HomeWordPress plugin vulnerabilities
WordPress plugin vulnerabilities
Search our live WordPress vulnerability database for published security issues affecting plugins, themes and WordPress core. Check affected versions, available fixes and severity before deciding what action your site needs.
- 21,256 vulnerabilities on record
- 50 published in the last 24 hours
- 513 in the last 7 days
- Last checked 1 min ago
Latest WordPress vulnerabilities
| Plugin or theme | Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|---|
| Forminator Forms - Contact Form, Payment Form & Custom Form Builder 600,000+ installs | Broken access control CVE-2026-96335 | High 7.5 | Up to 1.57.2 | Fixed in a later version (latest 1.57.3) | 6 h ago |
| The Events Calendar 600,000+ installs | PHP object injection CVE-2026-95606 | Critical 9.8 | Up to 6.17.4 | Fixed in a later version (latest 6.18.0) | 6 h ago |
| WP Data Access - App Builder for Tables, Forms, Charts, Maps & Dashboards 10,000+ installs | SQL injection CVE-2026-95605 | Critical 9.3 | Up to 5.5.82 | Fixed in a later version (latest 5.5.85) | 6 h ago |
| Disable and Remove Google Fonts | GDPR & DSGVO friendly 100,000+ installs | Cross-site scripting (XSS) CVE-2026-95595 | High 7.1 | Up to 2.0.2 | Fixed in a later version (latest 2.0.3) | 6 h ago |
| Unlimited Elements for Elementor 300,000+ installs | PHP object injection CVE-2026-95534 | High 8.8 | Up to 2.0.19 | Fixed in a later version (latest 2.0.21) | 6 h ago |
| Everest Forms - Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI 90,000+ installs | Cross-site scripting (XSS) CVE-2026-94670 | High 7.1 | Up to 3.6.1 | Fixed in a later version (latest 3.6.2) | 6 h ago |
| Unlimited Elements for Elementor 300,000+ installs | Cross-site scripting (XSS) CVE-2026-94662 | High 7.1 | Up to 2.0.19 | Fixed in a later version (latest 2.0.21) | 6 h ago |
| WP Post Author - Author Box, Multiple Authors, Guest Authors & Custom Avatars 10,000+ installs | SQL injection CVE-2026-42708 | High 7.6 | Up to 4.0.0 | No fixed version yet | 11 h ago |
| Slider by 10Web - Responsive Image Slider 10,000+ installs | SQL injection CVE-2026-42710 | High 7.6 | Up to 1.2.63 | No fixed version yet | 11 h ago |
| Post title marquee scroll | SQL injection CVE-2026-42713 | High 7.6 | Up to 9.9 | Check for an update | 12 h ago |
| Pix por Piggly (para Woocommerce) 4,000+ installs | SQL injection CVE-2026-42714 | High 7.6 | Up to 2.1.2 | No fixed version yet | 12 h ago |
| Dynamic User Directory 1,000+ installs | SQL injection CVE-2026-42720 | High 7.6 | Up to 2.4 | No fixed version yet | 13 h ago |
| affiliate-toolkit - Multi-Network Affiliate & Amazon Product Display 2,000+ installs | SQL injection CVE-2026-42721 | High 7.6 | Up to 3.9.1 | No fixed version yet | 13 h ago |
| sc Internet Vivoo WP Rentals wprentals | Broken access control CVE-2026-27434 | Medium 5.3 | Up to 3.14.2 | Check for an update | 13 h ago |
| Booktics - Appointment Booking Calendar for Service Businesses 800+ installs | Broken access control CVE-2026-104390 | Medium 4.3 | Up to 1.0.27 | No fixed version yet | 14 h ago |
Being exploited in real attacks
WordPress plugin vulnerabilities on the US CISA Known Exploited Vulnerabilities list. If you run one of these, update today.
| Plugin or theme | Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|---|
| WordPress core | SQL injection Exploited in the wild CVE-2026-60137 | Medium 5.9 | Before 7.0.2 | Fixed in 7.0.2 | 17 Jul 2026 |
| WordPress core | SQL injection Exploited in the wild CVE-2026-63030 | Critical 9.8 | Before 7.0.2 | Fixed in 7.0.2 | 17 Jul 2026 |
| Social Sharing Plugin - Social Warfare 10,000+ installs | Cross-site scripting (XSS) Exploited in the wild CVE-2019-9978 | Medium 6.1 | Before 3.5.3 | Fixed in 3.5.3 | 24 Mar 2019 |
| Duplicator - Backups & Migration Plugin - Cloud Backups, Scheduled Backups, & More 1m+ installs | Path traversal Exploited in the wild CVE-2020-11738 | High 7.5 | Before 3.8.7.1 | Fixed in 3.8.7.1 | 13 Apr 2020 |
| File Manager 1m+ installs | Arbitrary file upload Exploited in the wild CVE-2020-25213 | Critical 10.0 | Before 6.9 | Fixed in 6.9 | 9 Sep 2020 |
Popular plugins with recent vulnerabilities
Plugins with 100,000+ active installs and at least one vulnerability in the last 4 months.
- Forminator Forms - Contact Form, Payment Form & Custom Form Builder21 vulnerabilities, latest 6 h ago600,000+ installs
- The Events Calendar3 vulnerabilities, latest 6 h ago600,000+ installs
- Disable and Remove Google Fonts | GDPR & DSGVO friendly1 vulnerability, latest 6 h ago100,000+ installs
- Unlimited Elements for Elementor18 vulnerabilities, latest 6 h ago300,000+ installs
- Modula Image Gallery - Photo Grid & Video Gallery3 vulnerabilities, latest 14 h ago100,000+ installs
- HappyAddons for Elementor - 160 Elementor Widgets, GSAP Animations & Templates2 vulnerabilities, latest 14 h ago400,000+ installs
- Prime Slider - Hero Slider, Carousel, WooCommerce & Post Slider Elementor Addons1 vulnerability, latest 14 h ago100,000+ installs
- LazyLoad Plugin - Lazy Load Images, Videos, and Iframes1 vulnerability, latest 14 h ago100,000+ installs
- Element Pack Addons for Elementor - Elementor Widgets, Elementor Templates, Elementor Addons4 vulnerabilities, latest 14 h ago100,000+ installs
- OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.2 vulnerabilities, latest 14 h ago300,000+ installs
- MetForm - Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor6 vulnerabilities, latest 16 h ago600,000+ installs
- Optimole - Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization6 vulnerabilities, latest 17 h ago200,000+ installs
How our WordPress vulnerability database is built
We collect public vulnerability records rather than discovering vulnerabilities ourselves. The database combines CVE records from the CVE List, including records published by CVE Numbering Authorities such as Wordfence, Patchstack and WPScan, with enrichment from the US National Vulnerability Database and plugin information from the WordPress.org plugin directory.
New CVE records are checked every 10 minutes. NVD details are refreshed hourly, while WordPress.org plugin information such as the current version, active install count and directory status is refreshed daily. The database includes historical WordPress CVEs going back to 2010 as well as newly published records.
A published vulnerability does not mean every website using that plugin has been attacked. It means a security issue has been publicly recorded. The practical question is whether your site runs the affected software and, if so, whether your installed version falls inside the vulnerable range.
How to read a WordPress CVE entry
Start with the affected product and version range. If the entry says versions up to a particular release are affected, compare that information with the version shown in your WordPress Plugins screen. Then look for a fixed version or later safe release.
Severity is based on the CVSS score published with the CVE where one is available. CVSS is a severity measure, not a complete measure of risk. A high score deserves attention, but your real priority also depends on factors such as whether exploitation requires authentication, whether the plugin is active on your site and whether the vulnerable function is exposed.
If a plugin is shown as closed in the WordPress.org directory, that tells you it is not currently available there. It does not by itself prove that your installed copy is compromised or that no fix exists. Check the vulnerability record, the plugin vendor's information and your installed version before acting.
What to do if a plugin you use is listed
First, confirm the exact plugin and installed version. If a fixed version is available, take a current backup and update promptly. Do not assume that deactivating a plugin removes all risk if vulnerable files remain on the server, particularly where a disclosure involves code that can be reached directly.
If no fixed version exists, assess whether the plugin can be disabled and removed or replaced without breaking a critical site function. For business critical sites, test the change on staging where possible before removing a component from production.
After dealing with the vulnerable software, check for signs that the site may already have been altered. Review administrator accounts, recently changed files, unexpected pages or redirects, security logs and Google Search Console security warnings. If compromise is suspected, preserve a copy before cleaning so there is a record of what changed and investigate the entry point rather than only deleting visible files. Our website security guidance explains the wider checks. Care plans from £59 a month include weekly WordPress updates, security scanning and daily backups. Hacked Site Rescue is available at £249 if the site is already compromised.
Free alerts for new plugin vulnerabilities
You can request a free email alert for a plugin you want to watch. After you confirm the subscription by email, we will notify you when a new vulnerability record is published for that plugin. Every alert email includes an unsubscribe link.
Alerts are useful for keeping watch on important plugins, but they do not replace normal update and security routines. A vulnerability may be disclosed after a fix is already available, and not every security problem receives a CVE immediately. Keep WordPress, themes and plugins maintained, remove software you no longer use and review your site when an alert applies to something you actually run.
Sources and further reading
Common questions
Answers to the questions we hear most about this.
What is a WordPress plugin vulnerability?
It is a security weakness in a WordPress plugin that could allow unintended access, actions or data exposure under particular conditions. The exact impact depends on the vulnerability, affected versions and how the plugin is used.
Does a vulnerability listing mean my website has been hacked?
No. A listing means a vulnerability has been publicly recorded. You still need to check whether your site uses the affected plugin and version, and whether there are signs of compromise.
How often is the WordPress vulnerability database updated?
New CVE records are checked every 10 minutes. NVD details are refreshed hourly and WordPress.org plugin details are refreshed daily.
What should I do if there is no fixed version?
Consider disabling and removing the affected plugin, or replacing it with a maintained alternative, after checking the effect on the site. If the plugin is business critical, test the change before applying it to production where possible.
Are CVSS scores the same as the risk to my website?
No. CVSS describes technical severity. Your actual risk also depends on whether you run the affected version, whether exploitation requires authentication, how the plugin is exposed and what controls are already in place.
Not sure if your site is affected?
Tell us which plugins you run and we will check them against the database and update what needs updating.