WordPress Vulnerability Database

Search 67,843+ known security issues across 16,091 plugins and 2,157 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

high WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter Wp Fusion · Sep 7, 2026 · CVE-2026-14444 medium Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field Email Subscribers · Sep 7, 2026 · CVE-2026-12757 medium LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' Learnpress · Sep 7, 2026 · CVE-2026-12230 high Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update Event Tickets · Sep 7, 2026 · CVE-2026-3174 medium WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’ Sitepress Multilingual Cms · Sep 7, 2026 · CVE-2026-17509 high EDD Product Catalog Feed by PixelYourSite <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter Edd Products Feed Pro · Sep 7, 2026 · CVE-2026-9331 medium Zephyr Project Manager <= 3.3.205 - Authenticated (Custom+) Stored Cross-Site Scripting via 'message' Parameter Zephyr Project Manager · Sep 7, 2026 · CVE-2026-76931 high Live Composer <= 2.1.18 - Authenticated (Contributor+) PHP Object Injection via Shortcode Live Composer Page Builder · Sep 7, 2026 · CVE-2026-16502 medium Beaver Builder Page Builder <= 2.10.3.1 - Unauthenticated Arbitrary Shortcode Execution Beaver Builder Lite Version · Sep 7, 2026 · CVE-2026-18021 medium Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update Bookly Responsive Appointment Booking Tool · Sep 7, 2026 · CVE-2026-2520 medium Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypass Otter Blocks · Sep 6, 2026 · CVE-2026-4945 high User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field Profile Builder · Sep 6, 2026 · CVE-2026-6431

Browse plugins

16,091 tracked
Woo Product Filter 17 Woo Product Finder 1 Woo Product Gallery Slider 3 Woo Product Multiaction 1 Woo Product Pricing Tables 1 Woo Product Reviews Shortcode 4 Woo Product Slider 2 Woo Product Slider And Carousel With Category 1 Woo Product Slider Pro 1 Woo Product Table 4 Woo Product Tables 4 Woo Product Variation Gallery 1 Woo Product Variation Swatches 1 Woo Products Widgets For Elementor 4 Woo Producttables Pro 4 Woo Quick Cart For Multiple Variations 1 Woo Quick Reports 1 Woo Quick View 1 Woo Quickview 2 Woo Quote Calculator Order 4 Woo Razorpay 11 Woo Recargo De Equivalencia 1 Woo Recent Purchases 1 Woo Rede 2 Woo Redsys Gateway Light 3 Woo Refund And Exchange Lite 11 Woo Related Products Refresh On Reload 1 Woo Remove Cart And Query Button 1 Woo Reviews By Wiremo 3 Woo Reviews Manager 1 Woo Rfq For Woocommerce 1 Woo Salesforce Plugin Crm Perks 2 Woo Save Abandoned Carts 2 Woo Seo Addon 1 Woo Shipping Display Mode 3 Woo Shipping Dpd Baltic 3 Woo Show Single Variations Shop Category 1 Woo Single Page Checkout 1 Woo Sku Label Changer 1 Woo Slider Pro Drag Drop Slider Builder For Woocommerce 4 Woo Smart Compare 2 Woo Smart Quick View 8 Woo Smart Wishlist 12 Woo Social Login 19 Woo Store Mode 1 Woo Stripe Payment 2 Woo Suggestion Engine 1 Woo Superb Slideshow Transition Gallery With Random Effect 1 Woo Swatches Manager 1 Woo Tbc Payment Gateway 2 Woo Thank You Page Customizer 11 Woo Thank You Page Nextmove Lite 17 Woo Tipdonation 1 Woo Tools 1 Woo Total Sales 1 Woo Tranzila Gateway 1 Woo Tumblog 1 Woo Tuner 1 Woo Ukrposhta 9 Woo Update Variations In Cart 1

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free