writesonic] < 1.0.6

The Writesonic plugin for WordPress contains a security weakness that allows malicious individuals to deceive administrators into executing…

Medium

CVE-2025-53195

JetEngine [jet-engine] < 3.7.1.1

The JetEngine plugin for WordPress contains a security flaw in versions 3.7.0 and earlier, allowing malicious users with at least contribut…

Medium

CVE-2025-49321

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.29

The Eventin plugin for WordPress contains a security flaw that allows malicious actors to inject unauthorized code into the website's pages…

Medium

CVE-2024-50555

Elementor Website Builder – more than just a page builder [elementor] < 3.29.1

The Elementor Website Builder plugin for WordPress contains a stored cross-site scripting vulnerability in versions 3.29.0 and earlier that…

Medium

CVE-2025-52707

Firelight Lightbox [easy-fancybox] < 2.3.17

The Firelight Lightbox plugin for WordPress is susceptible to stored cross-site scripting (XSS) vulnerabilities up to version 2.3.16, as a …

Medium

CVE-2025-52711

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9

The BoldGrid Post and Page Builder plugin, used in WordPress sites, has a security weakness that allows malicious individuals to deceive ad…

Medium

CVE-2025-52713

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.9

The Post and Page Builder by BoldGrid plugin, up to version 1.27.8, is susceptible to Server-Side Request Forgery vulnerabilities for users…

High

CVE-2025-52708

HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.7.1

Authenticated users with contributor-level access or higher can exploit a flaw in HUSKY plugin versions up to 1.3.7, allowing them to inclu…

Medium

CVE-2025-50010

Zapier for WordPress [zapier] < 1.5.3

A security flaw exists within the Zapier for WordPress plugin, affecting all versions prior to 1.5.3. The issue stems from a lack of capabi…

High

CVE-2025-49331

eCommerce Product Catalog [ecommerce-product-catalog] < 3.4.4

The eCommerce Product Catalog plugin for WordPress contains a flaw that allows attackers with elevated access to inject malicious PHP objec…

Medium

CVE-2025-49882

CubeWP Framework [cubewp-framework] < 1.1.24

The CubeWP Framework plugin for WordPress contains a security flaw in versions 1.1.23 and earlier, allowing malicious users with contributo…

Medium

CVE-2025-49875

If-So Dynamic Content – Elementor & All Page Builders Personalization [if-so] < 1.9.3.2

The If-So Dynamic Content Personalization plugin for WordPress contains a security flaw that allows malicious users with contributor privil…

Medium

CVE-2025-62882

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.14.0

A flaw exists in the Seriously Simple Podcasting plugin for WordPress, allowing users with subscriber-level access or higher to execute a s…

Medium

CVE-2025-49239

Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.6.0

The Print Invoice & Delivery Notes for WooCommerce plugin has a security flaw in all versions up to 5.5.0, allowing malicious individuals t…

Medium

CVE-2025-49305

Product Catalog Simple [post-type-x] < 1.8.2

The Product Catalog Simple plugin for WordPress contains a security flaw in versions 1.8.1 and earlier, allowing malicious users with contr…

Medium

CVE-2025-49292

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.13.9

A vulnerability has been discovered in the User Profile Builder plugin for WordPress, affecting versions prior to 3.14. The issue allows an…

High

CVE-2025-30999

External Store for Shopify [wp-shopify] < 1.6.0

The WP Shopify plugin for WordPress contains a security flaw that allows attackers with contributor-level access and above to inject arbitr…

Medium

CVE-2025-49333

Simple Membership [simple-membership] < 4.6.4

The Simple Membership plugin for WordPress contains a security flaw affecting versions up to 4.6.3, which allows malicious users with eleva…

Medium

CVE-2025-49262

Sina Extension for Elementor [sina-extension-for-elementor] < 3.7.0

The Sina Extension for Elementor plugin on WordPress contains a security flaw in versions 3.6.1 and earlier, which can be exploited by auth…

Medium

CVE-2025-49244

Shortcodes Ultimate – Content Elements [shortcodes-ultimate] < 7.4.0

The Shortcodes Ultimate plugin for WordPress contains a security flaw in versions 7.3.5 and earlier, allowing malicious users with at least…

Medium

CVE-2025-49068

Ocean Extra [ocean-extra] < 2.4.9

The Ocean Extra plugin for WordPress is susceptible to stored cross-site scripting (XSS) attacks across all versions up to 2.4.8. Insuffici…

Critical

CVE-2025-48133

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 6.5.0

The Uncanny Automator plugin for WordPress contains a security flaw that allows unauthorized users to execute certain actions without prope…

Medium

CVE-2025-49076

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.8

The Plus Addons for Elementor Page Builder Lite plugin's security has been compromised by a critical flaw in versions 6.2.7 and earlier. Th…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.