WordPress Vulnerability Database

Search 67,535+ known security issues across 16,056 plugins and 2,156 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

critical MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token Myhome Core · Aug 29, 2026 · CVE-2026-15980 critical Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout User Registration Plugin For Woocommerce · Aug 29, 2026 · CVE-2026-15369 high SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning Miniorange Saml 20 Single Sign On · Aug 29, 2026 · CVE-2026-75807 critical GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Give · Aug 28, 2026 · CVE-2026-82222 critical Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field Sigmaforms Pro · Aug 28, 2026 · CVE-2026-14494 critical WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion Wpmudev Updates · Aug 27, 2026 · CVE-2026-76581 medium Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute Fusion Builder · Aug 27, 2026 · CVE-2026-16654 medium Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters Tutor · Aug 27, 2026 · CVE-2026-16759 high One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter One User Avatar · Aug 27, 2026 · CVE-2026-18983 high LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content Litespeed Cache · Aug 27, 2026 · CVE-2026-18978 medium LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes Litespeed Cache · Aug 27, 2026 · CVE-2026-3129 high Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field Forminator · Aug 27, 2026 · CVE-2026-18324

Browse plugins

16,056 tracked
4K Icon Fonts For Visual Composer 1 4Stats 1 5 Anker Connect 2 5 Stars Rating Funnel 5 5 Sterrenspecialist 1 5280 Bootstrap Modal Contact Form 2 59Sec Lite Contact Form 7 Push Notifications On Ios And Android 1 5Centscdn 1 6Storage Rentals 6 8 Degree Coming Soon Page 1 8 Degree Notification Bar 1 99Fy Core 4 99Robots Header Footer Code Manager Pro 1 A Forms 1 A Gateway For Pasargad Bank On Woocommerce 1 A Simple Multilanguage 1 A Staff 2 A Team Showcase 1 A1Post Bg Shipping For Woocommerce 1 A2 Optimized Wp 1 A2Z Fedex Shipping 1 A3 Lazy Load 6 A3 Portfolio 7 A3 Responsive Slider 6 A3 User Importer 1 A4 Barcode Generator 4 Aa Audio Player 1 Aa Block Country 2 Aa Calculator 1 Aajoda Testimonials 4 Aapanel Wp Toolkit 1 Aardvark Plugin 2 Aawp 2 Aawp Obfuscator 2 Ab Categories Search Widget 1 Ab Google Map Travel 4 Ab Press Optimizer Lite 1 Ab Rankings Testing Tool 1 Ab Testing For Wp 1 Aba Payway Woocommerce Payment Gateway 1 Abandoned Contact Form 7 2 Abbie Expander 1 Abbs Bing Search 1 Abc Notation 3 Abcapp Creator 2 Abcbiz Addons 1 Abcsubmit 1 Abeta Punchout 1 Abg Rich Pins 1 Abitgone Commentsafe 2 Ableplayer 2 Ablocks 4 About Author 5 About Author Box 1 About Me 1 About Me 3000 2 About Rentals 1 Absolute Addons 2 Absolute Links 1 Absolute Privacy 2

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free