WordPress Vulnerability Database

Search 67,535+ known security issues across 16,056 plugins and 2,156 themes. Find a plugin to see its vulnerabilities and affected versions.

Recently disclosed

critical MyHome Core <= 4.4.5 - Authentication Bypass to Account Takeover via Activation Token Myhome Core · Aug 29, 2026 · CVE-2026-15980 critical Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout User Registration Plugin For Woocommerce · Aug 29, 2026 · CVE-2026-15369 high SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning Miniorange Saml 20 Single Sign On · Aug 29, 2026 · CVE-2026-75807 critical GiveWP – Donation Plugin and Fundraising Platform <= 4.16.7.1 - Unauthenticated PHP Object Injection to Remote Code Execution Give · Aug 28, 2026 · CVE-2026-82222 critical Sigma Forms Pro <= 1.4.5 - Unauthenticated Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via Pre-built Template File Upload Field Sigmaforms Pro · Aug 28, 2026 · CVE-2026-14494 critical WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion Wpmudev Updates · Aug 27, 2026 · CVE-2026-76581 medium Avada (Fusion) Builder <= 3.15.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'size' Shortcode Attribute Fusion Builder · Aug 27, 2026 · CVE-2026-16654 medium Tutor LMS <= 4.0.5 - Unauthenticated Remote Code Execution via 'template' and 'data' POST Parameters Tutor · Aug 27, 2026 · CVE-2026-16759 high One User Avatar | User Profile Picture <= 2.5.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wpua-file Parameter One User Avatar · Aug 27, 2026 · CVE-2026-18983 high LiteSpeed Cache <= 7.8.1 - Unauthenticated Stored Cross-Site Scripting via Comment Content Litespeed Cache · Aug 27, 2026 · CVE-2026-18978 medium LiteSpeed Cache <= 7.7 - Authenticated (Author+) Stored Cross-Site Scripting via img Tag Attributes Litespeed Cache · Aug 27, 2026 · CVE-2026-3129 high Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field Forminator · Aug 27, 2026 · CVE-2026-18324

Browse plugins

16,056 tracked
Adapta Rgpd 4 Adaptive Images 8 Adblock Notify By Bweb 2 Adbuddy Adblocker Detection 2 Add Actions And Filters 8 Add Admin Css 2 Add Admin Javascript 2 Add Any Extension To Pages 5 Add Categories Post Footer 1 Add Code To Head 2 Add Comments 1 Add Custom Body Class 1 Add Custom Codes 8 Add Custom Content After Post 1 Add Custom Css And Js 2 Add Custom Fields To Media 2 Add Custom Google Tag Manager 1 Add Custom Page Template 1 Add Customer For Woocommerce 1 Add Edit Delete Listing For Member Module 3 Add Expires Headers 5 Add Facebook 2 Add Fields To Checkout Page Woocommerce 7 Add From Server 1 Add Google Plus One Social Share Button 2 Add Google Social Profiles To Knowledge Graph Box 2 Add Hierarchy Parent To Post 3 Add Image To Post 1 Add Infos To The Events Calendar 2 Add Instagram 1 Add Link To Facebook 3 Add Linked Images To Gallery V01 1 Add Local Avatar 2 Add Multiple Marker 3 Add Pinterest Conversion Tags 2 Add Polylang Support For Customizer 1 Add Posts To Pages 2 Add Product Frontend For Woocommerce 2 Add Replace Affiliate Links For Amazon 1 Add Ribbon 1 Add Rss 2 Add Search To Menu 36 Add Social Share 1 Add Social Share Buttons 1 Add Subtitle 1 Add Svg Support For Media Uploader Inventivo 1 Add Tabs Xforwc 5 Add Tiktok Advertising Pixel 1 Add To All 1 Add To Any 3 Add To Calendar Button 1 Add To Cart Button Labels For Woocommerce 1 Add To Cart Direct Checkout For Woocommerce 1 Add To Feedly 4 Add To Header 1 Add To Home Screen Wp 2 Add Twitter Pixel 1 Add User Meta 2 Add User Role 1 Add Whatsapp Button 1

Is your site running a vulnerable version?

A free scan detects the plugins and themes installed on your WordPress site and flags the ones with known security issues.

Scan your site free