CVE DATABASE
WordPress Plugin CVE Database
1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.
Medium
CVE-2025-49922
WPeMatico RSS Feed Fetcher [wpematico] < 2.8.4
Medium
CVE-2024-13427
Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 2.0.1
Medium
CVE-2025-48246
The Events Calendar [the-events-calendar] < 6.12.0
Medium
CVE-2025-48247
PrettyLinks – Affiliate Link Management, URL Shortener, Link Cloaking, Tracking & Branded Short Links [pretty-link] < 3.6.16
Critical
CVE-2025-60245
WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13
High
CVE-2025-47445
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27
Medium
CVE-2025-47437
LiteSpeed Cache [litespeed-cache] < 7.1
Medium
CVE-2025-47656
Spiraclethemes Site Library [spiraclethemes-site-library] < 1.5.5
High
CVE-2025-47636
List category posts [list-category-posts] < 0.92.0
Critical
CVE-2025-47688
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.3.2
High
CVE-2025-47439
Download Monitor [download-monitor] < 5.0.23
Medium
CVE-2025-47450
Simple File List [simple-file-list] < 6.1.14
Medium
CVE-2025-47506
Contextual Related Posts [contextual-related-posts] < 4.0.3
Medium
CVE-2025-47604
Inline Related Posts [intelly-related-posts] < 3.9.0
Medium
CVE-2025-47470
AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.9.15
Medium
CVE-2025-47471
Envo Extra [envo-extra] < 1.9.10
CVE
CVE-2025-47539
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.27
Medium
CVE-2025-47691
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.4
Medium
CVE-2025-47521
Robo Gallery – Photo & Image Slider [robo-gallery] < 5.0.3
Medium
CVE-2025-47443
Countdown Timer – Widget Countdown [widget-countdown] < 2.7.5
Medium
CVE-2024-13858
Buddyboss Platform [buddyboss-platform] < 2.8.51
Medium
CVE-2024-13859
Buddyboss Platform [buddyboss-platform] < 2.8.51
Medium
CVE-2024-13860
Buddyboss Platform [buddyboss-platform] < 2.8.51
Critical
CVE-2025-27007
OttoKit: All-in-One Automation Platform [suretriggers] < 1.0.83
Medium
CVE-2025-46261
Seriously Simple Podcasting [seriously-simple-podcasting] < 3.10.0
Medium
CVE-2025-39404
Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.74
Medium
CVE-2025-39444
MaxButtons – Create buttons [maxbuttons] < 9.8.4
Medium
CVE-2025-39453
Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.5
High
CVE-2025-39452
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.33
Medium
CVE-2025-39589
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10
Medium
CVE-2025-39590
Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.1.10
High
CVE-2025-39584
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.26
High
CVE-2026-15290
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.2
Medium
CVE-2025-26870
JetEngine [jet-engine] < 3.6.5
Medium
CVE-2025-32640
Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.2.0
Medium
CVE-2025-32679
User Registration Using Contact Form 7 [user-registration-using-contact-form-7] < 2.5
Cross-Site Request Forgery (CSRF)
High
CVE-2025-32117
Widgetize Pages Light [widgetize-pages-light] <= 3.0 (unfixed + closed)
Medium
CVE-2024-13820
Melhor Envio [melhor-envio-cotacao] < 2.15.12
Critical
CVE-2025-32118
CMP – Coming Soon & Maintenance Plugin by NiteoThemes [cmp-coming-soon-maintenance] < 4.1.15
Medium
CVE-2025-32195
Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 7.0.1
Medium
CVE-2025-32134
URL Shortify – Simple and Easy URL Shortener [url-shortify] < 1.10.6
Medium
CVE-2025-32163
Xpro Addons — 150+ Widgets for Elementor [xpro-elementor-addons] < 1.4.11
Medium
CVE-2025-32201
Xpro Theme Builder For Elementor – FREE [xpro-theme-builder] < 1.2.8.5
Medium
CVE-2025-32235
MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9.5
Medium
CVE-2024-13898
Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.5
Medium
CVE-2025-31627
Media Library Assistant [media-library-assistant] < 3.25
Medium
CVE-2025-22288
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN [wp-smushit] < 3.17.1
Medium
CVE-2024-11180
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.4.8
Medium
CVE-2025-30912
Float menu – awesome floating side menu [float-menu] < 6.1.3
Medium
CVE-2025-30766
Happy Addons for Elementor [happy-elementor-addons] < 3.16.3
High
CVE-2025-30773
TranslatePress – Translate Multilingual sites with AI Translation [translatepress-multilingual] < 2.9.7
Medium
CVE-2025-30836
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress [latepoint] < 5.1.7
High
CVE-2025-30814
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.7.18
Medium
CVE-2026-49054
The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid [the-post-grid] < 7.9.3
High
CVE-2025-30829
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System [wp-cafe] < 2.2.32
High
CVE-2025-30855
Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 2.0.88
Critical
CVE-2025-30876
Quads Ads Manager for Google AdSense [quick-adsense-reloaded] < 2.0.88
Medium
CVE-2025-30914
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.9.3
Medium
CVE-2024-13207
Buttonizer – Social Media Share Buttons, Social Icons, & Social Feeds [facebook-pagelike-widget] < 6.4.2
High
CVE-2024-13889
WordPress Importer [wordpress-importer] < 0.8.4
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.