WordPress Vulnerability Database

Search 67,561+ known security issues across 16,057 plugins and 2,156 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

critical Nokri - Job Board WordPress Theme <= 1.6.6 - Unauthenticated Privilege Escalation via 'token' Parameter Nokri · Aug 31, 2026 · CVE-2026-18550 medium WPBakery Page Builder <= 8.7.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'data' Parameter Js Composer · Aug 31, 2026 · CVE-2026-15101 high Welcart e-Commerce <= 2.12.1 - Unauthenticated Stored Cross-Site Scripting via 'custom_order' Parameter Usc E Shop · Aug 31, 2026 · CVE-2026-19914 medium Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode Live Composer Page Builder · Aug 31, 2026 · CVE-2026-16786 medium Live Composer <= 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_projects_output Shortcode Live Composer Page Builder · Aug 31, 2026 · CVE-2026-16788 medium Blocksy Companion <= 2.1.51 - Authenticated (Author+) Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) Blocksy Companion · Aug 31, 2026 · CVE-2026-18488 medium User Profile Builder <= 4.0.0 - Unauthenticated Stored Cross-Site Scripting via 'email' Parameter Profile Builder · Aug 31, 2026 · CVE-2026-75964 medium Charitable <= 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'order' Shortcode Attribute Charitable · Aug 31, 2026 · CVE-2026-77189 medium BetterDocs <= 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content Betterdocs · Aug 31, 2026 · CVE-2026-75980 medium User Profile Builder <= 4.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'date' Shortcode Attribute Profile Builder · Aug 31, 2026 · CVE-2026-75965 high Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token Support Genix Lite · Aug 31, 2026 · CVE-2026-19806 medium Shopping Cart & eCommerce Store <= 5.9.2 - Authenticated (Administrator+) SQL Injection via 'product_order' Parameter Wp Easycart · Aug 31, 2026 · CVE-2026-17589

Browse plugins

16,057 tracked
Card Flip Image Slideshow 2 Card Oracle 1 Cardealer 3 Cardealerpress 2 Cardgate 6 Cardinity Free Payment Gateway For Woocommerce 1 Cardoza 3D Tag Cloud 2 Cardoza Ajax Search 1 Cardoza Facebook Like Box 2 Cardoza Wordpress Poll 9 Career Section 4 Caret Country Access Limit 1 Cargo Shipping Location For Woocommerce 1 Cargus 1 Carousel 2 Carousel Anything 2 Carousel Ck 1 Carousel Horizontal Posts Content Slider 1 Carousel Of Post Images 1 Carousel Slider 15 Carousels Slider For Divi 1 Carrrot 1 Cars Seller Auto Classifieds Script 1 Cart Lift 4 Cart Link For Woocommerce 1 Cart Notices For Woocommerce 1 Cart Products Suggestions For Woocommerce 1 Cart Rest Api For Woocommerce 3 Cart Tracking For Woocommerce 2 Cart Weight For Woocommerce 1 Cart2Cart Magento To Woocommerce Migration 1 Cart66 Cloud 2 Cart66 Lite 10 Carta Online 2 Cartasi X Pay 2 Cartboss 2 Carter Elementor 2 Cartflows 21 Cartflows Pro 2 Cartoon Url 1 Cartpauj Register Captcha 1 Cartpops 1 Carts Guru 1 Cas Maestro 1 Case Addons 2 Case Study 1 Case Theme User 2 Cashbill Payment Method 1 Cashtomer 1 Casso Tu Dong Xac Nhan Thanh Toan Chuyen Khoan Ngan Hang 1 Catablog 8 Catalog 1 Catalog Mode Pricing Enquiry Forms Promotions 1 Catalyst Connect Client Portal 3 Catch Breadcrumb 2 Catch Dark Mode 2 Catch Duplicate Switcher 4 Catch Gallery 1 Catch Ids 1 Catch Import Export 1

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free