Known Plugin Vulnerabilities
Track known vulnerabilities from configured sources. Default view shows all open and closed vulnerabilities, ordered by most recently updated first.
Open Vulnerabilities
36189Across tracked plugins
Affected Plugins
71With open vulnerabilities
Critical / High
0Require immediate attention
Recently Updated
0In the last 30 days
Vulnerability List
Export CSV| Plugin | Slug | Score | Vulnerability | CVE ID | Severity | Affected Versions | Patched | Updated |
|---|---|---|---|---|---|---|---|---|
| wp-twitter-feed | wp-twitter-feed | N/A | Peadig's Twitter Feed: Embedded Timeline WordPress Plugin <= 2.2 - Reflected Cross-Site Scripting | LOW | *-2.2 | June 28, 2026 | ||
| wptouch | wptouch | N/A | WPtouch < 1.9.20 - Cross-Site Scripting | LOW | [*, 1.9.20) | 1.9.20 | June 28, 2026 | |
| register-plus | register-plus | N/A | Register Plus <= 3.5.11 - Stored Cross-Site Scripting | LOW | *-3.5.11 | June 28, 2026 | ||
| register-plus | register-plus | N/A | Register Plus <= 3.5.11 - Sensitive Information Disclosure | LOW | *-3.5.11 | June 28, 2026 | ||
| event-registration | event-registration |
93
|
Event Registration < 6.00.03 - SQL Injection | LOW | [*, 6.00.03) | 6.00.03 | June 28, 2026 | |
| wp-survey-and-quiz-tool | wp-survey-and-quiz-tool | N/A | WP Survey And Quiz Tool < 1.3 - Cross-Site Scripting | LOW | [*, 1.3) | 1.3 | June 28, 2026 | |
| vodpod-video-gallery | vodpod-video-gallery | N/A | Vodpod Video Gallery <= 3.1.7 - Reflected Cross-Site Scripting | LOW | *-3.1.7 | June 28, 2026 | ||
| feedlist | feedlist |
93
|
FeedList <= 2.61.03 - Reflected Cross-Site Scripting | LOW | *-2.61.03 | 2.70.00 | June 28, 2026 | |
| cforms2 | cforms2 |
93
|
CformsII <=11.5 - Cross-Site Scripting | LOW | *-11.5 | 11.6.1 | June 28, 2026 | |
| mylinksdump | mylinksdump | N/A | myLinksDump <= 1.2 - SQL Injection | LOW | *-1.2 | June 28, 2026 | ||
| wp-useronline | wp-useronline | N/A | WP-UserOnline < 2.70 - Cross-Site Scripting | LOW | *-2.62 | 2.70 | June 28, 2026 | |
| Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | nextgen-gallery |
66
|
WordPress Gallery Plugin – NextGEN Gallery <= 1.5.1 - Cross-Site Scripting | LOW | [*, 1.5.2) | 1.5.2 | June 28, 2026 | |
| cpl | cpl |
91
|
Copperleaf Photolog <= 0.16- SQL injection | LOW | *-0.16 | June 28, 2026 | ||
| wp-cumulus | wp-cumulus | N/A | WP-Cumulus <= 1.22 - Cross-Site Scripting via tagcloud | LOW | *-1.22 | 1.23 | June 28, 2026 | |
| wp-cumulus | wp-cumulus | N/A | WP-Cumulus <= 1.20 - Sensitive Information Exposure | LOW | *-1.20 | 1.23 | June 28, 2026 | |
| woopra | woopra | N/A | Various Affected Software (Various Versions) - Arbitrary File Upload | LOW | *-1.4.3.1 | 1.4.3.2 | June 28, 2026 | |
| piwik-pro | piwik-pro | N/A | Various Affected Software (Various Versions) - Arbitrary File Upload | LOW | 0.2.35-0.4.3 | 0.4.4 | June 28, 2026 | |
| wp-forum | wp-forum | N/A | WP Forum <= 2.3 - Multiple SQL Injections | LOW | [*, 2.4) | 2.4 | June 28, 2026 | |
| wp-cumulus | wp-cumulus | N/A | WP Cumulus < 1.22 - Cross-Site Scripting | LOW | [*, 1.22) | 1.22 | June 28, 2026 | |
| google-analyticator | google-analyticator |
93
|
Google Analyticator <= 5.2 - Cross-Site Scripting | LOW | [*, 5.2.1) | 5.2.1 | June 28, 2026 | |
| my-category-order | my-category-order | N/A | my-category-order <= 2.8.7 - SQL Injection | LOW | *-2.8.7 | 3.0.1 | June 28, 2026 | |
| related-sites | related-sites | N/A | Related Sites <= 2.2 - SQL Injection | LOW | *-2.2 | 2.2.1 | June 28, 2026 | |
| dm-albums | dm-albums |
91
|
DM Albums <= 1.9.2 - Remote File Inclusion | LOW | *-1.9.2 | 1.9.3 | June 28, 2026 | |
| firestats | firestats |
93
|
FireStats <1.6.2 - SQL Injection | LOW | [*, 1.6.2) | 1.6.2 | June 28, 2026 | |
| photoracer | photoracer | N/A | Photoracer Plugin <= 1.0 - SQL Injection | LOW | *-1.0 | June 28, 2026 | ||
| firestats | firestats |
93
|
FireStats < 1.6.2 - Remote File Inclusion | LOW | [*, 1.6.2) | 1.6.2 | June 28, 2026 | |
| wp-lytebox | wp-lytebox | N/A | Lytebox <= 1.3 - Local File Inclusion | LOW | *-1.3 | June 28, 2026 | ||
| wp-syntax | wp-syntax | N/A | WP Syntax < 0.9.10 - Remote Code Execution | LOW | *-0.9.9 | 0.9.10 | June 28, 2026 | |
| fmoblog | fmoblog |
91
|
fMoblog <= 2.1 - SQL Injection | LOW | *-2.1 | June 28, 2026 | ||
| page-flip-image-gallery | page-flip-image-gallery | N/A | Page Flip Image Gallery <= 0.2.2 - Directory Traversal | LOW | *-0.2.2 | June 28, 2026 | ||
| wp-shopping-cart | wp-shopping-cart | N/A | Instinct WP e-Commerce <= 3.4 - Arbitrary File Upload | LOW | *-3.4 | 3.6.8 RC1 | June 28, 2026 | |
| st_newsletter | st_newsletter | N/A | ShiftThis Newsletter <= 2.3.1 - SQL Injection | LOW | *-2.3.1 | June 28, 2026 | ||
| php-shell | php-shell | N/A | PHP Shell (All Versions) - Backdoor | LOW | * | June 28, 2026 | ||
| wp-comment-remix | wp-comment-remix | N/A | WP Comment Remix <= 1.4.3 - SQL Injection | LOW | *-1.4.3 | 1.4.4 | June 28, 2026 | |
| wp-comment-remix | wp-comment-remix | N/A | WP Comment Remix < 1.4.4 - SQL Injection | LOW | [*, 1.4.4) | 1.4.4 | June 28, 2026 | |
| wp-comment-remix | wp-comment-remix | N/A | WP Comment Remix < 1.4.4 - Cross-Site Request Forgery | LOW | [*, 1.4.4) | 1.4.4 | June 28, 2026 | |
| downloads-manager | downloads-manager |
91
|
Downloads Manager <= 0.2 - Arbitrary File Upload | LOW | *-0.2 | June 28, 2026 | ||
| tubepress | tubepress | N/A | TubePress < 1.6.5 - Cross-Site Scripting | LOW | *-1.5.7 | 1.6.5 | June 28, 2026 | |
| Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery | nextgen-gallery |
66
|
NextGEN Gallery Plugin <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting | LOW | *-1.9.0 | 1.9.1 | June 28, 2026 | |
| download-monitor | download-monitor |
93
|
Download Monitor <= 2.0.6 - Unauthenticated SQL Injection | LOW | *-2.0.6 | 2.0.9 | June 28, 2026 | |
| wpss | wpss | N/A | WordPress Spreadsheet <= 0.6 - Unauthenticated SQL Injection | LOW | *-0.6 | June 28, 2026 | ||
| wp-download | wp-download | N/A | WP-Download <= 1.2 - SQL Injection | LOW | *-1.2 | 1.2.1 | June 28, 2026 | |
| sniplets | sniplets | N/A | Sniplets < 1.2.3 - Cross-Site Scripting | LOW | [*, 1.2.3) | 1.2.3 | June 28, 2026 | |
| sniplets | sniplets | N/A | Sniplets < 1.2.3 - Remote Code Execution | LOW | [*, 1.2.3) | 1.2.3 | June 28, 2026 | |
| wp-photo-album-plus | wp-photo-album-plus | N/A | WP Photo Album Plus <= 1.1 - SQL Injection | LOW | *-1.0 | 1.1 | June 28, 2026 | |
| sniplets | sniplets | N/A | Sniplets < 1.2.3 - Remote File Inclusion | LOW | [*, 1.2.3) | 1.2.3 | June 28, 2026 | |
| wp-people | wp-people | N/A | WP People <= 3.4.1 - SQL Injection | LOW | *-3.4.1 | June 28, 2026 | ||
| simple-forum | simple-forum | N/A | Yellow Swordfish Simple Forum <= 1.11 - SQL Injection | LOW | *-1.11 | June 28, 2026 | ||
| search-unleashed | search-unleashed | N/A | Search Unleashed <= 0.2.10 - Cross-Site Scripting | LOW | *-0.2.10 | 0.2.11 | June 28, 2026 | |
| st_newsletter | st_newsletter | N/A | ShiftThis (Unspecified Version) - SQL Injection | LOW | * | June 28, 2026 | ||
| wp-footnotes | wp-footnotes | N/A | WP-Footnotes <= 2.2 - Multiple Cross-Site Scripting | LOW | *-2.2 | 3.0 | June 28, 2026 | |
| wordspew | wordspew | N/A | WordSpew <= 3.71 - SQL Injection | LOW | *-3.71 | June 28, 2026 | ||
| dmsguestbook | dmsguestbook |
91
|
DMSGuestbook < 1.9.0 - Cross-Site Scripting | LOW | [*, 1.9.0) | 1.9.0 | June 28, 2026 | |
| dmsguestbook | dmsguestbook |
91
|
DMSGuestbook <= 1.8.0 - Directory Traversal | LOW | *-1.8.0 | 1.8.1 | June 28, 2026 | |
| dmsguestbook | dmsguestbook |
91
|
DMSGuestbook < 1.9.0 - Cross-Site Scripting | LOW | [*, 1.9.0) | 1.9.0 | June 28, 2026 | |
| dmsguestbook | dmsguestbook |
91
|
DMSGuestbook <= 1.7.0 - SQL Injection | LOW | * | June 28, 2026 | ||
| wassup | wassup | N/A | WassUp Real Time Analytics 1.4 - 1.4.3 - SQL Injection | LOW | 1.4-1.4.3 | 1.4.4 | June 28, 2026 | |
| fgallery | fgallery |
93
|
fGallery 2.4.1 - SQL injection | LOW | *-2.4.1 | 2.4.2 | June 28, 2026 | |
| adserve | adserve |
97
|
AdServe < 0.3 - SQL Injection | LOW | *-0.2 | 0.3 | June 28, 2026 | |
| wp-cal | wp-cal | N/A | WP-Cal <= 0.3 - SQL Injection | LOW | *-0.3 | June 28, 2026 | ||
| permalinks-migration-plugin-for-wordpress | permalinks-migration-plugin-for-wordpress | N/A | Dean's Permalinks Migration <= 1.0 - Cross-Site Request Forgery to Cross-Site Scripting | LOW | *-1.0 | June 28, 2026 | ||
| wp-forum | wp-forum | N/A | WP-Forum <= 1.7.4 - Remote SQL Injection | LOW | *-1.7.4 | 1.7.7 | June 28, 2026 | |
| spambam | spambam | N/A | Spambam <= 2.1 - Authorization Bypass | LOW | *-2.1 | June 28, 2026 | ||
| peters-math-anti-spam | peters-math-anti-spam | N/A | Peter's Math Anti-Spam Spinoff < 1.0.0 - CAPTCHA Bypass | LOW | *-0.1.6 | 1.0.0 | June 28, 2026 | |
| wp-contactform | wp-contactform | N/A | WP-ContactForm <= 1.5 - Authenticated (Admin+) Stored Cross-Site Scripting | LOW | *-1.5 | June 28, 2026 | ||
| wp-filemanager | wp-filemanager | N/A | Wp-FileManager <= 1.2 - Arbitrary File Upload | LOW | *-1.2 | 1.3 | June 28, 2026 | |
| wp-contactform | wp-contactform | N/A | WP-ContactForm <= 1.5.1 - Cross-Site Request Forgery | LOW | *-1.5.1 | June 28, 2026 | ||
| math-comment-spam-protection | math-comment-spam-protection | N/A | Math Comment Spam Protection <= 2.1 - Reflected Cross-Site Scripting | LOW | *-2.1 | 2.2 | June 28, 2026 | |
| pictpress | pictpress | N/A | PictPress <= 0.91 - Directory Traversal | LOW | *-0.91 | 0.99 | June 28, 2026 | |
| cryptographp | cryptographp |
91
|
Cryptographp <= 1.2 - Cross-Site Scripting | LOW | *-1.2 | June 28, 2026 | ||
| captcha-offrepo | captcha-offrepo |
93
|
Captcha! <= 2.5d - Cross-Site Scripting | LOW | * - 2.5d | 2.6 | June 28, 2026 | |
| math-comment-spam-protection | math-comment-spam-protection | N/A | Math Comment Spam Protection <= 2.1 - Cross-Site Request Forgery | LOW | *-2.1 | 2.2 | June 28, 2026 | |
| peters-random-anti-spam-image | peters-random-anti-spam-image | N/A | Peter’s Random Anti-Spam Image <= 1.0.6 - Cross-Site Scripting | LOW | *-1.0.6 | June 28, 2026 | ||
| backupwordpress | backupwordpress |
93
|
BackUpWordPress <= 0.4.2b - Remote File Inclusion | LOW | [*, 0.4.3) | 0.4.3 | June 28, 2026 | |
| feedburner-feedsmith | feedburner-feedsmith |
93
|
FeedBurner FeedSmith <= 2.2 - Cross-Site Request Forgery | LOW | *-2.2 | 2.3 | June 28, 2026 | |
| stats | stats | N/A | stats <= 1.1 - SQL Injection | LOW | *-1.1 | 1.1.1 | June 28, 2026 | |
| feedstats-de | feedstats-de |
93
|
FeedStats < 2.4 - Cross-Site Scripting | LOW | [*, 2.4) | 2.4 | June 28, 2026 | |
| stats | stats | N/A | stats <= 1.0 - Stored Cross-Site Scripting | LOW | *-1.0 | 1.1 | June 28, 2026 | |
| adsense-deluxe | adsense-deluxe |
95
|
AdSense-Deluxe <= 0.8 - Cross-Site Request Forgery | LOW | *-0.8 | June 28, 2026 | ||
| Akismet Anti-spam: Spam Protection | akismet |
92
|
Akismet Spam Protection < 2.0.2 - Cross-Site Scripting | LOW | *-2.0.1 | 2.0.2 | June 28, 2026 | |
| wp-table | wp-table | N/A | WP-Table <= 1.43 - Local File Inclusion | LOW | *-1.43 | 1.44 | June 28, 2026 | |
| wordtube | wordtube | N/A | wordTube <= 1.43 - Remote File Inclusion | LOW | *-1.43 | 1.44 | June 28, 2026 | |
| wordtube | wordtube | N/A | wordTube <= 1.43 - Directory Traversal and File Inclusion | LOW | *-1.43 | 1.44 | June 28, 2026 | |
| myflash | myflash | N/A | Myflash < 1.11 - Remote File Inclusion | LOW | *-1.00 | 1.11 | June 28, 2026 | |
| the-hackers-diet | the-hackers-diet | N/A | The Hacker's Diet <= 0.9.6b - SQL Injection | LOW | * - 0.9.6b | 0.9.7b | June 28, 2026 | |
| mygallery | mygallery | N/A | MySliderGallery <= 1.2.1 - Remote File Inclusion | LOW | *-1.2.1 | 1.4b5 | June 28, 2026 | |
| subscribe-to-comments | subscribe-to-comments | N/A | Subscribe to Comments <= 2.0.7 - Reflected Cross-Site Scripting | LOW | *-2.0.7 | 2.0.8 | June 28, 2026 | |
| wp-db-backupphp | wp-db-backupphp | N/A | Skippy WP-DB Backup (Legacy Plugin) <= 1.7 - Authenticated (Admin+) Directory Traversal | LOW | *-1.7 | June 28, 2026 | ||
| secure-files | secure-files | N/A | secure-files <= 1.1 - Directory Traversal | LOW | *-1.1 | 1.2 | June 28, 2026 |
wp-twitter-feed
wp-twitter-feed
wptouch
wptouch
register-plus
register-plus
register-plus
register-plus
event-registration
event-registration
wp-survey-and-quiz-tool
wp-survey-and-quiz-tool
vodpod-video-gallery
vodpod-video-gallery
feedlist
feedlist
cforms2
cforms2
mylinksdump
mylinksdump
wp-useronline
wp-useronline
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
cpl
cpl
wp-cumulus
wp-cumulus
wp-cumulus
wp-cumulus
woopra
woopra
piwik-pro
piwik-pro
wp-forum
wp-forum
wp-cumulus
wp-cumulus
google-analyticator
google-analyticator
my-category-order
my-category-order
related-sites
related-sites
dm-albums
dm-albums
firestats
firestats
photoracer
photoracer
firestats
firestats
wp-lytebox
wp-lytebox
wp-syntax
wp-syntax
fmoblog
fmoblog
page-flip-image-gallery
page-flip-image-gallery
wp-shopping-cart
wp-shopping-cart
st_newsletter
st_newsletter
php-shell
php-shell
wp-comment-remix
wp-comment-remix
wp-comment-remix
wp-comment-remix
wp-comment-remix
wp-comment-remix
downloads-manager
downloads-manager
tubepress
tubepress
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
download-monitor
download-monitor
wpss
wpss
wp-download
wp-download
sniplets
sniplets
sniplets
sniplets
wp-photo-album-plus
wp-photo-album-plus
sniplets
sniplets
wp-people
wp-people
simple-forum
simple-forum
search-unleashed
search-unleashed
st_newsletter
st_newsletter
wp-footnotes
wp-footnotes
wordspew
wordspew
dmsguestbook
dmsguestbook
dmsguestbook
dmsguestbook
dmsguestbook
dmsguestbook
dmsguestbook
dmsguestbook
wassup
wassup
fgallery
fgallery
adserve
adserve
wp-cal
wp-cal
permalinks-migration-plugin-for-wordpress
permalinks-migration-plugin-for-wordpress
wp-forum
wp-forum
spambam
spambam
peters-math-anti-spam
peters-math-anti-spam
wp-contactform
wp-contactform
wp-filemanager
wp-filemanager
wp-contactform
wp-contactform
math-comment-spam-protection
math-comment-spam-protection
pictpress
pictpress
cryptographp
cryptographp
captcha-offrepo
captcha-offrepo
math-comment-spam-protection
math-comment-spam-protection
peters-random-anti-spam-image
peters-random-anti-spam-image
backupwordpress
backupwordpress
feedburner-feedsmith
feedburner-feedsmith
stats
stats
feedstats-de
feedstats-de
stats
stats
adsense-deluxe
adsense-deluxe
Akismet Anti-spam: Spam Protection
akismet
wp-table
wp-table
wordtube
wordtube
wordtube
wordtube
myflash
myflash
the-hackers-diet
the-hackers-diet
mygallery
mygallery
subscribe-to-comments
subscribe-to-comments
wp-db-backupphp
wp-db-backupphp
secure-files
secure-files
Showing 36101 to 36189 of 36189 results
Vulnerability data is aggregated from automated feeds and public sources. Results may include false positives or outdated information. Always verify details and apply updates in a staging environment before deploying to production.
Data updated daily from trusted sources. Last updated: June 28, 2026 at 16:47 UTC.