WordPress Vulnerability Database

Search 67,880+ known security issues across 16,100 plugins and 2,157 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

high Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret Wp Plugin Hostgator · Sep 8, 2026 · CVE-2026-80099 high Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret Wp Module Data · Sep 8, 2026 · CVE-2026-80099 high Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret Wp Plugin Crazy Domains · Sep 8, 2026 · CVE-2026-80099 high Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret Bluehost Wordpress Plugin · Sep 8, 2026 · CVE-2026-80099 high Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret Wp Plugin Web · Sep 8, 2026 · CVE-2026-80099 high YITH WooCommerce Waitlist Premium <= 3.35.0 - Authenticated (Subscriber+) Privilege Escalation to Admin via wp_ajax_yith_wcwtl_add_user Yith Woocommerce Waiting List Premium · Sep 8, 2026 · CVE-2026-14359 high Cookie Banner for GDPR / CCPA <= 4.4.1 - Unauthenticated Stored Cross-Site Scripting via 'wpl_user_preference' Parameter Gdpr Cookie Consent · Sep 8, 2026 · CVE-2026-14989 medium myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute Mycred · Sep 8, 2026 · CVE-2026-17149 medium Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) <= 4.1.22 - Authenticated (Subscriber+) Missing Authorization to Order Completion / Free Ticket Redemption Wp Event Solution · Sep 8, 2026 · CVE-2026-15398 medium WPMR Google Feed Manager for WooCommerce <= 2.23.7 - Authenticated (Administrator+) SQL Injection via 'feed' Parameter Wp Product Feed Manager · Sep 8, 2026 · CVE-2026-19778 high PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant Capability Manager Enhanced · Sep 8, 2026 · CVE-2026-75927 medium Checkout Custom Fields Builder for WooCommerce <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation via 'plugin' Parameter Checkout Custom Fields Builder For Woocommerce · Sep 8, 2026 · CVE-2026-19802

Browse plugins

16,100 tracked
Zoho Forms 3 Zoho Marketinghub 1 Zoho Salesiq 4 Zoho Subscriptions 2 Zohocreator 1 Zoloblocks 11 Zombify 1 Zoom Image Shortcode 2 Zooom 1 Zoorum Comments 2 Zopim Live Chat 1 Zotpress 19 Zportals 1 Zstore Manager Basic 1 Zt Captcha 1 Zuppler Online Ordering 1 Zweb Social Mobile 2 Zx Csv Upload 1 Zynith Seo 3 Zypento Blocks 1

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free