Recent
Vulnerabilities.
WordPress plugin and theme CVEs published in the last 30 days, sorted by severity. Updated continuously from the Wordfence Intelligence feed.
100 vulnerabilities found
Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
WordPress · CVSS 7.5 · Jul 15, 2026
Podlove Podcast Publisher <= 4.5.1 - Unauthenticated Arbitrary File Upload via podlove_image_cache_url Parameter
Podlove Podcast Publisher · CVSS 9.8 · Jul 14, 2026
WP Customer Area <= 8.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'type' Shortcode Attribute
WP Customer Area · CVSS 6.4 · Jul 13, 2026
FoodBook Lite <= 1.5.6 - Missing Authorization to Unauthenticated User Registration via 'registration_action' AJAX Action
FoodBook Lite – Online Food Ordering System · CVSS 5.3 · Jul 13, 2026
News Kit Addons For Elementor <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets
News Kit Addons For Elementor · CVSS 6.4 · Jul 13, 2026
Avada Builder <= 3.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Module Title
WordPress · CVSS 6.4 · Jul 13, 2026
Smart Slider 3 <= 3.5.1.37 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via WP_Query Parameter Injection via 'keyword' Parameter
Smart Slider 3 · CVSS 4.3 · Jul 13, 2026
Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'
WordPress · CVSS 9.8 · Jul 13, 2026
Academy LMS <= 3.8.0 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'user_id' Parameter
Academy LMS – WordPress LMS Plugin for Complete eLearning Solution · CVSS 4.3 · Jul 13, 2026
sync-basalam <= 3.0.2 - Authenticated (Administrator+) SQL Injection
گرویتی فرم فارسی · CVSS 4.9 · Jul 12, 2026
sync-basalam <= 1.9.1 - Cross-Site Request Forgery
ووسلام – همگام سازی ووکامرس و باسلام · CVSS 4.3 · Jul 12, 2026
Bulk Edit Products for WooCommerce – WP Sheet Editor <= 1.8.21 - Missing Authorization
Bulk Edit Products for WooCommerce – WP Sheet Editor · CVSS 4.3 · Jul 12, 2026
Genolve – AI image AI video generation <= 5.0.5 - Authenticated (Contributor+) Incorrect Authorization to Privilege Escalation via theopt
Genolve – AI image AI video generation · CVSS 8.8 · Jul 10, 2026
W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read via 'f_array[]' Parameter
W3 Total Cache · CVSS 7.5 · Jul 10, 2026
NEX-Forms <= 9.2.2 - Missing Authorization to Unauthenticated Arbitrary Form Entry Modification via nf_send_nf_email AJAX Action
NEX-Forms – Ultimate Forms Plugin for WordPress · CVSS 5.3 · Jul 10, 2026
bbp style pack <= 6.4.5 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Topic Form Additional Fields
bbp style pack · CVSS 6.4 · Jul 10, 2026
Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
Cost Calculator Builder · CVSS 5.3 · Jul 10, 2026
Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
Wallet for WooCommerce · CVSS 4.3 · Jul 10, 2026
fresh Podcaster <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'freshpodcaster' Shortcode Attributes
fresh Podcaster · CVSS 6.4 · Jul 10, 2026
Catalyst Connect Zoho CRM Client Portal <= 2.2.0 - Authenticated (Administrator+) SQL Injection via uid Parameter
Catalyst Connect Zoho CRM Client Portal · CVSS 4.9 · Jul 10, 2026
Context Blog <= 1.3.5 - Unauthenticated Sensitive Information Exposure via 'postID' Parameter
Context Blog · CVSS 5.3 · Jul 10, 2026
WP CTA <= 2.2.2 - Unauthenticated Time-Based Blind SQL Injection via 'fildname' Parameter
WP CTA – Call Now Button, Sticky Button & Call to Action Builder · CVSS 7.5 · Jul 10, 2026
WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Missing Authorization to Unauthenticated Arbitrary Inquiry Reply Injection via wcfm-my-account-enquiry-manage Controller
WCFM – Frontend Manager for WooCommerce · CVSS 5.3 · Jul 10, 2026
WP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN Handler
WP Hotel Booking · CVSS 5.3 · Jul 10, 2026
WP Easy Pay <= 4.5.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Status Modification via wpep_draft_confirm AJAX Action
WP Easy Pay – Payment and Donation form Builder for Square · CVSS 4.3 · Jul 10, 2026
Widgets for Google Reviews <= 13.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'fomo-title' and 'fomo-text' Parameters
Widgets for Google Reviews · CVSS 4.4 · Jul 10, 2026
Essential Addons for Elementor <= 6.6.10 - Authenticated (Contributor+) Account Takeover via Email Header Injection
Essential Addons for Elementor – Popular Elementor Templates & Widgets · CVSS 8.8 · Jul 10, 2026
White Label CMS <= 2.7.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via Import Settings
White Label CMS · CVSS 4.4 · Jul 10, 2026
CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Stored Cross-Site Scripting via 'approval_code' Parameter
CorvusPay WooCommerce Payment Gateway · CVSS 7.2 · Jul 10, 2026
Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution
Code Engine · CVSS 8.8 · Jul 10, 2026
WCFM – Frontend Manager for WooCommerce <= 6.7.27 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Vendor Data Manipulation via Multiple AJAX Handlers
WCFM – Frontend Manager for WooCommerce · CVSS 4.3 · Jul 10, 2026
WCFM Marketplace <= 3.7.3 - Authenticated (Vendor+) Stored Cross-Site Scripting via Attachment 'post_title'
WCFM Marketplace – Multivendor Marketplace for WooCommerce · CVSS 6.4 · Jul 10, 2026
Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field
Form Vibes – Database Manager for Forms · CVSS 7.2 · Jul 10, 2026
SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook
SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payments · CVSS 8.1 · Jul 10, 2026
ThriveDesk <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Cache Deletion
Agentic Help Desk Plugin for WordPress – Live Chat, AI Chatbot & Ticketing – ThriveDesk · CVSS 4.3 · Jul 10, 2026
Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Map Module 'b_width_map' Field
Themify Builder · CVSS 6.4 · Jul 10, 2026
Themify Builder <= 7.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height_slider' Slider Module Field
Themify Builder · CVSS 6.4 · Jul 10, 2026
SurfLink < 2.6.0 - Missing Authorization to Authenticated (Subscriber+) 410 Gone URL Import via 'surfl_import_410' AJAX Action
SurfLink – Link Manager & Backup Restore · CVSS 4.3 · Jul 10, 2026
Swiss Toolkit For WP <= 1.4.6 - Authenticated (Author+) Arbitrary File Upload via upload_extension_files()
Swiss Toolkit For WP · CVSS 8.8 · Jul 10, 2026
Starboard Suite Reservation Calendars <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
Starboard Suite Reservation Calendars · CVSS 6.4 · Jul 10, 2026
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Modification via 'publishTasks' and 'unpublishTasks' AJAX Actions
AI Chatbot & Workflow Automation by AIWU · CVSS 5.3 · Jul 10, 2026
AI Chatbot & Workflow Automation by AIWU <= 1.4.12 - Missing Authorization to Unauthenticated Arbitrary Data Deletion via AJAX Actions 'removeGroup' and 'clear'
AI Chatbot & Workflow Automation by AIWU · CVSS 5.3 · Jul 10, 2026
Affilia <= 3.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Status Modification
Affilia – Affiliate Program & Referral Tracking for WordPress · CVSS 4.3 · Jul 10, 2026
Solace Extra <= 1.5.3 - Missing Authorization to Unauthenticated Arbitrary Content Deletion via delete_previously_imported AJAX Action
Solace Extra · CVSS 5.3 · Jul 10, 2026
Simple JWT Login <= 3.6.6 - Authenticated (Subscriber+) Authentication Bypass to Privilege Escalation via 'payload' Parameter
Simple JWT Login – Allows you to use JWT on REST endpoints. · CVSS 8.8 · Jul 10, 2026
Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter
Premium Addons for Elementor – Powerful Elementor Templates & Widgets · CVSS 4.9 · Jul 10, 2026
Print, PDF, Email by PrintFriendly <= 5.5.10 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'content_position_css' Parameter
Print, PDF, Email by PrintFriendly · CVSS 4.4 · Jul 10, 2026
Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter
Planyo online reservation system · CVSS 7.2 · Jul 10, 2026
PDF Invoices & Packing Slips for WooCommerce <= 5.14.0 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via 'order_id' Shortcode Attribute
PDF Invoices & Packing Slips for WooCommerce · CVSS 4.3 · Jul 10, 2026
Notification for Telegram <= 3.5.1 - Missing Authorization to Authenticated (Subscriber+) Cron Modification via nftb_cron_action_set AJAX Action
Notification for Telegram · CVSS 4.3 · Jul 10, 2026
Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin · CVSS 6.5 · Jul 10, 2026
MyParcel <= 4.25.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Data Disclosure and Modification via wcmp_get_shipment_options and wcmp_save_shipment_options AJAX Actions
MyParcel · CVSS 4.3 · Jul 10, 2026
Mux Video Uploader <= 1.1.4 - Authenticated (Subscriber+) Information Exposure
Mux Video Uploader · CVSS 4.3 · Jul 10, 2026
LA-Studio Element Kit for Elementor <= 1.6.1 - Authenticated (Contributor+) Local File Inclusion via 'progress_type' Widget Setting
LA-Studio Element Kit for Elementor · CVSS 7.5 · Jul 10, 2026
Motors <= 1.4.112 - Unauthenticated Stored Cross-Site Scripting via Comment Content and User Biographical Info
Motors – Car Dealership & Classified Listings Plugin · CVSS 7.2 · Jul 10, 2026
Mixed Media Gallery Blocks <= 3.3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via sliderMaxHeight Block Attribute
Mixed Media Gallery Blocks · CVSS 6.4 · Jul 10, 2026
Members <= 3.2.22 - Unauthenticated Sensitive Information Disclosure via REST API Pagination Side Channel
Members – Membership & User Role Editor Plugin · CVSS 5.3 · Jul 10, 2026
Lockme OAuth2 calendars integration <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'App ID' Setting
Lockme calendars integration · CVSS 4.4 · Jul 10, 2026
KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in KCQueryBuilder
KiviCare – Clinic & Patient Management System (EHR) · CVSS 6.5 · Jul 10, 2026
KiviCare <= 4.5.0 - Authenticated (Doctor+) SQL Injection via 'orderby' Parameter in DoctorSessionController
KiviCare – Clinic & Patient Management System (EHR) · CVSS 6.5 · Jul 10, 2026
Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions
Points and Rewards for WooCommerce · CVSS 4.3 · Jul 10, 2026
WP Ultimate CSV Importer <= 8.0.1 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via 'MappedFields' Parameter
WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress · CVSS 8.8 · Jul 10, 2026
UnderConstructionPage PRO <= 5.76 - Authenticated (Subscriber+) Arbitrary File Read via template_thumbnail Parameter
Under Construction · CVSS 6.5 · Jul 10, 2026
WP Grid Builder <= 2.3.3 - Authenticated (Subscriber+) Privilege Escalation via 'key' Parameter
WordPress · CVSS 8.8 · Jul 10, 2026
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow
miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) · CVSS 9.8 · Jul 10, 2026
SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()
SEO Plugin by Squirrly SEO · CVSS 7.2 · Jul 10, 2026
Booking Package <= 1.7.20 - Unauthenticated SQL Injection via 'email' Form Parameter
Booking Package · CVSS 7.5 · Jul 10, 2026
WPZOOM Portfolio Lite – Filterable Portfolio Plugin <= 1.4.29 - Unauthenticated Stored Cross-Site Scripting
WPZOOM Portfolio Lite – Filterable Portfolio Plugin · CVSS 7.2 · Jul 10, 2026
ICS Calendar <= 12.1.1 - Unauthenticated Stored Cross-Site Scripting
ICS Calendar · CVSS 7.2 · Jul 10, 2026
FunnelKit – Funnel Builder for WooCommerce Checkout <= 3.15.0.8 - Unauthenticated Stored Cross-Site Scripting
FunnelKit – Funnel Builder for WooCommerce Checkout · CVSS 7.2 · Jul 10, 2026
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy <= 5.0.6 - Unauthenticated Stored Cross-Site Scripting
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy · CVSS 7.2 · Jul 10, 2026
NEX-Forms – Ultimate Forms Plugin for WordPress <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting
NEX-Forms – Ultimate Forms Plugin for WordPress · CVSS 7.2 · Jul 10, 2026
Document Gallery <= 5.1.0 - Unauthenticated Stored Cross-Site Scripting
Document Gallery · CVSS 7.2 · Jul 10, 2026
Database for Contact Form 7, WPforms, Elementor forms <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting
Database for Contact Form 7, WPforms, Elementor forms · CVSS 7.2 · Jul 10, 2026
Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting
WordPress · CVSS 7.2 · Jul 10, 2026
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 - Authenticated (Customer+) Stored Cross-Site Scripting
SupportCandy – Helpdesk & Customer Support Ticket System · CVSS 6.4 · Jul 10, 2026
Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recipients' Parameter
Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails · CVSS 4.9 · Jul 9, 2026
Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter
Logo Slider – Logo Carousel, Logo Showcase & Client Logo Slider Plugin · CVSS 6.4 · Jul 9, 2026
KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint
KiviCare – Clinic & Patient Management System (EHR) · CVSS 5.3 · Jul 9, 2026
JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute
JoomSport – for Sports: Team & League, Football, Hockey & more · CVSS 6.5 · Jul 9, 2026
Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress · CVSS 6.4 · Jul 9, 2026
Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions
Invoice123 · CVSS 4.3 · Jul 9, 2026
Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action
Import and export users and customers · CVSS 4.3 · Jul 9, 2026
ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter
ICS Calendar · CVSS 6.1 · Jul 9, 2026
Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode
Hostel · CVSS 6.4 · Jul 9, 2026
Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting
Highlighting Code Block · CVSS 4.4 · Jul 9, 2026
HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms · CVSS 6.6 · Jul 9, 2026
GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion
GW AI Website Builder · CVSS 4.3 · Jul 9, 2026
GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'
GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference · CVSS 4.3 · Jul 9, 2026
Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 6.4 · Jul 9, 2026
FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints
FlowForms – Conversational Form Builder for WordPress · CVSS 4.3 · Jul 9, 2026
Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) · CVSS 5.3 · Jul 9, 2026
Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter
Easy Upload Files During Checkout · CVSS 5.3 · Jul 9, 2026
Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation
Easy Appointments · CVSS 4.3 · Jul 9, 2026
Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent · CVSS 4.9 · Jul 9, 2026
Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action
Cookie Banner for GDPR / CCPA – WPLP Cookie Consent · CVSS 4.3 · Jul 9, 2026
BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor · CVSS 6.5 · Jul 9, 2026
Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter
Hide My WP Lite · CVSS 7.5 · Jul 9, 2026
All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter
All-in-One Video Gallery · CVSS 6.4 · Jul 9, 2026
Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter
Salon Booking System – Free Version · CVSS 8.8 · Jul 9, 2026