CVE DATABASE

WordPress Plugin CVE Database

1000 known WordPress plugin CVEs, checked against WP Clinic's local security database.

Medium

CVE-2024-12875

Easy Digital Downloads – eCommerce Payments and Subscriptions made easy [easy-digital-downloads] < 3.3.3

The Easy Digital Downloads plugin before version 3.3.3 contains a directory traversal vulnerability in its file download functionality that…

High

CVE-2024-12771

eCommerce Product Catalog [ecommerce-product-catalog] < 3.3.44

The eCommerce Product Catalog Plugin for WordPress through version 3.3.43 contains a cross-site request forgery vulnerability in the custom…

Medium

CVE-2024-56225

Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.57

The Premium Addons for Elementor plugin contains a capability check vulnerability affecting versions 4.10.56 and earlier that allows authen…

Medium

CVE-2024-56219

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.0.8

The Widget Options plugin for WordPress contains a flaw in the widgetopts_save_widget_editor_cache() function that fails to properly verify…

Medium

CVE-2024-56217

Download Manager [download-manager] < 3.3.04

The Download Manager plugin contains a capability check deficiency that exposes a function to unauthorized use. Attackers who are authentic…

Medium

CVE-2024-56213

Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce [wp-event-solution] < 4.0.9

The Eventin event management plugin for WordPress contains a local file inclusion vulnerability affecting versions through 4.0.7 that allow…

Medium

CVE-2024-56063

Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 6.0.8

The Essential Addons for Elementor plugin contains a stored cross-site scripting vulnerability affecting versions 6.0.7 and earlier, caused…

High

CVE-2024-11740

Download Manager [download-manager] < 3.3.04

The Download Manager plugin for WordPress through version 3.3.03 contains a vulnerability that permits unauthenticated attackers to execute…

Medium

CVE-2024-11768

Download Manager [download-manager] < 3.3.04

The Download Manager plugin for WordPress contains a flaw in its checkFilePassword function that fails to properly validate passwords, affe…

Medium

CVE-2024-12454

Affiliate Program Suite — SliceWP Affiliates [slicewp] < 1.1.24

The SliceWP Affiliates plugin for WordPress versions up to 1.1.23 contains a cross-site request forgery vulnerability resulting from inadeq…

Low

CVE-2024-10102

Robo Gallery – Photo & Image Slider [robo-gallery] < 3.2.22

The Robo Gallery plugin for WordPress versions up to 3.2.21 contains a stored cross-site scripting vulnerability in the gallery settings fu…

Medium

CVE-2024-12061

Events Addon for Elementor [events-addon-for-elementor] < 2.2.4

The Events Addon for Elementor plugin contains an information disclosure vulnerability affecting versions 2.2.3 and earlier through the nae…

High

CVE-2024-12293

User Role Editor [user-role-editor] < 4.64.4

The User Role Editor plugin through version 4.64.3 contains a cross-site request forgery vulnerability stemming from inadequate nonce verif…

Medium

CVE-2024-11849

Pods - Custom Content Types and Fields [pods] < 3.2.8.1

The Pods plugin for WordPress contains a stored cross-site scripting vulnerability in its admin settings affecting versions up to 3.2.8. At…

High

CVE-2024-10646

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder [fluentform] < 5.2.7

The Fluent Forms contact form plugin for WordPress contains a stored cross-site scripting vulnerability in the form subject parameter affec…

Medium

CVE-2024-12309

Rate My Post – Star Rating Plugin by FeedbackWP [rate-my-post] < 4.2.5

The Rate My Post – Star Rating Plugin by FeedbackWP contains an insecure direct object reference vulnerability in versions 4.2.4 and earlie…

Medium

CVE-2024-11727

NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar [notificationx] < 2.9.4

The NotificationX plugin through version 2.9.3 contains a stored cross-site scripting vulnerability in its notification content settings ca…

Medium

CVE-2024-10583

Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.20.3

The Popup Maker plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions through 1.20.2, where the 'pos…

Medium

CVE-2024-54300

AutoWP – AI Content Writer & Rewriter [autowp-ai-content-writer-rewriter] < 2.0.9

The AutoWP plugin contains a cross-site request forgery vulnerability affecting versions 2.0.8 and earlier, stemming from inadequate nonce …

Medium

CVE-2024-54315

Events Addon for Elementor [events-addon-for-elementor] < 2.2.3

The Events Addon for Elementor plugin contains a stored cross-site scripting vulnerability affecting versions 2.2.2 and earlier. Attackers …

Medium

CVE-2024-12263

Child Theme Creator by Orbisius [orbisius-child-theme-creator] < 1.5.6 (closed)

The Child Theme Creator by Orbisius plugin was vulnerable to unauthorized data manipulation in versions up to 1.5.5 because the cloud_delet…

Medium

CVE-2024-54268

SiteOrigin Widgets Bundle [so-widgets-bundle] < 1.64.1

The SiteOrigin Widgets Bundle plugin for WordPress contains a capability check vulnerability in all versions through 1.64.0 that allows aut…

Medium

CVE-2024-11205

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] >= 1.8.4 - < 1.9.2.2

The WPForms plugin contains a capability verification gap in the 'wpforms_is_admin_page' function that permits authenticated users with min…

Medium

CVE-2023-51360

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns [essential-blocks] < 4.2.1

The Essential Blocks plugin for WordPress contained a broken access control flaw in versions before 4.2.1 that allowed unauthenticated or l…

High

CVE-2024-11010

FileOrganizer – WordPress File Manager [fileorganizer] < 1.1.5

The FileOrganizer – Manage WordPress and Website Files plugin through version 1.1.4 contains a local JavaScript file inclusion vulnerabilit…

Medium

CVE-2024-11223

WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.9.2.3

The WPForms plugin for WordPress prior to version 1.9.2.3 contains a stored cross-site scripting vulnerability in its admin settings that a…

Medium

CVE-2024-10903

Broken Link Checker [broken-link-checker] < 2.4.2

The Broken Link Checker plugin for WordPress through version 2.4.1 contains a server-side request forgery vulnerability that allows adminis…

Medium

CVE-2024-54253

Xpro Addons — 150+ Widgets for Elementor [xpro-elementor-addons] < 1.4.6.6

The 140+ Widgets | Xpro Addons For Elementor plugin for WordPress contains a stored cross-site scripting vulnerability affecting versions 1…

Medium

CVE-2024-11352

TwentyTwenty [twentytwenty] <= 1.0.1 (unfixed + closed)

The TwentyTwenty plugin through version 1.0.1 contains a stored cross-site scripting flaw in its shortcode functionality that fails to prop…

Medium

CVE-2024-53825

FileBird – WordPress Media Library Folders & File Manager [filebird] < 6.3.4

The FileBird WordPress plugin for managing media library folders is vulnerable to unauthorized access in versions through 6.3.2 because it …

High

CVE-2024-11391

Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution [file-manager-advanced] < 5.2.11

The Advanced File Manager plugin for WordPress contains a file upload vulnerability caused by insufficient file type checking in the class_…

Medium

CVE-2024-53823

The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce [the-plus-addons-for-elementor-page-builder] < 6.0.1

The Plus Addons for Elementor plugin through version 5.6.14 contains a stored cross-site scripting vulnerability caused by inadequate sanit…

Medium

CVE-2024-10484

Spectra Legacy – Gutenberg Blocks [ultimate-addons-for-gutenberg] < 2.16.3

The Spectra – WordPress Gutenberg Blocks plugin through version 2.16.2 contains a stored cross-site scripting vulnerability in its Team wid…

Medium

CVE-2024-10706

Download Manager [download-manager] < 3.3.03

The Download Manager plugin for WordPress contains a stored cross-site scripting vulnerability in its administrator settings that affects a…

Medium

CVE-2024-11252

Social Sharing Plugin – Sassy Social Share [sassy-social-share] < 3.3.70

The Sassy Social Share plugin for WordPress contains a reflected cross-site scripting vulnerability affecting versions up to 3.3.69 through…

Medium

CVE-2024-10555

MaxButtons – Create buttons [maxbuttons] < 9.8.1

The MaxButtons plugin for WordPress versions up to 9.8.0 contains a stored cross-site scripting vulnerability in the Button Width field due…

Critical

CVE-2024-8672

Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets [widget-options] < 4.0.8

The Widget Options plugin for WordPress contains a vulnerability in versions up to 4.0.7 that allows attackers with contributor-level acces…

Medium

CVE-2024-11203

EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents [embedpress] < 4.1.4

The EmbedPress plugin for WordPress is susceptible to a stored cross-site scripting vulnerability through the 'provider_name parameter in v…

Medium

CVE-2024-8236

Elementor Website Builder – more than just a page builder [elementor] < 3.25.8

The Elementor Website Builder plugin for WordPress contains a security flaw affecting all versions up to 3.25.7. Specifically, the 'url' pa…

Medium

CVE-2024-5333

The Events Calendar [the-events-calendar] < 6.8.2.1

The Events Calendar plugin contains an information disclosure vulnerability in versions up to 6.8.2 where the /wp-json/tribe/events/v1/even…

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.