WordPress Vulnerability Database

Search 67,535+ known security issues across 16,056 plugins and 2,156 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

critical MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token Myhome Core · Aug 29, 2026 · CVE-2026-15980 critical Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout User Registration Plugin For Woocommerce · Aug 29, 2026 · CVE-2026-15369 high SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning Miniorange Saml 20 Single Sign On · Aug 29, 2026 · CVE-2026-75807 critical GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Give · Aug 28, 2026 · CVE-2026-82222 critical Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field Sigmaforms Pro · Aug 28, 2026 · CVE-2026-14494 critical WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion Wpmudev Updates · Aug 27, 2026 · CVE-2026-76581 medium Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute Fusion Builder · Aug 27, 2026 · CVE-2026-16654 medium Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters Tutor · Aug 27, 2026 · CVE-2026-16759 high One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter One User Avatar · Aug 27, 2026 · CVE-2026-18983 high LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content Litespeed Cache · Aug 27, 2026 · CVE-2026-18978 medium LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes Litespeed Cache · Aug 27, 2026 · CVE-2026-3129 high Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field Forminator · Aug 27, 2026 · CVE-2026-18324

Browse plugins

16,056 tracked
Basepress Migration Tools 1 Basic Google Maps Placemarks 1 Basic Interactive World Map 2 Baslider 6 Basticom Framework 2 Batch Cat 2 Bauernregeln 1 Baw Login Logout Menu 1 Baw Post Views Count 1 Bayarcash Wc 1 Bb Bootstrap Cards 3 Bb Plugin 4 Bb Ultimate Addon 9 Bbcode Deluxe 1 Bbp Api 1 Bbp Core 3 Bbp Members Only 1 Bbp Move Topics 6 Bbp Style Pack 7 Bbp Toolkit 4 Bbp Topic Count 1 Bbp Voting 1 Bbpowerpack 2 Bbpress 23 Bbpress Login Register Links On Forum Topic Pages 1 Bbpress Notify Nospam 2 Bbpress Post Topics 2 Bbpress Simple Advert Units 1 Bbpress2 Shortcode Whitelist 1 Bbq Pro 1 Bbresolutions 1 Bbs E Franchise 1 Bbs E Popup 2 Bbspoiler 1 Bc Menu Cart Woo 1 Bc Woo Custom Thank You Pages 1 Bck Tu Dong Xac Nhan Thanh Toan Chuyen Khoan Ngan Hang 4 Bcm Duplicate Menu 1 Bcorp Shortcodes 1 Bcs Bertline Book Importer 1 Bd Courier Order Ratio Checker 2 Bdthemes Element Pack 8 Bdthemes Element Pack Lite 80 Bdthemes Prime Slider Lite 39 Bdvs Password Reset 4 Be Popia Compliant 4 Be Shortcodes 1 Beacon By 2 Beacon For Helpscout 1 Beaf Before And After Gallery 3 Beam Me Up Scotty 2 Bears Backup 1 Beautiful And Responsive Cookie Consent 12 Beautiful Link Preview 1 Beautiful Taxonomy Filters 1 Beauty Contact Popup Form 1 Beaver Builder Lite Version 65 Beaver Themer 2 Bebetter Social Icons 1 Becustom 1

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free