Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress plugin vulnerabilities

WordPress plugin vulnerabilities

Search our live WordPress vulnerability database for published security issues affecting plugins, themes and WordPress core. Check affected versions, available fixes and severity before deciding what action your site needs.

  • 21,256 vulnerabilities on record
  • 50 published in the last 24 hours
  • 513 in the last 7 days
  • Last checked 1 min ago

Latest WordPress vulnerabilities

See everything from the last 7 days

Plugin or themeVulnerabilitySeverityAffectedFixPublished
Forminator Forms - Contact Form, Payment Form & Custom Form Builder
600,000+ installs
Broken access control
CVE-2026-96335
High 7.5Up to 1.57.2Fixed in a later version (latest 1.57.3)6 h ago
The Events Calendar
600,000+ installs
PHP object injection
CVE-2026-95606
Critical 9.8Up to 6.17.4Fixed in a later version (latest 6.18.0)6 h ago
WP Data Access - App Builder for Tables, Forms, Charts, Maps & Dashboards
10,000+ installs
SQL injection
CVE-2026-95605
Critical 9.3Up to 5.5.82Fixed in a later version (latest 5.5.85)6 h ago
Disable and Remove Google Fonts | GDPR & DSGVO friendly
100,000+ installs
Cross-site scripting (XSS)
CVE-2026-95595
High 7.1Up to 2.0.2Fixed in a later version (latest 2.0.3)6 h ago
Unlimited Elements for Elementor
300,000+ installs
PHP object injection
CVE-2026-95534
High 8.8Up to 2.0.19Fixed in a later version (latest 2.0.21)6 h ago
Everest Forms - Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI
90,000+ installs
Cross-site scripting (XSS)
CVE-2026-94670
High 7.1Up to 3.6.1Fixed in a later version (latest 3.6.2)6 h ago
Unlimited Elements for Elementor
300,000+ installs
Cross-site scripting (XSS)
CVE-2026-94662
High 7.1Up to 2.0.19Fixed in a later version (latest 2.0.21)6 h ago
WP Post Author - Author Box, Multiple Authors, Guest Authors & Custom Avatars
10,000+ installs
SQL injection
CVE-2026-42708
High 7.6Up to 4.0.0No fixed version yet11 h ago
Slider by 10Web - Responsive Image Slider
10,000+ installs
SQL injection
CVE-2026-42710
High 7.6Up to 1.2.63No fixed version yet11 h ago
Post title marquee scrollSQL injection
CVE-2026-42713
High 7.6Up to 9.9Check for an update12 h ago
Pix por Piggly (para Woocommerce)
4,000+ installs
SQL injection
CVE-2026-42714
High 7.6Up to 2.1.2No fixed version yet12 h ago
Dynamic User Directory
1,000+ installs
SQL injection
CVE-2026-42720
High 7.6Up to 2.4No fixed version yet13 h ago
affiliate-toolkit - Multi-Network Affiliate & Amazon Product Display
2,000+ installs
SQL injection
CVE-2026-42721
High 7.6Up to 3.9.1No fixed version yet13 h ago
sc Internet Vivoo WP Rentals wprentalsBroken access control
CVE-2026-27434
Medium 5.3Up to 3.14.2Check for an update13 h ago
Booktics - Appointment Booking Calendar for Service Businesses
800+ installs
Broken access control
CVE-2026-104390
Medium 4.3Up to 1.0.27No fixed version yet14 h ago

Being exploited in real attacks

WordPress plugin vulnerabilities on the US CISA Known Exploited Vulnerabilities list. If you run one of these, update today.

Plugin or themeVulnerabilitySeverityAffectedFixPublished
WordPress coreSQL injection
Exploited in the wild
CVE-2026-60137
Medium 5.9Before 7.0.2Fixed in 7.0.217 Jul 2026
WordPress coreSQL injection
Exploited in the wild
CVE-2026-63030
Critical 9.8Before 7.0.2Fixed in 7.0.217 Jul 2026
Social Sharing Plugin - Social Warfare
10,000+ installs
Cross-site scripting (XSS)
Exploited in the wild
CVE-2019-9978
Medium 6.1Before 3.5.3Fixed in 3.5.324 Mar 2019
Duplicator - Backups & Migration Plugin - Cloud Backups, Scheduled Backups, & More
1m+ installs
Path traversal
Exploited in the wild
CVE-2020-11738
High 7.5Before 3.8.7.1Fixed in 3.8.7.113 Apr 2020
File Manager
1m+ installs
Arbitrary file upload
Exploited in the wild
CVE-2020-25213
Critical 10.0Before 6.9Fixed in 6.99 Sep 2020

Popular plugins with recent vulnerabilities

Plugins with 100,000+ active installs and at least one vulnerability in the last 4 months.

How our WordPress vulnerability database is built

We collect public vulnerability records rather than discovering vulnerabilities ourselves. The database combines CVE records from the CVE List, including records published by CVE Numbering Authorities such as Wordfence, Patchstack and WPScan, with enrichment from the US National Vulnerability Database and plugin information from the WordPress.org plugin directory.

New CVE records are checked every 10 minutes. NVD details are refreshed hourly, while WordPress.org plugin information such as the current version, active install count and directory status is refreshed daily. The database includes historical WordPress CVEs going back to 2010 as well as newly published records.

A published vulnerability does not mean every website using that plugin has been attacked. It means a security issue has been publicly recorded. The practical question is whether your site runs the affected software and, if so, whether your installed version falls inside the vulnerable range.

How to read a WordPress CVE entry

Start with the affected product and version range. If the entry says versions up to a particular release are affected, compare that information with the version shown in your WordPress Plugins screen. Then look for a fixed version or later safe release.

Severity is based on the CVSS score published with the CVE where one is available. CVSS is a severity measure, not a complete measure of risk. A high score deserves attention, but your real priority also depends on factors such as whether exploitation requires authentication, whether the plugin is active on your site and whether the vulnerable function is exposed.

If a plugin is shown as closed in the WordPress.org directory, that tells you it is not currently available there. It does not by itself prove that your installed copy is compromised or that no fix exists. Check the vulnerability record, the plugin vendor's information and your installed version before acting.

What to do if a plugin you use is listed

First, confirm the exact plugin and installed version. If a fixed version is available, take a current backup and update promptly. Do not assume that deactivating a plugin removes all risk if vulnerable files remain on the server, particularly where a disclosure involves code that can be reached directly.

If no fixed version exists, assess whether the plugin can be disabled and removed or replaced without breaking a critical site function. For business critical sites, test the change on staging where possible before removing a component from production.

After dealing with the vulnerable software, check for signs that the site may already have been altered. Review administrator accounts, recently changed files, unexpected pages or redirects, security logs and Google Search Console security warnings. If compromise is suspected, preserve a copy before cleaning so there is a record of what changed and investigate the entry point rather than only deleting visible files. Our website security guidance explains the wider checks. Care plans from £59 a month include weekly WordPress updates, security scanning and daily backups. Hacked Site Rescue is available at £249 if the site is already compromised.

Free alerts for new plugin vulnerabilities

You can request a free email alert for a plugin you want to watch. After you confirm the subscription by email, we will notify you when a new vulnerability record is published for that plugin. Every alert email includes an unsubscribe link.

Alerts are useful for keeping watch on important plugins, but they do not replace normal update and security routines. A vulnerability may be disclosed after a fix is already available, and not every security problem receives a CVE immediately. Keep WordPress, themes and plugins maintained, remove software you no longer use and review your site when an alert applies to something you actually run.

Sources and further reading

Common questions

Answers to the questions we hear most about this.

What is a WordPress plugin vulnerability?

It is a security weakness in a WordPress plugin that could allow unintended access, actions or data exposure under particular conditions. The exact impact depends on the vulnerability, affected versions and how the plugin is used.

Does a vulnerability listing mean my website has been hacked?

No. A listing means a vulnerability has been publicly recorded. You still need to check whether your site uses the affected plugin and version, and whether there are signs of compromise.

How often is the WordPress vulnerability database updated?

New CVE records are checked every 10 minutes. NVD details are refreshed hourly and WordPress.org plugin details are refreshed daily.

What should I do if there is no fixed version?

Consider disabling and removing the affected plugin, or replacing it with a maintained alternative, after checking the effect on the site. If the plugin is business critical, test the change before applying it to production where possible.

Are CVSS scores the same as the risk to my website?

No. CVSS describes technical severity. Your actual risk also depends on whether you run the affected version, whether exploitation requires authentication, how the plugin is exposed and what controls are already in place.

Not sure if your site is affected?

Tell us which plugins you run and we will check them against the database and update what needs updating.

Get website support