CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2024-13411

Zapier for WordPress [zapier] < 1.5.2

The Zapier for WordPress plugin contains a server-side request forgery vulnerability affecting versions 1.5.1 and earlier through its updat…

Medium

CVE-2024-13666

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 6.0.0

The Fluent Forms plugin for WordPress through version 5.2.12 contains an IP address spoofing vulnerability stemming from inadequate validat…

High

CVE-2025-26890

HUSKY – Products Filter for WooCommerce Professional [woocommerce-products-filter] < 1.3.6.5

The HUSKY – Products Filter Professional for WooCommerce plugin contains a security flaw that allows attackers with Subscriber-level permis…

High

CVE-2024-10942

All-in-One WP Migration and Backup [all-in-one-wp-migration] < 7.90

The All-in-One WP Migration and Backup plugin through version 7.89 contains a PHP Object Injection vulnerability in the 'replace_serialized…

Medium

CVE-2025-26762

WooCommerce [woocommerce] < 9.7.1

The WooCommerce plugin for WordPress is susceptible to Stored Cross-Site Scripting when used on admin settings across all versions from the…

Medium

CVE-2024-13430

Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.9

The Pagelayer page builder plugin for WordPress contains an information disclosure flaw affecting versions 1.9.8 and earlier in the pagelay…

Medium

CVE-2024-13838

Uncanny Automator – AI + Automation for WordPress | AI Agent, AI Page Builder, Free AI Usage Included [uncanny-automator] < 6.3

The Uncanny Automator plugin for WordPress versions 6.2 and earlier contains a server-side request forgery vulnerability in the 'call_webho…

Medium

CVE-2024-10144

Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22

The Robo Gallery plugin for WordPress through version 3.2.21 contains a stored cross-site scripting vulnerability in its gallery settings f…

Medium

CVE-2024-13844

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 3.1.3

The Post SMTP plugin for WordPress contains a generic SQL injection vulnerability affecting versions 3.1.2 and earlier through the 'columns…

Medium

CVE-2024-13640

Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.5.0

The Print Invoice & Delivery Notes for WooCommerce plugin through version 5.4.1 contains a sensitive information exposure vulnerability tha…

Medium

CVE-2024-13649

Xpro Addons — 150+ Widgets for Elementor [xpro-elementor-addons] < 1.4.6.8

The Xpro Addons plugin for Elementor through version 1.4.6.7 contains a stored cross-site scripting vulnerability affecting multiple widget…

Medium

CVE-2024-12743

MailPoet – Newsletters, Email Marketing, and Automation [mailpoet] < 5.5.2

The MailPoet plugin through version 5.5.1 contains a stored cross-site scripting vulnerability in its admin settings caused by inadequate s…

Medium

CVE-2024-13805

Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.3.0

The Advanced File Manager plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions up to 5.2.14 that st…

Medium

CVE-2024-13431

Simply Schedule Appointments [simply-schedule-appointments] < 1.6.8.5

The Simply Schedule Appointments plugin through version 1.6.8.3 contains a reflected cross-site scripting vulnerability in the accent_color…

CVE

CVE-2025-22623

Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.8.1

The Ad Inserter plugin for WordPress contains a security flaw affecting all versions up to 2.8.0, allowing malicious actors to introduce un…

Low

CVE-2024-12769

Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 3.0.4

The Simple Banner plugin for WordPress versions up to 3.0.3 contains a stored cross-site scripting vulnerability in its administrator setti…

Medium

CVE-2024-13384

Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.24

The Robo Gallery plugin for WordPress up to version 3.2.23 contains a stored cross-site scripting vulnerability in its admin settings due t…

High

CVE-2024-13611

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0

The Better Messages plugin for WordPress and its compatible social platforms is susceptible to unauthorized access of sensitive data in ver…

Medium

CVE-2024-13697

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.5

The Better Messages plugin for WordPress contains a Server-Side Request Forgery vulnerability affecting versions 2.7.4 and earlier through …

Medium

CVE-2024-13796

Post Grid [post-grid] < 2.3.7

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress contains a sensitive information exposure flaw affecting versions 2.3…

Medium

CVE-2025-1249

Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4.2

The Events Manager plugin for WordPress suffers from a security weakness that allows unauthorized individuals to bypass certain access cont…

Medium

CVE-2024-13402

Buddyboss Platform [buddyboss-platform] < 2.8.00

The Buddyboss Platform plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions up to 2.7.70, where the…

Medium

CVE-2024-13217

Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress [jeg-elementor-kit] < 2.6.12

The Jeg Kit for Elementor plugin prior to version 2.6.12 contains a sensitive information exposure vulnerability in the 'expired_data' and …

Medium

CVE-2024-13803

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.3.0

The Essential Blocks plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions through 5.2.3, stemming f…

Medium

CVE-2024-54444

Elementor Website Builder – more than just a page builder [elementor] < 3.25.11

The Elementor Website Builder plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions 3.25.10 and earl…

Low

CVE-2025-26977

FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.4.6

A security flaw exists in FileBird plugin versions prior to 6.4.2.1 that allows authorized users with at least author privileges to bypass …

Medium

CVE-2025-26965

Booking for Appointments and Events Calendar – Amelia [ameliabooking] < 1.2.17

The Amelia plugin for WordPress contains a security flaw that allows unauthorized access to sensitive functionality through manipulation of…

High

CVE-2025-26964

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.21

Authenticated users with contributor-level access and above in WordPress installations using Eventin plugin versions 4.0.20 and below can e…

Medium

CVE-2025-26871

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.8.4

The Essential Blocks plugin for WordPress contains a security flaw that allows users with at least contributor permissions to bypass intend…

High

CVE-2024-13869

WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.113

The WPvivid Backup & Migration plugin for WordPress contains a file upload vulnerability in versions through 0.9.112, where the upload_file…

Medium

CVE-2024-13798

Post Grid [post-grid] < 2.3.6

The Post Grid and Gutenberg Blocks – ComboBlocks plugin through version 2.3.5 contains a vulnerability that allows unauthenticated users to…

Medium

CVE-2024-13900

Head, Footer and Post Injections [header-footer] < 3.3.1

The Head, Footer and Post Injections plugin contains a PHP code injection vulnerability affecting versions 3.3.0 and earlier. Attackers wit…

High

CVE-2024-11260

Events Manager – Calendar, Bookings, Tickets, and more! [events-manager] < 6.6.4

The Events Manager plugin for WordPress versions up to 6.6.3 contains a time-based SQL injection flaw in the active_status parameter that a…

Medium

CVE-2024-12276

Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin [ultimate-member] < 2.10.0

The Ultimate Member plugin for WordPress versions up to 2.9.2 contains a second-order SQL injection vulnerability in its handling of filena…

Medium

CVE-2024-13445

Elementor Website Builder – more than just a page builder [elementor] < 3.27.5

The Elementor Website Builder plugin through version 3.27.4 contains a stored cross-site scripting vulnerability in its handling of border,…

Medium

CVE-2024-13795

Ecwid by Lightspeed Ecommerce Shopping Cart [ecwid-shopping-cart] < 6.12.28

The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress through version 6.12.27 contains a cross-site request forgery vulnerab…

Critical

CVE-2025-26763

Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider [ml-slider] < 3.95.0

The MetaSlider Image Slider Video Slider WordPress plugin has a security flaw in versions 3.94.0 and earlier that allows attackers with Edi…

Medium

CVE-2025-26758

Spotlight Social Feeds – Block, Shortcode, and Widget [spotlight-social-photo-feeds] < 1.7.2

A plugin called Spotlight Social Media Feeds, developed by RebelCode, contains a flaw that lets attackers access sensitive system data they…

Medium

CVE-2024-13227

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236

The Rank Math SEO plugin for WordPress contains a stored cross-site scripting flaw in its API functionality affecting versions up to 1.0.23…

Medium

CVE-2024-13229

Rank Math SEO – AI SEO Tools to Dominate SEO Rankings [seo-by-rank-math] < 1.0.236

The Rank Math SEO plugin for WordPress contains a vulnerability in versions up to 1.0.235 where the update_metadata() function lacks proper…

High

CVE-2024-13345

Fusion Builder [fusion-builder] < 3.11.14

The Avada Builder plugin for WordPress contains a vulnerability in versions 3.11.13 and earlier that permits unauthenticated attackers to e…

Critical

CVE-2025-22630

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.1.1

The Widget Options plugin for WordPress has a critical security flaw that allows malicious users with at least contributor privileges to in…

Medium

CVE-2024-13821

Booking Calendar [booking] < 10.10.1

The Booking Calendar plugin contains a vulnerability in versions up to 10.10 that allows unauthenticated users to modify their confirmed bo…

High

CVE-2025-24752

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.15

The Essential Addons for Elementor plugin has a security flaw affecting all versions up to 6.0.14, allowing malicious actors to inject unau…

Low

CVE-2024-10545

Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery [nextgen-gallery] < 3.59.9

The NextGEN Gallery plugin contains a stored cross-site scripting vulnerability affecting versions 3.59.8 and earlier through inadequately …

Medium

CVE-2025-22659

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.45

The Orbit Fox by ThemeIsle plugin for WordPress is susceptible to stored cross-site scripting (XSS) vulnerabilities up to version 2.10.44. …

Medium

CVE-2024-13403

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.3.2

The WPForms plugin through version 1.9.3.1 contains a stored cross-site scripting vulnerability in the fieldHTML parameter caused by inadeq…

Medium

CVE-2025-22642

Dynamic Conditions [dynamicconditions] < 1.7.5

The Dynamic Conditions plugin for WordPress contains a security flaw that allows malicious users with contributor privileges or higher to e…

Medium

CVE-2024-13699

Qi Addons For Elementor [qi-addons-for-elementor] < 1.8.8

The Qi Addons For Elementor plugin through version 1.8.7 contains a stored cross-site scripting vulnerability in the 'cursor' parameter tha…

Medium

CVE-2025-22683

NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar [notificationx] < 3.0.0

The NotificationX plugin for WordPress is susceptible to stored cross-site scripting (XSS) vulnerabilities up to version 2.9.5, as a result…

Low

CVE-2024-13585

Ajax Search Lite – Live Search & Filter [ajax-search-lite] < 4.12.5

The Ajax Search Lite – Live Search & Filter plugin contains a stored cross-site scripting vulnerability affecting versions 4.12.4 and earli…

Medium

CVE-2025-22260

Meta Tag Manager [meta-tag-manager] < 3.2

A security flaw exists within the Meta Tag Manager plugin's functionality, allowing malicious users with elevated permissions to bypass int…

Medium

CVE-2025-22686

GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.18

A security flaw exists within the CF7 Google Sheets Connector plugin for WordPress, allowing malicious individuals to bypass authentication…

Medium

CVE-2024-11829

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.2.0

The Plus Addons for Elementor plugin through version 6.1.8 contains a stored cross-site scripting vulnerability in the Table Widget's searc…

Medium

CVE-2024-13612

Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots [bp-better-messages] < 2.7.0

The Better Messages plugin for WordPress versions up to 2.6.9 contains a stored cross-site scripting vulnerability in the 'better_messages_…

Medium

CVE-2024-13157

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9.4

The MP3 Audio Player plugin for WordPress allows authenticated users with contributor permissions or higher to store malicious scripts thro…

Medium

CVE-2025-24810

Simple Image Sizes [simple-image-sizes] < 3.2.4

The Simple Image Sizes plugin for WordPress contains a security flaw that allows malicious code injection through admin settings in version…

Medium

CVE-2025-24689

Import and export users and customers [import-users-from-csv-with-meta] < 1.27.13

A flaw exists in the import function of a plugin that handles user and customer data, allowing sensitive information to be inadvertently ex…

Medium

CVE-2025-24568

Starter Templates: AI-Powered Website Templates for Elementor & Gutenberg [astra-sites] < 4.4.10

The Starter Templates plugin for WordPress, up to and including version 4.4.9, is susceptible to Cross-Site Request Forgery due to insuffic…

Medium

CVE-2025-24623

Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.2.0

The Really Simple SSL plugin for WordPress contains a security flaw in versions up to 9.1.4, allowing malicious individuals to deceive admi…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.