WordPress Vulnerability Database

Search 67,535+ known security issues across 16,056 plugins and 2,156 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

critical MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token Myhome Core · Aug 29, 2026 · CVE-2026-15980 critical Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout User Registration Plugin For Woocommerce · Aug 29, 2026 · CVE-2026-15369 high SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning Miniorange Saml 20 Single Sign On · Aug 29, 2026 · CVE-2026-75807 critical GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Give · Aug 28, 2026 · CVE-2026-82222 critical Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field Sigmaforms Pro · Aug 28, 2026 · CVE-2026-14494 critical WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion Wpmudev Updates · Aug 27, 2026 · CVE-2026-76581 medium Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute Fusion Builder · Aug 27, 2026 · CVE-2026-16654 medium Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters Tutor · Aug 27, 2026 · CVE-2026-16759 high One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter One User Avatar · Aug 27, 2026 · CVE-2026-18983 high LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content Litespeed Cache · Aug 27, 2026 · CVE-2026-18978 medium LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes Litespeed Cache · Aug 27, 2026 · CVE-2026-3129 high Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field Forminator · Aug 27, 2026 · CVE-2026-18324

Browse plugins

16,056 tracked
0 Day Analytics 1 001 Prime Strategy Translate Accelerator 2 012 Ps Multi Languages 2 0Mk Shortener 2 1 Click Backup Restore Database By Sunbytes 2 1 Click Close Store 1 1 Click Migration 4 1 Decembrie 1918 1 1 Flash Gallery 1 1 Jquery Photo Gallery Slideshow Flash 2 1003 Mortgage Application 5 10Centmail Subscription Management And Analytics 1 10To8 Online Booking 1 1180Px Shortcodes 1 12 Step Meeting List 17 123 Chat Videochat 4 123Contactform For Wordpress 3 17Track 1 1App Business Forms 1 1G Music Share 1 1Player 4 2 Click Socialmedia Buttons 2 24Liveblog 2 2Coders Integration Mux Video 1 2D Tag Cloud Widget By Sujin 1 2Download Connector 1 2J Slideshow 4 2Kb Amazon Affiliates Store 5 2Mb Autocode 1 3 Word Address Validation Field 2 360 Product Rotation 7 360 Sphere Images 1 360 View 1 360Crest Themeone Tinymce Shortcodes 1 360Deg Javascript Viewer 7 3Com Asesor De Cookies 1 3D Avatar User Profile 1 3D Cover Carousel 1 3D Flipbook Dflip Lite 17 3D Image Gallery 1 3D Photo Gallery 1 3D Presentation 1 3D Viewer 3 3Dady Real Time Web Stats 1 3Dprint 4 3Dprint Lite 19 3Dvieweronline Wp 1 3R Elementor Timeline Widget 1 3Xsocializer 2 4 Author Cheer Up Donate 1 404 Error Monitor 1 404 Page 1 404 Redirection Manager 3 404 Solution 18 404 To 301 26 404 To Start 2 404Like 1 404Page 1 404S 1 4Ecps Webforms 2

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free