WordPress Vulnerability Database

Search 67,535+ known security issues across 16,056 plugins and 2,156 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

critical MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token Myhome Core · Aug 29, 2026 · CVE-2026-15980 critical Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout User Registration Plugin For Woocommerce · Aug 29, 2026 · CVE-2026-15369 high SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning Miniorange Saml 20 Single Sign On · Aug 29, 2026 · CVE-2026-75807 critical GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Give · Aug 28, 2026 · CVE-2026-82222 critical Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field Sigmaforms Pro · Aug 28, 2026 · CVE-2026-14494 critical WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion Wpmudev Updates · Aug 27, 2026 · CVE-2026-76581 medium Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute Fusion Builder · Aug 27, 2026 · CVE-2026-16654 medium Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters Tutor · Aug 27, 2026 · CVE-2026-16759 high One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter One User Avatar · Aug 27, 2026 · CVE-2026-18983 high LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content Litespeed Cache · Aug 27, 2026 · CVE-2026-18978 medium LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes Litespeed Cache · Aug 27, 2026 · CVE-2026-3129 high Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field Forminator · Aug 27, 2026 · CVE-2026-18324

Browse plugins

16,056 tracked
Auto Date Year Month 2 Auto Delete Posts 1 Auto Excerpt Everywhere 1 Auto Featured Image 1 Auto Featured Image Auto Generated 1 Auto Featured Image From Title 1 Auto Ftp 1 Auto Hide Admin Bar 3 Auto Hyperlink Urls 1 Auto Iframe 4 Auto Image Attributes From Filename With Bulk Updater 1 Auto Install Free Ssl 1 Auto Keyword Backlink 1 Auto Last Youtube Video 1 Auto Limit Posts Reloaded 1 Auto Listings 2 Auto Load Next Post 1 Auto Location For Wp Job Manager 2 Auto Login After Registration 1 Auto Login New User After Registration 4 Auto Login When Resister 2 Auto Making Json Ld 1 Auto More Tag 1 Auto Post After Image Upload 1 Auto Post Scheduler 1 Auto Post Thumbnail 16 Auto Post To Social Media Wp To Social Champ 1 Auto Poster 2 Auto Prune Posts 3 Auto Refresh Single Page 1 Auto Rename Media On Upload 4 Auto Save Remote Images Drafts 1 Auto Scroll For Reading 1 Auto Seo 1 Auto Tag Creator 1 Auto Tag Links 2 Auto Terms Of Service And Privacy Policy 1 Auto Thickbox 1 Auto Thickbox Plus 1 Auto Thumbnailer 1 Auto Translate 1 Auto Upload Images 3 Auto Youtube Importer 1 Autocatset 2 Autocomplete Address And Location Picker For Woocommerce 1 Autocomplete Location Field Contact Form 7 2 Autocompleter 2 Autogen Headers Menu 1 Autoglot 1 Autolinks 1 Autolisticle Automatically Update Numbered List Articles 1 Automail 1 Automate Hub Free By Sperse Io 2 Automated Editor 2 Automatewoo 4 Automatic Ban Ip 1 Automatic Domain Changer 1 Automatic Featured Images From Videos 2 Automatic Grid Image Listing 1 Automatic Internal Links For Seo 3

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free