WordPress Vulnerability Database

Search 67,843+ known security issues across 16,091 plugins and 2,157 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

high WP Fusion (Pro) <= 3.47.13 - Authenticated (Subscriber+) Privilege Escalation via ThriveCart Auto Login 'role' Parameter Wp Fusion · Sep 7, 2026 · CVE-2026-14444 medium Email Subscribers & Newsletters <= 5.9.27 - Unauthenticated Arbitrary Shortcode Execution via Subscriber Name Field Email Subscribers · Sep 7, 2026 · CVE-2026-12757 medium LearnPress <= 4.3.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'layout_custom_css' Learnpress · Sep 7, 2026 · CVE-2026-12230 high Event Tickets and Registration <= 5.27.4 - Missing Authorization to Unauthenticated Stripe Credentials Update Event Tickets · Sep 7, 2026 · CVE-2026-3174 medium WPML Multilingual CMS <= 4.9.5 - Incorrect Authorization to Authenticated (Subscriber+) SQL Injection via ‘elementIds’ Sitepress Multilingual Cms · Sep 7, 2026 · CVE-2026-17509 high EDD Product Catalog Feed by PixelYourSite <= 1.0.2 - Authenticated (Subscriber+) Arbitrary Options Deletion via Missing Authorization on 'delete' Parameter Edd Products Feed Pro · Sep 7, 2026 · CVE-2026-9331 medium Zephyr Project Manager <= 3.3.205 - Authenticated (Custom+) Stored Cross-Site Scripting via 'message' Parameter Zephyr Project Manager · Sep 7, 2026 · CVE-2026-76931 high Live Composer <= 2.1.18 - Authenticated (Contributor+) PHP Object Injection via Shortcode Live Composer Page Builder · Sep 7, 2026 · CVE-2026-16502 medium Beaver Builder Page Builder <= 2.10.3.1 - Unauthenticated Arbitrary Shortcode Execution Beaver Builder Lite Version · Sep 7, 2026 · CVE-2026-18021 medium Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Plugin Update Bookly Responsive Appointment Booking Tool · Sep 7, 2026 · CVE-2026-2520 medium Otter Blocks <= 3.1.7 - Missing Authorization to Unauthenticated Purchase Verification Bypass Otter Blocks · Sep 6, 2026 · CVE-2026-4945 high User Profile Builder <= 3.15.7 - Unauthenticated Stored Cross-Site Scripting via 'Biographical Info' Meta Field Profile Builder · Sep 6, 2026 · CVE-2026-6431

Browse plugins

16,091 tracked
Wp Fancybox 6 Wp Fast Cache 2 Wp Fastest Cache 85 Wp Fastest Cache Premium 1 Wp Favorite Posts 4 Wp Fb Autoconnect 12 Wp Featherlight 1 Wp Feature Box 2 Wp Featured Content And Slider 3 Wp Featured Content Slider 2 Wp Featured Entries 2 Wp Featured Screenshot 1 Wp Fevents Book 4 Wp Fiddle 1 Wp File Checker 1 Wp File Download 3 Wp File Download Light 1 Wp File Get Contents 4 Wp File Manager 31 Wp File Manager Pro 16 Wp File Upload 68 Wp File Uploader 1 Wp Filebase 3 Wp Filemanager 5 Wp Film Studio 1 Wp Filter Combine Rss Feeds 1 Wp Filter Post Categories 1 Wp Finance 2 Wp Find Your Nearest 2 Wp Fixtag 1 Wp Flash Player 1 Wp Flashy Marketing Automation 1 Wp Flexible Map 1 Wp Flickr Press 1 Wp Flickrshow 1 Wp Flipclock 2 Wp Flipkart Importer 1 Wp Flipper 1 Wp Flipslideshow 1 Wp Floating Menu 1 Wp Flot 1 Wp Flybox 2 Wp Foft Loader 1 Wp Font Awesome 4 Wp Font Awesome Share Icons 1 Wp Font Pairing Preview 2 Wp Food 2 Wp Food Manager 2 Wp Foodbakery 10 Wp Football 2 Wp Footnotes 1 Wp Force Images Download 2 Wp Force Ssl 1 Wp Forecast 4 Wp Forms Connector 2 Wp Forms Puzzle Captcha 6 Wp Forms Signature Contract Add On 2 Wp Forum 3 Wp Fountain 1 Wp Fpo 1

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free