CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2025-24720

Sticky Buttons – Floating Buttons Builder [sticky-buttons] < 4.1.2

The Sticky Buttons WordPress plugin, up to version 4.1.1, is susceptible to Cross-Site Request Forgery due to inadequate nonce validation i…

Medium

CVE-2025-24738

Call Now Button – The Free Click to Call Button for WordPress [call-now-button] < 1.4.14

The Call Now Button plugin, version 1.4.13 and earlier, is susceptible to Cross-Site Request Forgery due to inadequate nonce validation in …

Medium

CVE-2025-24746

Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3

The Popup Maker plugin for WordPress is susceptible to stored cross-site scripting (XSS) attacks in versions 1.20.2 and earlier, as it fail…

Medium

CVE-2025-24713

Button Generator – Easily Create Custom Buttons with Icons and Analytics [button-generation] < 3.1.2

The Button Generator - easily Button Builder plugin for WordPress contains a security flaw in versions up to 3.1.1, allowing malicious acto…

Medium

CVE-2025-24753

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.3.2

The Kadence WP – Page Builder Features plugin's Gutenberg Blocks with AI functionality has a security flaw that allows users with contribut…

Medium

CVE-2025-24736

Post Duplicator [post-duplicator] < 2.36

A security flaw exists within the Post Duplicator plugin for WordPress, where a critical oversight has been identified in its authorization…

Medium

CVE-2025-24742

WP Go Maps – Google Map, OpenStreetMap, Leaflet Map [wp-google-maps] < 9.0.41

The WP Go Maps plugin for WordPress contains a security flaw in versions 9.0.40 and earlier, allowing malicious actors to exploit Cross-Sit…

Medium

CVE-2025-24644

WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels [print-invoices-packing-slip-labels-for-woocommerce] < 4.7.2

A stored cross-site scripting vulnerability exists within the WooCommerce PDF Invoices plugin for WordPress, affecting all versions up to 4…

Medium

CVE-2025-24573

Page Builder: Pagelayer – Drag and Drop website builder [pagelayer] < 1.9.5

The PageLayer plugin for WordPress contains a security flaw in versions 1.9.4 and earlier, where input validation is inadequate, allowing m…

Medium

CVE-2025-24662

LearnDash LMS [sfwd-lms] < 4.20.0.3

A security flaw exists within the LearnDash LMS plugin's functionality, allowing malicious users without proper authorization to execute ce…

Medium

CVE-2025-24719

Countdown Timer – Widget Countdown [widget-countdown] < 2.7.2

The Widget Countdown plugin for WordPress contains a security flaw that allows malicious users with contributor permissions or higher to em…

Medium

CVE-2024-12477

Fusion Builder [fusion-builder] < 3.11.12

The Fusion Builder plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions 3.11.11 and earlier due to …

Medium

CVE-2024-12118

The Events Calendar [the-events-calendar] < 6.9.1

The Events Calendar plugin for WordPress contains a stored cross-site scripting vulnerability in the Event Calendar Link Widget that affect…

Medium

CVE-2024-13361

AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97

The AI Power: Complete AI Pack WordPress plugin through version 1.8.96 contains a capability check vulnerability in the wpaicg_save_image_m…

Medium

CVE-2024-13360

AI Puffer – Chat. Create. Automate. (formerly AI Power) [gpt3-ai-content-generator] < 1.8.97

The AI Power: Complete AI Pack WordPress plugin contains a server-side request forgery vulnerability in the wpaicg_troubleshoot_add_vector(…

Medium

CVE-2024-12117

Stackable – Page Builder Gutenberg Blocks [stackable-ultimate-gutenberg-blocks] < 3.13.12

The Stackable Page Builder Gutenberg Blocks plugin contains a stored cross-site scripting vulnerability affecting versions up to 3.13.11 in…

Medium

CVE-2024-13230

Social Share, Social Login and Social Comments Plugin – Super Socializer [super-socializer] < 7.14.1

The Super Socializer plugin for WordPress contains a limited SQL injection vulnerability affecting versions 7.14 and earlier through the 'S…

Medium

CVE-2026-11798

Social Share, Social Login and Social Comments Plugin – Super Socializer [super-socializer] <= 7.14.5 (unfixed)

The Super Socializer plugin for WordPress contains a security flaw in versions 7.14.5 and earlier, allowing malicious code injection throug…

Medium

CVE-2024-13126

Download Manager [download-manager] < 3.3.07

The Download Manager plugin for WordPress through version 3.3.06 fails to properly restrict access to the directory containing uploaded dow…

Medium

CVE-2024-13517

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3

The Easy Digital Downloads plugin versions 3.3.2 and earlier contains a stored cross-site scripting vulnerability in the Title field caused…

High

CVE-2024-13333

Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.14

The Advanced File Manager plugin contains a file upload vulnerability in versions 5.2.12 to 5.2.13 affecting the 'fma_local_file_system' fu…

High

CVE-2024-13377

Gravity Forms [gravityforms] < 2.9.2

The Gravity Forms plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions 2.9.1.3 and earlier through …

Medium

CVE-2024-13378

Gravity Forms [gravityforms] < 2.9.2

The Gravity Forms plugin contains a stored cross-site scripting vulnerability in versions 2.9.0.1 through 2.9.1.3 affecting the 'style_sett…

Medium

CVE-2025-22722

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.0.9

The Widget Options plugin for WordPress is susceptible to unauthorized data modification because it lacks proper capability checks in the w…

Medium

CVE-2025-22759

Post and Page Builder by BoldGrid – Visual Drag and Drop Editor [post-and-page-builder] < 1.27.6

The Post and Page Builder by BoldGrid plugin, versions 1.27.5 and earlier, is susceptible to stored cross-site scripting (XSS) attacks due …

Medium

CVE-2024-10775

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.33

The Piotnet Addons For Elementor plugin contains an information disclosure vulnerability affecting versions 2.4.32 and earlier through the …

Low

CVE-2024-12767

Buddyboss Platform [buddyboss-platform] < 2.7.60

The BuddyBoss Platform plugin for WordPress contains an Insecure Direct Object Reference vulnerability affecting versions below 2.7.60, cau…

Medium

CVE-2024-13215

Addon Elements for Elementor (formerly Elementor Addon Elements) [addon-elements-for-elementor-page-builder] < 1.14

The Addon Elements for Elementor plugin contains a sensitive information disclosure vulnerability affecting versions 1.13.10 and earlier. A…

Medium

CVE-2024-12240

Page Builder by SiteOrigin [siteorigin-panels] < 2.31.1

The Page Builder by SiteOrigin plugin contains a stored cross-site scripting vulnerability in versions 2.31.0 and earlier through improper …

Medium

CVE-2024-13323

Booking Calendar [booking] < 10.9.3

The Booking Calendar plugin for WordPress contains a stored cross-site scripting vulnerability in its booking shortcode affecting versions …

Medium

CVE-2024-12008

W3 Total Cache [w3-total-cache] < 2.8.2

The W3 Total Cache plugin before version 2.8.2 contains an information disclosure flaw where debug log files are publicly accessible withou…

Medium

CVE-2024-12006

W3 Total Cache [w3-total-cache] < 2.8.2

The W3 Total Cache WordPress plugin through version 2.8.1 contains a flaw where certain functions lack proper permission validation, allowi…

High

CVE-2024-12365

W3 Total Cache [w3-total-cache] < 2.8.2

W3 Total Cache versions 2.8.1 and earlier contain a capability check vulnerability in the is_w3tc_admin_page function that allows authentic…

Medium

CVE-2024-12304

Kadence Blocks — Page Builder Toolkit for Gutenberg Editor [kadence-blocks] < 3.4.3

The Kadence Blocks plugin for WordPress contains a stored cross-site scripting vulnerability in its button block link functionality affecti…

Medium

CVE-2024-12472

Post Duplicator [post-duplicator] < 2.37

The Post Duplicator plugin for WordPress contains an information disclosure flaw in versions 2.36 and earlier within the mtphr_duplicate_po…

Medium

CVE-2024-13183

Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More [themeisle-companion] < 2.10.44

The Orbit Fox plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions up to 2.10.43, where the 'title_…

Medium

CVE-2025-24537

The Events Calendar [the-events-calendar] < 6.7.1

The Events Calendar plugin for WordPress contains a security flaw in versions up to 6.7.0, which allows unauthorized individuals to manipul…

Medium

CVE-2025-22800

Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App [post-smtp] < 2.9.12

The Post SMTP plugin for WordPress is susceptible to unauthorized access in versions from 2.9.11 and earlier, as a capability check was omi…

Medium

CVE-2024-12852

Happy Addons for Elementor [happy-elementor-addons] < 3.15.2

The Happy Addons for Elementor plugin contains a stored cross-site scripting vulnerability in the Happy Mouse Cursor feature affecting vers…

Medium

CVE-2024-12584

Xpro Addons — 150+ Widgets for Elementor [xpro-elementor-addons] < 1.4.6.3

The Xpro Addons plugin for Elementor containing over 140 widgets is affected by a sensitive data exposure flaw in versions 1.4.6.2 and earl…

Medium

CVE-2024-12045

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 5.1.1

The Essential Blocks plugin for WordPress contains a stored cross-site scripting vulnerability in the Google Maps block's maker title field…

High

CVE-2024-11465

Custom Product Tabs for WooCommerce [yikes-inc-easy-custom-woocommerce-product-tabs] < 1.8.6

The Custom Product Tabs for WooCommerce plugin is susceptible to PHP Object Injection through deserialization of unverified data in the 'yi…

Medium

CVE-2024-12738

User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor [profile-builder] < 3.13.0

The User Profile Builder plugin for WordPress versions up to 3.12.9 contains a stored cross-site scripting vulnerability affecting multiple…

Medium

CVE-2024-12624

Sina Extension for Elementor [sina-extension-for-elementor] < 3.6.0

The Sina Extension for Elementor plugin contains a stored cross-site scripting vulnerability in its Sina Image Differ widget affecting vers…

High

CVE-2025-24632

Advanced Dynamic Pricing and Discount Rules for WooCommerce [advanced-dynamic-pricing-for-woocommerce] < 4.9.1

The Advanced Dynamic Pricing for WooCommerce plugin for WordPress has a security flaw that allows attackers to inject malicious code into w…

Medium

CVE-2024-56273

WPvivid — Backup, Migration & Staging [wpvivid-backuprestore] < 0.9.107

The WPvivid Backup and Migration plugin for WordPress contains a capability verification gap in the handle_auth_actions() function that aff…

Medium

CVE-2024-56276

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.2.3

The WPForms plugin for WordPress up through version 1.9.2.2 contains a vulnerability where a function lacks proper capability verification.…

High

CVE-2024-10957

UpdraftPlus: WP Backup & Migration Plugin [updraftplus] < 1.24.12

The UpdraftPlus: WP Backup & Migration Plugin for WordPress contains a PHP Object Injection flaw affecting versions 1.23.8 through 1.24.11 …

Medium

CVE-2024-11974

Media Library Assistant [media-library-assistant] < 3.24

The Media Library Assistant plugin contains a reflected cross-site scripting vulnerability in versions 3.23 and earlier through the smc_set…

Medium

CVE-2025-22333

Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.32

The Piotnet Addons For Elementor plugin contains a security flaw in its Heading widget, allowing malicious users with contributor-level acc…

Medium

CVE-2025-24628

reCaptcha by BestWebSoft [google-captcha] < 1.79

A security flaw exists in the BestWebSoft reCaptcha plugin for WordPress, allowing unauthorized users to circumvent CAPTCHA checks across a…

Medium

CVE-2024-56279

Compact WP Audio Player [compact-wp-audio-player] < 1.9.15

The Compact WP Audio Player plugin for WordPress contains a server-side request forgery vulnerability affecting versions 1.9.14 and earlier…

Medium

CVE-2024-56266

MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar [mp3-music-player-by-sonaar] < 5.9

The MP3 Audio Player plugin for WordPress contains a capability check vulnerability affecting versions 5.8 and earlier, where authenticated…

Medium

CVE-2024-12335

Fusion Builder [fusion-builder] < 3.11.13

The Fusion Builder plugin for WordPress contains an information disclosure vulnerability affecting versions 3.11.12 and earlier through the…

Medium

CVE-2024-12636

Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages [wplegalpages] < 3.2.8

The WP Legal Pages plugin through version 3.2.6 contains a cross-site request forgery vulnerability in the popup deletion functionality cau…

Medium

CVE-2024-12034

Advanced Google reCAPTCHA [advanced-google-recaptcha] < 1.26

The Advanced Google reCAPTCHA plugin for WordPress before version 1.26 contains a weakness in its IP blocking mechanism that allows unauthe…

Medium

CVE-2024-12210

Print Invoice & Delivery Notes for WooCommerce [woocommerce-delivery-notes] < 5.4.1

The Print Invoice & Delivery Notes for WooCommerce plugin through version 5.4.0 contains a vulnerability where the 'wcdn_remove_shoplogo' A…

Medium

CVE-2024-11230

Ultimate Addons for Elementor – Widgets, Templates, WooCommerce & Header Footer Builder [header-footer-elementor] < 1.6.47

The Elementor Header & Footer Builder plugin contains a stored cross-site scripting vulnerability in the 'size' parameter affecting version…

Medium

CVE-2024-10453

Elementor Website Builder – more than just a page builder [elementor] < 3.25.10

The Elementor Website Builder plugin for WordPress contains a stored cross-site scripting vulnerability in its Typography Settings affectin…

Medium

CVE-2024-51915

LiteSpeed Cache [litespeed-cache] < 6.5.3

The LiteSpeed Cache plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions prior to 6.5.3, stemming f…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.