Plugin vulnerabilities
Recently disclosed security vulnerabilities in WordPress plugins, newest first: what the issue is, which versions it hits, and the release that fixes it. The plugin directory itself never shows you any of this.
200 shown
- A ACPT (Premium) Critical
ACPT (Premium) <= 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_form_post_id' Parameter
- D Divi Ajax Filter Critical
Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter
- L LearnDash LMS High
LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler
-
JetFormBuilder <= 3.6.2 - Missing Authorization to Unauthenticated JetEngine Options Page Modification
-
GutenKit <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss'
- E Easy Waveform Player Medium
Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_easywaveformplayer Function
-
Broken Link Checker High Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log
- S SigmaForms Pro – AI Generated Forms Critical
SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field
- D DevKit Pro High
DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter
- W WP File Download High
WP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter
- G Gravity Forms High
Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion
-
Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId'
- W WPBakery Page Builder Medium
WPBakery Page Builder <= 8.7.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter
-
Welcart e-Commerce High
Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter
-
Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode
-
Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_projects_output Shortcode
-
Blocksy Companion Medium Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data)
-
User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting via 'email' Parameter
-
Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attribute
-
BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content
-
User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'date' Shortcode Attribute
-
Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token
-
Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL Injection via 'product_order' Parameter
-
Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates Medium Cozy Blocks <= 2.2.17 - Missing Authorization to Unauthenticated Unpublished Product Information Disclosure via 'wishlistData' Parameter
-
Affiliate Super Assistent <= 1.10.2 - Unauthenticated Stored Cross-Site Scripting via ‘doCommentShortcode’ function
-
Photo Gallery by Ays <= 6.8.2 - Authenticated (Administrator+) SQL Injection via 's' Parameter
-
Persistent Login Medium Persistent Login <= 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wppl_device_id' Cookie
-
Master Addons for Elementor <= 3.1.9 - Incorrect Authorization to Authenticated (Editor+) Arbitrary File Upload via upload_template_kit AJAX ZIP Extraction
-
Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode
-
Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_id' Shortcode Attribute
-
Listdom: AI-powered Business Directory with Classifieds Ads Listings <= 5.8.1 - Unauthenticated Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter
-
LearnPress <= 4.4.4 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter
-
Frontend Admin by DynamiApps Medium Frontend Admin by DynamiApps <= 3.29.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Shortcode Attribute
-
Frontend Admin by DynamiApps <= 3.29.12 - Unauthenticated Arbitrary File Deletion via Path Traversal via custom_directory_name Merge Tag
-
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode Critical WPLP Cookie Consent <= 4.4.1 - Unauthenticated Arbitrary File Upload via 'upload-logo' REST Endpoint
- U Uix UserCenter High
Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation
-
MemberHero – Simple User Registration & Login <= 6.9 - Unauthenticated Privilege Escalation
-
WCFM Marketplace – Multivendor Marketplace for WooCommerce <= 3.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
-
bbPress Medium
bbPress <= 2.6.14 - Missing Authorization
- F FS Poster - WordPress Social media Auto Poster & Scheduler [Facebook, Instagram, Twitter, Pinterest] High
FS Poster <= 8.0.1 - Authenticated (Subscriber+) Remote Code Execution via FFmpeg Path Setting
-
Rest Routes – Custom Endpoints for WordPress REST API <= 5.5.5 - Unauthenticated SQL Injection
-
WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode Critical WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode <= 4.4.1 - Unauthenticated Arbitrary File Upload
- W WP Recipe Maker Premium Medium
WP Recipe Maker Premium <= 10.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wprm-call-to-action' Shortcode
- B Breakdance Medium
Breakdance <= 2.8.1 - Missing Authorization
-
Total processing card payments for WooCommerce <= 7.3 - Unauthenticated Server-Side Request Forgery
- H HEL Online Classroom: AI-powered Online Classrooms Medium
HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Information Exposure
-
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Missing Authorization
-
Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored Cross-Site Scripting
-
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) < 9.8.0 - Authenticated (Custom Role+) Remote Code Execution
- O Oxygen Medium
Oxygen 6.0 - 6.1.1 - Missing Authorization
-
Groundhogg — CRM, Newsletters, and Marketing Automation < 4.5.13 - Unauthenticated Stored Cross-Site Scripting
-
Simple Membership Medium Simple Membership <= 4.8.1 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Multisite Identity Binding
-
WPvivid — Backup, Migration & Staging < 0.9.133 - Authenticated (Administrator+) Remote Code Execution
-
SOGO Add Script to Individual Pages Header Footer <= 3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
- M MyHome Core Critical
MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token
- C Custom User Registration Fields for WooCommerce Critical
Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout
-
SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning
-
SmartAIPress Medium SmartAIPress <= 1.2.0 - Authenticated (Subscriber+) Server-Side Request Forgery
-
MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.42 - Authenticated (Custom Role+) Insecure Direct Object Reference
-
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Administrator+) PHP Object Injection
-
Newsletters Medium Newsletters < 4.17 - Cross-Site Request Forgery
-
WP Ultimate CSV Importer – WordPress CSV, XML & Excel Import < 9.0 - Authenticated (Administrator+) SQL Injection
- H HEL Online Classroom: AI-powered Online Classrooms Medium
HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Information Exposure
- C Catfolders Document Gallery Pro Medium
Catfolders Document Gallery Pro < 2.0.7 - Missing Authorization
-
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings < 1.0.277 - Missing Authorization
-
Booking for Appointments and Events Calendar – Amelia 1.2.32 - 2.4.8 - Missing Authorization
-
User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor < 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
- A Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress High
Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation
- T Tailored Tools High
Tailored Tools <= 3.0.2 - Unauthenticated Stored Cross-Site Scripting
- G GeotargetingWP Medium
GeotargetingWP < 3.5.6.2 - Reflected Cross-Site Scripting
-
KiviCare – Clinic & Patient Management System (EHR) <= 4.5.4 - Unauthenticated Information Exposure
-
User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission < 4.3.10 - Unauthenticated Information Exposure
-
OwnerRez Medium OwnerRez <= 1.2.6 - Missing Authorization
- S Super Store Finder High
Super Store Finder <= 7.10 - Unauthenticated Stored Cross-Site Scripting
-
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards <= 5.5.81 - Unauthenticated SQL Injection
-
Email Essentials High Email Essentials <= 6.0.6 - Unauthenticated Stored Cross-Site Scripting
-
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution
-
Smart Marketing SMS and Newsletters Forms <= 5.1.24 - Unauthenticated SQL Injection
-
Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.1 - Unauthenticated Privilege Escalation
-
Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.0.7 - Authenticated (Custom Role+) Privilege Escalation
-
Booking for Appointments and Events Calendar – Amelia 9.0 - 9.7 - Authenticated (Provider+) Arbitrary Provider Password Update
-
Tickera – Sell Tickets & Manage Events <= 3.6.0.2 - Unauthenticated PHP Object Injection
-
User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission < 4.3.10 - Authenticated (Editor+) PHP Object Injection
-
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy < 5.0.14 - Authenticated (Shop Manager+) Remote Code Execution
-
Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment <= 2.7.6 - Missing Authorization
-
StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce < 2.1.2 - Unauthenticated Arbitrary Price Manipulation
- F Fluent Forms Pro Add On Pack Medium
Fluent Forms Pro Add On Pack <= 6.2.12 - Missing Authorization
-
Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates – WPLP Legal Pages < 3.7.1 - Unauthenticated Information Exposure
- M MW WP Form Medium
MW WP Form < 5.1.6 - Authenticated (Editor+) Stored Cross-Site Scripting
-
Affiliate Program Suite — SliceWP Affiliates <= 1.2.10 - Unauthenticated Stored Cross-Site Scripting
-
WPBulky – WordPress Bulk Edit Post Types <= 1.2.2 - Authenticated (Contributor+) SQL Injection
- S SigmaForms Pro – AI Generated Forms Critical
Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field
-
GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution
-
WP OAuth Server ( Login with WordPress ) < 6.3.1 - Unauthenticated Information Exposure
-
Security Optimizer – The All-In-One Protection Plugin <= 1.6.6 - 2-Factor Authentication Bypass
-
Hash Form – Drag & Drop Form Builder Critical Hash Form – Drag & Drop Form Builder <= 1.4.2 - Unauthenticated Arbitrary File Upload
-
LeadConnector High LeadConnector <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting
-
Breeze Cache Medium Breeze Cache < 2.5.13 - Unauthenticated File Creation via Path Traversal
-
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.5 - Authenticated (Subscriber+) Insecure Direct Object Reference
-
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.9.8 - Authentication Bypass
-
Content Mask Medium Content Mask 1.8.0 - 1.8.5.4 - Missing Authorization
-
Directorist: AI-Powered Business Directory, Listings & Classified Ads 8.5 - 8.9.2 - Authenticated (Subscriber+) Arbitrary Image Move
-
Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.57.1 - Unauthenticated Payment Bypass
-
Tutor LMS – eLearning and online course solution < 4.0.6 - Authenticated (Custom Role+) Arbitrary File Read
- F Fluent Forms Pro Add On Pack Medium
Fluent Forms Pro Add On Pack <= 6.2.12 - Authenticated (Subscriber+) Privilege Escalation
-
Return Refund and Exchange For WooCommerce < 4.6.4 - Missing Authorization
- W WP Rocket Medium
WP Rocket 3.23.1 - 3.23.3.2 - Unauthenticated Information Exposure
-
Shared Files Pro < 1.7.68 & Shared Files Free < 1.7.67 - Unauthenticated Arbitrary File Deletion
- S Shared Files Pro Critical
Shared Files Pro < 1.7.68 & Shared Files Free < 1.7.67 - Unauthenticated Arbitrary File Deletion
-
Social Login, Social Sharing by miniOrange <= 7.8.2 - Unauthenticated Stored Cross-Site Scripting
-
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 2.6.7 - 2.12.1 - Unauthenticated Privilege Escalation
-
12 Step Meeting List High 12 Step Meeting List 3.17 - 3.19.16 - Unauthenticated Stored Cross-Site Scripting
- T Throws SPAM Away High
Throws SPAM Away <= 3.8.2 - Unauthenticated SQL Injection
-
CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 4.1.18 - Authenticated (Editor+) Privilege Escalation
-
Pods – Custom Content Types and Fields < 3.3.9.1 - Authenticated (Author+) Remote Code Execution
-
Document Embedder – let visitors read files without downloading < 2.3.1 - Unauthenticated Arbitrary Document Download
- S Simple Payment Medium
Simple Payment <= 2.5.2 - Missing Authorization
-
Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker < 11.2.4 - Authenticated (Contributor+) Insecure Direct Object Reference
-
AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.4.0 - 3.7.1 - Missing Authorization to Unauthenticated Arbitrary AI Query Execution
-
Slider Hero with Video Background, Animation < 9.1.3 - Unauthenticated Stored Cross-Site Scripting
-
Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates < 2.7.2 - Unauthenticated Server-Side Request Forgery
-
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.6 - Authenticated (Custom Role+) Privilege Escalation
- W WPMU DEV Dashboard Critical
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
- A Avada (Fusion) Builder Medium
Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute
-
Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters
-
One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter
-
LiteSpeed Cache High LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content
-
LiteSpeed Cache Medium LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes
-
Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
-
TranslatePress <= 3.3.3 - Unauthenticated Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser
-
Optimole <= 4.2.10 - Unauthenticated Stored Cross-Site Scripting via 'a' (above_fold_images) Parameter
-
Smart Slider 3 Medium
Smart Slider 3 <= 3.5.1.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'slider' Block Attribute
-
RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin) High RestrictMate – Restrict Page, Post and any Content ( Content Restriction and Membership Plugin) < 1.3.0 - Unauthenticated Privilege Escalation
-
Frontend Admin by DynamiApps Medium Frontend Admin by DynamiApps < 3.29.11 - Authenticated (Subscriber+) Membership Plan Deletion
-
Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via Gallery Description
-
Defender Security – Malware Scanner, Login Security & Firewall < 6.2.0 - Authenticated (Administrator+) Remote Code Execution
- W WP Rocket High
WP Rocket <= 3.21.0.1 - Unauthenticated Stored Cross-Site Scripting via Picture Source Attributes in rocket_beacon Endpoint
-
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.276 - Authenticated (Author+) Remote Code Execution
-
WP Job Portal – AI-Powered Recruitment System for Company or Job Board website <= 2.5.9 - Authenticated (Subscriber+) Insecure Direct Object Reference
-
Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions < 8.5.5 - Unauthenticated Insecure Direct Object Reference
-
CMP – Coming Soon & Maintenance Plugin by NiteoThemes < 4.1.18 - Missing Authorization to Unauthenticated Settings Change
-
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN < 4.3.2 - Authenticated (Administrator+) Remote Code Execution
-
Newsletters Medium Newsletters < 4.17 - Insufficient Authorization
-
MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Completion
-
Finale Lite – Sales Countdown Timer & Discount for WooCommerce < 2.21.0 - Authenticated (Subscriber+) Information Exposure
-
Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Upload
- J JetEngine High
JetEngine <= 3.8.14.2 - Unauthenticated Stored Cross-Site Scripting
-
爱采集数据采集和发布插件 High 爱采集数据采集和发布插件 <= 1.0.0 - Unauthenticated Arbitrary File Read
-
UpdraftPlus: WP Backup & Migration Plugin < 1.26.7 - Cross-Site Request Forgery
-
AI Engine – The Chatbot, AI Framework & MCP for WordPress 3.3.3 - 3.7.1 - Authenticated (Subscriber+) Arbitrary File Read
-
Essential Addons for Elementor – Popular Elementor Templates & Widgets <= 6.8.0 - Unauthenticated Captcha Bypass
-
Workeera – AI Job Board with Applicant Tracking System (ATS) < 1.0.6 - Authenticated (Subscriber+) Arbitrary File Read
-
Booking for Appointments and Events Calendar <= 2.2 - Unauthenticated Stored Cross-Site Scripting via Customer Name Fields in Booking Submission
- E ElementsKit Pro Medium
ElementsKit Pro <= 4.10.1 - Unauthenticated Stored Cross-Site Scripting via 's' Parameter
-
Smush – Image Optimization, Compression, Lazy Load, WebP & CDN <= 4.2.0 - Unauthenticated Denial of Service
-
Notifima – WooCommerce Stock Manager, Inventory Management, Waitlist < 3.1.4 - Authenticated (Subscriber+) Insecure Direct Object Reference
-
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar Medium Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar <= 5.5.0 - Missing Authorization
- M Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce Medium
Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce <= 0.4.62 - Authenticated (Subscriber+) Insecure Direct Object Reference
-
Advanced Custom Fields: Extended <= 0.9.2.6 - Missing Authorization
-
wpForo Forum High wpForo Forum <= 2.4.17 - Unauthenticated SQL Injection via 'referer' Parameter
-
MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.43 - Unauthenticated Open Redirect
- H HEL Online Classroom: AI-powered Online Classrooms High
HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Missing Authorization to Unauthenticated Settings Update
-
Everest Forms <= 3.4.4 - Unauthenticated Server-Side Request Forgery via Upload Field 'Previous Value'
-
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress <= 5.9.33 - Unauthenticated Stored Cross-Site Scripting
- A All-in-One WP Migration Unlimited Extension Medium
All-in-One WP Migration Unlimited Extension <= 2.84 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ai1wm_backups_path' Parameter
-
Customer Reviews for WooCommerce <= 5.106.0 - Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form
-
GiveWP <= 4.14.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
-
MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization
-
MasterStudy LMS WordPress Plugin – for Online Courses and Education < 3.7.40 - Unauthenticated Payment Bypass
-
Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar Medium Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar <= 5.5.0 - Missing Authorization
-
Forminator Forms – Contact Form, Payment Form & Custom Form Builder < 1.57.0.5 - Authenticated (Administrator+) Remote Code Execution
- F Formidable Charts High
Formidable Charts <= 2.0.1 - Unauthenticated Arbitrary File Read via 'frm_graph' Parameter
-
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker Medium Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker < 4.0.7 - Authenticated (Subscriber+) Insecure Direct Object Reference
-
Shared Files Pro < 1.7.70 & Shared Files Free < 1.7.67 - Unauthenticated Limited File Upload
- S Shared Files Pro Medium
Shared Files Pro < 1.7.70 & Shared Files Free < 1.7.67 - Unauthenticated Limited File Upload
-
Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce < 4.1.22 - Unauthenticated Information Exposure
-
Kirki – Freeform Page Builder, Website Builder & Customizer < 6.0.14 - Missing Authorization
-
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker Medium Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker 2.2.0 - 4.0.6 - Authenticated (Subscriber+) Insecure Direct Object Reference
- S Suggestion Engine for WooCommerce Medium
Suggestion Engine for WooCommerce <= 2.0.11 - Authenticated (Contributor+) SQL Injection
-
Booking for Appointments and Events Calendar – Amelia < 2.4.7 - Missing Authorization
- F Fluent Boards Pro High
Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) Arbitrary File Upload
- F Fluent Boards Pro Medium
Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) Arbitrary File Deletion
-
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login < 6.0.9.4 - Authenticated (Administrator+) SQL Injection
- F Fluent Player Pro Low
FluentPlayer Pro <= 1.3.2 - Missing Authorization
-
Kali Forms — Contact Form & Drag-and-Drop Builder <= 2.4.23 - Missing Authorization
-
Ditty – Responsive News Tickers, Sliders, and Lists <= 3.1.67 - Missing Authorization
- F Fluent Booking Pro Medium
FluentBooking Pro <= 2.2.4 - Cross-Site Request Forgery
-
GeoDirectory – WP Business Directory Plugin and Classified Listings Directory <= 2.8.176 - Cross-Site Request Forgery
-
SureFeedback Client Site Medium
SureFeedback Client Site <= 1.2.12 - Authenticated (Subscriber+) Information Exposure
-
Simple Newsletter Plugin – Noptin < 4.3.3 - Missing Authorization
- S SmilePass Selfie Login Critical
SmilePass Selfie Login <= 1.0.2 - Authentication Bypass to Administrator
-
Push Notification for Post and BuddyPress <= 3.20 - Missing Authorization
-
WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System < 3.0.18 - Missing Authorization
- F Fluent Boards Pro Medium
Fluent Boards Pro <= 2.0.11 - Authenticated (Subscriber+) Stored Cross-Site Scripting
-
WCFM Marketplace – Multivendor Marketplace for WooCommerce < 3.8.2 - Insecure Direct Object Reference to Unauthenticated Arbitrary Order Refund Request
- F Fluent Boards Pro Medium
Fluent Boards Pro <= 2.0.11 - Authenticated (Editor+) PHP Object Injection
-
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Missing Authorization
-
Royal Addons for Elementor – Addons and Templates Kit for Elementor < 1.7.1066 - Authenticated (Contributor+) Stored Cross-Site Scripting
-
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App 4.0.0-beta.1 - Missing Authorization to Authenticated (Subscriber+) Settings Change
- C Classified Listing - Mobile Number Verification High
Classified Listing - Mobile Number Verification <= 1.6.0 - Unauthenticated Authentication Bypass via Firebase OTP Login
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Severity is the CVSS rating from the feed. "Affects" is the vulnerable version range; running a version in that range without the patched release means the hole is live on your site.