CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2025-49922

WPeMatico RSS Feed Fetcher [wpematico] < 2.8.4

The WPeMatico RSS Feed Fetcher plugin for WordPress contains a security flaw that allows users with higher than basic account permissions t…

Medium

CVE-2024-13427

Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.1

The Pagelayer plugin for WordPress contains a stored cross-site scripting vulnerability in its Button widget affecting versions up to 2.0.0…

Medium

CVE-2025-48246

The Events Calendar [the-events-calendar] < 6.12.0

The Events Calendar plugin for WordPress contains a security flaw that allows authorized users with elevated privileges to bypass normal ac…

Medium

CVE-2025-48247

PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links [pretty-link] < 3.6.16

An issue has been identified in PrettyLinks – Affiliate Links plugin that affects WordPress installations running up to version 3.6.15. The…

Critical

CVE-2025-60245

WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13

The User Manager plugin for WordPress contains a vulnerability that allows attackers with subscriber-level access and above to inject malic…

High

CVE-2025-47445

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27

A flaw exists in the way Eventin handles file paths, allowing an attacker to access files outside of their intended directory by manipulati…

Medium

CVE-2025-47437

LiteSpeed Cache [litespeed-cache] < 7.1

The LiteSpeed Cache plugin for WordPress contains a vulnerability that allows malicious users with elevated permissions to craft unauthoriz…

Medium

CVE-2025-47656

Spiraclethemes Site Library [spiraclethemes-site-library] < 1.5.5

The Spiraclethemes Site Library plugin for WordPress versions up to 1.5.4 is susceptible to stored cross-site scripting (XSS) attacks due t…

High

CVE-2025-47636

List category posts [list-category-posts] < 0.92.0

Authenticated users with contributor-level access or higher in WordPress installations running List category posts plugin versions 0.90.3 o…

Critical

CVE-2025-47688

Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.3.2

A security flaw exists in the Advanced File Manager plugin for WordPress, affecting versions prior to or equal to 5.3.1. The issue arises f…

High

CVE-2025-47439

Download Monitor [download-monitor] < 5.0.23

The Download Monitor plugin for WordPress contains a security flaw that allows authenticated users with contributor-level access or higher …

Medium

CVE-2025-47450

Simple File List [simple-file-list] < 6.1.14

A security flaw exists in the Simple File List plugin for WordPress, where an oversight has left its core setup function susceptible to tam…

Medium

CVE-2025-47506

Contextual Related Posts [contextual-related-posts] < 4.0.3

The Contextual Related Posts plugin for WordPress contains a security flaw in versions 4.0.2 and earlier, allowing malicious users with con…

Medium

CVE-2025-47604

Inline Related Posts [intelly-related-posts] < 3.9.0

The Inline Related Posts plugin for WordPress contains a security flaw in versions 3.8.0 and earlier that allows malicious users with at le…

Medium

CVE-2025-47470

AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.9.15

The GPT3 AI Content Writer plugin for WordPress contains a security flaw in versions up to 1.9.14, allowing malicious actors to exploit Cro…

Medium

CVE-2025-47471

Envo Extra [envo-extra] < 1.9.10

Authenticated users with at least subscriber-level permissions can modify a specific setting due to an oversight in capability checks withi…

CVE

CVE-2025-47539

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27

The Eventin plugin for WordPress has an issue with its import functionality, which allows anyone to bring in new users without proper verif…

Medium

CVE-2025-47691

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.4

The Ultimate Member plugin for WordPress contains a flaw in versions up to 2.10.3 that allows attackers with administrator privileges or hi…

Medium

CVE-2025-47521

Robo Gallery – Photo & Image Slider [robo-gallery] < 5.0.3

A Stored Cross-Site Scripting vulnerability exists in the Robo Gallery plugin for WordPress, affecting versions up to 5.0.2. The issue aris…

Medium

CVE-2025-47443

Countdown Timer – Widget Countdown [widget-countdown] < 2.7.5

The Widget Countdown plugin for WordPress contains a security flaw affecting versions 2.7.4 and earlier, where input data is not properly c…

Medium

CVE-2024-13858

Buddyboss Platform [buddyboss-platform] < 2.8.51

The BuddyBoss Platform plugin contains a stored cross-site scripting vulnerability in the invitee_name parameter affecting versions through…

Medium

CVE-2024-13859

Buddyboss Platform [buddyboss-platform] < 2.8.51

The Buddyboss Platform plugin for WordPress contains a stored cross-site scripting vulnerability in the 'bp_nouveau_ajax_media_save' functi…

Medium

CVE-2024-13860

Buddyboss Platform [buddyboss-platform] < 2.8.51

The Buddyboss Platform plugin for WordPress versions 2.8.50 and earlier contains a stored cross-site scripting vulnerability through the 'b…

Critical

CVE-2025-27007

OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83

The OttoKit plugin for WordPress has an issue with its create_wp_connection function in versions up to 1.0.82. The function fails to proper…

Medium

CVE-2025-46261

Seriously Simple Podcasting [seriously-simple-podcasting] < 3.10.0

The Seriously Simple Podcasting plugin for WordPress contains a security flaw affecting all versions up to 3.9.0. In these versions, the pl…

Medium

CVE-2025-39404

Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.74

The Sassy Social Share plugin for WordPress has a flaw in its handling of redirects, allowing anyone to send users to any website without n…

Medium

CVE-2025-39444

MaxButtons – Create buttons [maxbuttons] < 9.8.4

The MaxButtons plugin for WordPress contains a security flaw in versions 9.8.3 and earlier, which allows malicious users with administrator…

Medium

CVE-2025-39453

Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.5

The Advanced Dynamic Pricing for WooCommerce WordPress plugin has a security flaw that allows malicious individuals to manipulate plugin se…

High

CVE-2025-39452

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.33

Authenticated users with contributor-level access or higher can exploit a Local File Inclusion vulnerability in WPCafe plugin versions up t…

Medium

CVE-2025-39589

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10

The Essential Addons for Elementor, a popular WordPress plugin, exposes sensitive information through all versions from the earliest availa…

Medium

CVE-2025-39590

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10

The Essential Addons for Elementor plugin on WordPress is susceptible to stored cross-site scripting (XSS) attacks in versions 6.1.9 and ea…

High

CVE-2025-39584

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.26

Authenticated users with contributor-level access or higher can exploit a Local File Inclusion vulnerability in Eventin plugin versions up …

High

CVE-2026-15290

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.2

The Ultimate Member plugin for WordPress contains a security flaw in versions up to and including 2.10.1, allowing unauthenticated attacker…

Medium

CVE-2025-26870

JetEngine [jet-engine] < 3.6.5

The JetEngine plugin for WordPress contains a security flaw in versions 3.6.4.1 and earlier, which allows malicious users with contributor …

Medium

CVE-2025-32640

Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.2.0

The One Click Accessibility plugin for WordPress versions 3.1.0 and earlier is susceptible to Stored Cross-Site Scripting due to inadequate…

Medium

CVE-2025-32679

User Registration Using Contact Form 7 [user-registration-using-contact-form-7] < 2.5

Cross-Site Request Forgery (CSRF)

High

CVE-2025-32117

Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed)

A pair of WordPress plugins, Widgetize Pages Light and Widgets as Shortcodes, contain a security flaw that allows attackers to inject malic…

Medium

CVE-2024-13820

Melhor Envio [melhor-envio-cotacao] < 2.15.12

The Melhor Envio plugin for WordPress contains a sensitive information exposure flaw in versions up to 2.15.11 affecting the 'run' function…

Critical

CVE-2025-32118

CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.15

The NiteoThemes CMP plugin for WordPress has a security flaw that allows authorized users with high-level permissions to upload any type of…

Medium

CVE-2025-32195

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.1

The Ecwid Shopping Cart plugin for WordPress contains a security flaw in versions 7.0 and earlier, allowing malicious users with contributo…

Medium

CVE-2025-32134

URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.10.6

The URL Shortify plugin for WordPress contains a security flaw in versions 1.10.5.1 and earlier, allowing malicious users with elevated per…

Medium

CVE-2025-32163

Xpro Addons — 150+ Widgets for Elementor [xpro-elementor-addons] < 1.4.11

The Xpro Elementor Addons plugin for WordPress contains a security flaw in versions 1.4.10 and earlier, allowing malicious users with contr…

Medium

CVE-2025-32201

Xpro Theme Builder For Elementor – FREE [xpro-theme-builder] < 1.2.8.5

The Xpro Theme Builder For Elementor – FREE plugin has a security flaw that allows malicious users with contributor-level permissions or hi…

Medium

CVE-2025-32235

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9.5

The MP3 Audio Player – Music Player, Podcast Player & Radio plugin for WordPress has a security flaw that allows users with higher-than-Sub…

Medium

CVE-2024-13898

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5

The Simple Banner plugin for WordPress contains a stored cross-site scripting vulnerability in its admin settings affecting versions up to …

Medium

CVE-2025-31627

Media Library Assistant [media-library-assistant] < 3.25

The Media Library Assistant plugin for WordPress contains a security flaw in versions 3.24 and earlier, which can be exploited by authorize…

Medium

CVE-2025-22288

Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1

A flaw exists in Smush Image Optimization plugin for WordPress, affecting all versions prior to 3.17.1, which allows authorized users with …

Medium

CVE-2024-11180

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.4.8

The ElementsKit Elementor addons plugin for WordPress contains a stored cross-site scripting vulnerability in the Countdown Timer Widget th…

Medium

CVE-2025-30912

Float menu – awesome floating side menu [float-menu] < 6.1.3

The Float menu plugin, used for creating floating side menus in WordPress, has a Cross-Site Request Forgery vulnerability affecting all ver…

Medium

CVE-2025-30766

Happy Addons for Elementor [happy-elementor-addons] < 3.16.3

The Happy Addons for Elementor plugin on WordPress is susceptible to stored cross-site scripting (XSS) vulnerabilities up to version 3.16.2…

High

CVE-2025-30773

TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.9.7

The TranslatePress WordPress plugin contains a vulnerability that allows attackers with administrator-level access and above to inject mali…

Medium

CVE-2025-30836

Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.7

The LatePoint plugin for WordPress contains a security flaw affecting versions 5.1.6 and earlier, allowing malicious users with contributor…

High

CVE-2025-30814

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.18

The Post Grid plugin for WordPress contains a security flaw that allows attackers with contributor-level access or higher to inject arbitra…

Medium

CVE-2026-49054

The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.9.3

The Post Grid plugin for WordPress contains a security flaw that allows users with contributor-level permissions or higher to bypass intend…

High

CVE-2025-30829

WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.32

A vulnerability exists in the WPCafe plugin for WordPress, specifically in versions up to 2.2.31, where an authenticated attacker with cont…

High

CVE-2025-30855

Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 2.0.88

The WPQuads Adsense Ads plugin contains a security flaw that allows unverified users to execute an illicit operation. The problem arises fr…

Critical

CVE-2025-30876

Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 2.0.88

The WPQuads Ads plugin for WordPress contains a security flaw in versions up to 2.0.87.1, allowing malicious input to compromise database i…

Medium

CVE-2025-30914

MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.9.3

The MetForm plugin for WordPress contains a security flaw in versions up to 3.9.2 that allows malicious users with elevated privileges to i…

Medium

CVE-2024-13207

Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds [facebook-pagelike-widget] < 6.4.2

The Widget for Social Page Feeds plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions up to 6.4.1, …

High

CVE-2024-13889

WordPress Importer [wordpress-importer] < 0.8.4

The WordPress Importer plugin through version 0.8.3 allows authenticated administrators to inject arbitrary PHP objects through unsafe dese…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.