WordPress Vulnerability Database

Search 67,765+ known security issues across 16,079 plugins and 2,157 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

medium Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Media Follow 'skype_url' Shortcode Parameter Divi · Sep 2, 2026 · CVE-2026-3852 medium GutenKit <= 2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postBodyCss' Gutenkit Blocks Addon · Sep 2, 2026 · CVE-2026-2573 medium Easy Waveform Player <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_easywaveformplayer Function Easy Waveform Player · Sep 1, 2026 · CVE-2025-7963 high Broken Link Checker <= 2.4.13 - Unauthenticated Stored Cross-Site Scripting via Comment Author URL / Link Log Broken Link Checker · Sep 1, 2026 · CVE-2026-75528 medium Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Contact Form 'redirect_url' Shortcode Parameter Divi · Sep 1, 2026 · CVE-2026-3850 critical SigmaForms Pro <= 1.4.11 - Unauthenticated Arbitrary File Deletion via Path Traversal in File Upload Field Sigmaforms Pro · Sep 1, 2026 · CVE-2026-78657 high DevKit Pro <= 2.3.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Theme Installation / Remote Code Execution via 'qqfile' Parameter Devkit · Sep 1, 2026 · CVE-2026-14357 medium Divi <= 4.27.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Dynamic Content (Legacy JSON Format) Shortcode Divi · Sep 1, 2026 · CVE-2026-3851 high WP File Download <= 6.3.4 - Authenticated (Subscriber+) Arbitrary File Deletion via 'remoteurl' Parameter Wp File Download · Sep 1, 2026 · CVE-2026-14982 high Gravity Forms <= 3.0.2 - Unauthenticated Arbitrary File Upload via State/Chunk Hash Confusion Gravityforms · Sep 1, 2026 · CVE-2026-19513 critical Booking for Appointments and Events Calendar – Amelia (Premium) 8.0 - 9.6.2 - Unauthenticated Privilege Escalation to Administrator via 'externalId' Ameliabooking · Sep 1, 2026 · CVE-2026-9055 critical Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter Nokri · Aug 31, 2026 · CVE-2026-18550

Browse plugins

16,079 tracked
Kk I Like It 1 Kk Star Ratings 16 Kk Youtube Video 1 Kkprogressbar 3 Klamra Paycal For Aspaclaria 1 Klarna Checkout For Woocommerce 6 Klarna Order Management For Woocommerce 1 Klarna Payments For Woocommerce 1 Klaviyo 4 Klubraum Membership Request 1 Kn Fix Your 1 Knews 6 Knight Lab Timelinejs 3 Knit Pay 2 Knowband Mobile App Builder For Woocommerce 1 Knowledge Base Maker 1 Knowledge Center 1 Knowledgebase 7 Knowledgebase Helpdesk Pro 4 Knr Author List Widget 2 Ko Fi Button 1 Koalendar Free Booking Widget 1 Kodex Posts Likes 10 Kodo Qiniu 1 Koko Analytics 2 Kona Instagram Feed For Gutenberg 2 Konami Easter Egg 2 Konnichiwa 1 Kontur Admin Style 1 Kontxt Semantic Engine 1 Kopa Nictitate Toolkit 1 Kopatheme 1 Korea For Woocommerce 2 Korea Sns 2 Kp Fastest Tawk To Chat 2 Kraken Image Optimizer 6 Kredeum Nfts 1 Krsp Frontend File Upload 2 Ksher Payment 2 Kstats Reloaded 2 Kubio 10 Kudos Donations 3 Kumihimo 1 Kundgenerator 1 Kunze Law 2 Kush Micro News 1 Kv Send Email From Admin 2 Kv Tinymce Editor Fonts 1 Kvcore Idx 2 Kvoucher 2 Kwayy Html Sitemap 2 L Squared Hub Wp Virtual Device 1 Label Grid Tools 1 Label Plugins 1 Labinator Content Types Duplicator 1 Labtools 1 Ladipage 18 Lafka Plugin 1 Laika Pedigree Tree 1 Laiser Tag 1

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free