Known Plugin Vulnerabilities

Track known vulnerabilities from configured sources. Default view shows all open and closed vulnerabilities, ordered by most recently updated first.

Open Vulnerabilities

36189

Across tracked plugins

Affected Plugins

95

With open vulnerabilities

Critical / High

0

Require immediate attention

Recently Updated

0

In the last 30 days

Vulnerability List

Export CSV
Vulnerability list with plugin score and patch status
PluginSlugScoreVulnerabilityCVE IDSeverityAffected VersionsPatchedUpdated
tutor tutor N/A Tutor LMS <= 3.7.4 - Authenticated (Administrator+) SQL Injection LOW *-3.7.4 3.8.0 June 29, 2026
searchpro searchpro N/A BerqWP <= 2.2.53 - Missing Authorization LOW *-2.2.53 2.2.54 June 29, 2026
product-tabs-for-woocommerce product-tabs-for-woocommerce N/A Additional Custom Product Tabs for WooCommerce <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.7.3 1.7.4 June 29, 2026
powerpack-lite-for-elementor powerpack-lite-for-elementor N/A PowerPack Lite for Elementor <= 2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url' LOW *-2.9.4 2.9.5 June 29, 2026
pixelines-email-protector pixelines-email-protector N/A Pixeline's Email Protector <= 1.3.8 - Authenticated (Admin+) Stored Cross-Site Scripting LOW *-1.3.8 1.4.0 June 29, 2026
pdf-generator-for-wp pdf-generator-for-wp N/A PDF Generator for WordPress <= 1.5.4 - Missing Authorization LOW *-1.5.4 1.5.5 June 29, 2026
my-tickets my-tickets N/A My Tickets <= 2.0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.0.22 2.0.23 June 29, 2026
include-me include-me
93
Include Me <= 1.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-1.3.2 1.3.3 June 29, 2026
football-pool football-pool
93
Football Pool <= 2.12.6 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.12.6 2.13.0 June 29, 2026
export-wp-page-to-static-html export-wp-page-to-static-html
93
Export WP Page to Static HTML/CSS <= 4.1.0 - Missing Authorization LOW *-4.1.0 4.2.0 June 29, 2026
ebay-feeds-for-wordpress ebay-feeds-for-wordpress
93
WP eBay Product Feeds <= 3.4.8 - Authenticated (Contributor+) Server Side Request Forgery LOW *-3.4.8 3.4.9 June 29, 2026
easy-appointments easy-appointments
93
Easy Appointments <= 3.12.14 - Unauthenticated Arbitrary Shortcode Execution LOW *-3.12.14 3.12.14.1 June 29, 2026
dynamic-text-field-for-contact-form-7 dynamic-text-field-for-contact-form-7
93
Dynamic Text Field For Contact Form 7 <= 2.0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.0 1.1 June 29, 2026
advanced-settings advanced-settings
97
Advanced Settings <= 3.1.1 - Cross-Site Request Forgery LOW *-3.1.1 3.2.0 June 29, 2026
Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance accessibility-checker
89
Accessibility Checker by Equalize Digital <= 1.31.0 - Missing Authorization LOW *-1.31.0 1.31.1 June 29, 2026
Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance accessibility-checker
89
Accessibility Checker by Equalize Digital <= 1.31.0 - Missing Authorization LOW *-1.31.0 1.31.1 June 29, 2026
automatorwp automatorwp
93
AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation LOW *-5.3.6 5.3.7 June 29, 2026
automatorwp automatorwp
93
AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions LOW *-5.3.7 5.3.8 June 29, 2026
wilmer-core wilmer-core N/A Wilmer Core <= 2.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode LOW *-2.4.5 2.4.6 June 29, 2026
mikado-core mikado-core N/A Mikado Core <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode LOW *-1.5.2 1.6 June 29, 2026
wp-members wp-members N/A WP-Members Membership Plugin <= 3.5.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names LOW *-3.5.4.2 3.5.4.3 June 29, 2026
doccure doccure
93
Doccure Core <= 1.5.3 - Unauthenticated Arbitrary File Upload LOW *-1.5.3 1.5.4 June 29, 2026
zip-code-based-content-protection zip-code-based-content-protection N/A ZIP Code Based Content Protection <= 1.0.0 - Authenticated (Administrator+) SQL Injection LOW *-1.0.0 1.0.1 June 29, 2026
wc-return-product wc-return-product N/A WC Return products <= 1.5 - Reflected Cross-Site Scripting LOW *-1.5 June 29, 2026
postie postie N/A Postie <= 1.9.70 - Authenticated (Admin+) Stored Cross-Site Scripting LOW *-1.9.70 1.9.71 June 29, 2026
easy-woocommerce-customizer easy-woocommerce-customizer
91
Easy Woocommerce Customizer <= 1.0.2 - Reflected Cross-Site Scripting LOW *-1.0.2 June 29, 2026
categorify categorify
91
Categorify <= 1.0.7.5 - Missing Authorization LOW *-1.0.7.5 June 29, 2026
toast-responsive-menu toast-responsive-menu N/A Toast Mobile Menu <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting LOW *-1.0.8 1.0.9 June 29, 2026
u-design-core u-design-core N/A UDesign Core <= 4.14.0 - Missing Authorization LOW *-4.14.0 June 29, 2026
u-design-core u-design-core N/A UDesign Core <= 4.14.0 - Reflected Cross-Site Scripting LOW *-4.14.0 June 29, 2026
permalink-manager permalink-manager N/A Permalink Manager Lite <= 2.5.1.3 - Unauthenticated Sensitive Information Exposure LOW *-2.5.1.3 2.5.1.4 June 29, 2026
recent-posts-widget-extended recent-posts-widget-extended N/A Recent Posts Widget Extended <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via rpwe Shortcode LOW *-2.0.2 June 29, 2026
skt-addons-for-elementor skt-addons-for-elementor N/A SKT Addons for Elementor <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets LOW *-3.7 3.8 June 29, 2026
admin-menu-editor admin-menu-editor
97
Admin Menu Editor <= 1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder Parameter LOW *-1.14 1.14.1 June 29, 2026
athemes-addons-for-elementor-lite athemes-addons-for-elementor-lite
93
aThemes Addons for Elementor Lite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget LOW *-1.1.2 1.1.3 June 29, 2026
smart-table-builder smart-table-builder N/A Smart Table Builder <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter LOW *-1.0.1 1.0.2 June 29, 2026
streamweasels-kick-integration streamweasels-kick-integration N/A StreamWeasels Kick Integration <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via vodsChannel Parameter LOW *-1.1.5 1.1.6 June 29, 2026
content-views-query-and-display-post-page content-views-query-and-display-post-page
93
Content Views <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Grid and List Widgets LOW *-4.1 4.2 June 29, 2026
optio-dentistry optio-dentistry N/A Optio Dentistry <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.2 2.3 June 29, 2026
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress easy-facebook-likebox
72
Easy Social Feed – Social Photos Gallery – Post Feed – Like Box <= 6.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting LOW *-6.6.7 6.6.8 June 29, 2026
html-social-share-buttons html-social-share-buttons
93
Html Social share buttons <= 2.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.1.16 2.2.0 June 29, 2026
zoom-image-shortcode zoom-image-shortcode N/A Zoomify embed for WP <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.5.2 June 29, 2026
wpb-image-widget wpb-image-widget N/A WPB Image Widget <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.1 June 29, 2026
wpb-elementor-addons wpb-elementor-addons N/A WPB Elementor Addons <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.6 June 29, 2026
wpa-seo-auto-linker wpa-seo-auto-linker N/A SEO Auto Linker <= 1.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-1.5.3 June 29, 2026
wp-storymap wp-storymap N/A StoryMap <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.1 June 29, 2026
wp-shortcm wp-shortcm N/A short.io <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.4.0 June 29, 2026
wp-publication-archive wp-publication-archive N/A WP Publication Archive <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-3.0.1 June 29, 2026
wp-notification-bell wp-notification-bell N/A WP Notification Bell <= 1.4.6 - Authenticated (Author+) Stored Cross-Site Scripting LOW *-1.4.6 1.4.7 June 29, 2026
wp-mail wp-mail N/A WP Mail <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.3 June 29, 2026
wp-likes wp-likes N/A WP likes <= 3.1.1 - Cross-Site Request Forgery to Cross-Site Scripting LOW *-3.1.1 June 29, 2026
wp-graphviz wp-graphviz N/A WP-GraphViz <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.5.1 June 29, 2026
wp-github-gist wp-github-gist N/A WP Github Gist <= 0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-0.5 June 29, 2026
wp-full-stripe-free wp-full-stripe-free N/A WP Full Stripe Free <= 8.2.5 - Authenticated (Administrator+) SQL Injection LOW *-8.2.5 8.2.6 June 29, 2026
wp-email-template wp-email-template N/A WP Email Template <= 2.8.3 - Cross-Site Request Forgery LOW *-2.8.3 June 29, 2026
woocommerce-notify-updated-product woocommerce-notify-updated-product N/A Woocommerce Notify Updated Product <= 1.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting LOW *-1.6 June 29, 2026
woo-single-page-checkout woo-single-page-checkout N/A WooCommerce Single Page Checkout <= 1.2.7 - Cross-Site Request Forgery LOW *-1.2.7 June 29, 2026
woo-gift-product woo-gift-product N/A Woocommerce Gifts Product <= 1.0.0 - Cross-Site Request Forgery LOW *-1.0.0 June 29, 2026
wn-flipbox-pro wn-flipbox-pro N/A WN Flipbox Pro <= 2.1 - Cross-Site Request Forgery LOW *-2.1 June 29, 2026
widgetize-pages-light widgetize-pages-light N/A Widgetize Pages Light <= 3.0 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-3.0 June 29, 2026
vipdrv-vip-test-drive vipdrv-vip-test-drive N/A vipdrv <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-1.0.3 June 29, 2026
userswp userswp N/A UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.44 - Authenticated (Subscriber+) SQL Injection LOW *-1.2.44 1.2.45 June 29, 2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder user-registration N/A User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection LOW *-4.3.0 4.4.0 June 29, 2026
ultimate-ajax-login ultimate-ajax-login N/A Ultimate AJAX Login <= 1.2.1 - Cross-Site Request Forgery LOW *-1.2.1 June 29, 2026
ulimate-client-dash ulimate-client-dash N/A Ultimate Client Dash <= 4.7 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-4.7 4.7.1 June 29, 2026
trustmate-io-integration-for-woocommerce trustmate-io-integration-for-woocommerce N/A TrustMate.io – WooCommerce integration <= 1.14.0 - Cross-Site Request Forgery LOW *-1.14.0 June 29, 2026
translate-this-google-translate-web-element-shortcode translate-this-google-translate-web-element-shortcode N/A Translate This gTranslate Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.0 June 29, 2026
themify-popup themify-popup N/A Themify Popup <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.4.2 1.4.3 June 29, 2026
swiftninjapro-inspect-element-console-blocker swiftninjapro-inspect-element-console-blocker N/A Developer Tools Blocker <= 3.2.1 - Cross-Site Request Forgery LOW *-3.2.1 June 29, 2026
stagtools stagtools N/A Stagtools <= 2.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.3.8 June 29, 2026
ss-font-awesome-icon ss-font-awesome-icon N/A SS Font Awesome Icon <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-4.1.3 June 29, 2026
smooth-accordion smooth-accordion N/A Smooth Accordion <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-2.1 June 29, 2026
site-info-dashboard-widget site-info-dashboard-widget N/A Site Info <= 1.1 - Authenticated (Editor+) Information Exposure LOW *-1.1 June 29, 2026
simple-text-slider simple-text-slider N/A Simple Text Slider <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.0.5 June 29, 2026
simple-price-calculator-basic simple-price-calculator-basic N/A Simple Price Calculator <= 1.3 - Missing Authorization LOW *-1.3 June 29, 2026
simple-link-list-widget simple-link-list-widget N/A Simple Link List Widget <= 0.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-0.3.2 June 29, 2026
simasicher-dsgvo-cookie simasicher-dsgvo-cookie N/A SimaCookie <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.3.2 June 29, 2026
simasicher-dsgvo-cookie simasicher-dsgvo-cookie N/A SimaCookie <= 1.3.2 - Cross-Site Request Forgery LOW *-1.3.2 June 29, 2026
showpass showpass N/A Showpass WordPress Extension <= 4.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-4.0.3 4.0.4 June 29, 2026
search-google search-google N/A Search by Google <= 1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-1.9 June 29, 2026
search-cloud-one search-cloud-one N/A Search Cloud One <= 2.2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-2.2.5 June 29, 2026
salesforce-wordpress-to-lead salesforce-wordpress-to-lead N/A To Lead For Salesforce <= 2.7.3.9 - Cross-Site Request Forgery LOW *-2.7.3.9 June 29, 2026
responder responder N/A Responder <= 4.3.8 - Cross-Site Request Forgery LOW *-4.3.8 4.4.0 June 29, 2026
quick-event-calendar quick-event-calendar N/A Quick Event Calendar <= 1.4.9 - Cross-Site Request Forgery LOW *-1.4.9 June 29, 2026
pushe-webpush pushe-webpush N/A Pushe Web Push Notification <= 0.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting LOW *-0.5.0 June 29, 2026
purge-varnish purge-varnish N/A Purge Varnish Cache <= 2.6 - Cross-Site Request Forgery LOW *-2.6 June 29, 2026
prettyphoto prettyphoto N/A prettyPhoto <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.2.4 June 29, 2026
popping-sidebars-and-widgets-light popping-sidebars-and-widgets-light N/A Popping Sidebars and Widgets Light <= 1.27 - Cross-Site Request Forgery LOW *-1.27 June 29, 2026
payoneer-checkout payoneer-checkout N/A Payoneer Checkout <= 3.4.0 - Missing Authorization LOW *-3.4.0 3.5.0 June 29, 2026
parallax-scrolling-enllax-js parallax-scrolling-enllax-js N/A Parallax Scrolling Enllax.js <= 0.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-0.0.6 June 29, 2026
parallax-scrolling-enllax-js parallax-scrolling-enllax-js N/A Parallax Scrolling Enllax.js <= 0.0.6 - Cross-Site Request Forgery LOW *-0.0.6 June 29, 2026
Notification for Telegram notification-for-telegram
97
Notification for Telegram <= 3.5.1 - Cross-Site Request Forgery LOW *-3.5.1 3.5.2 June 29, 2026
ninja-charts ninja-charts N/A Ninja Charts <= 3.3.5 - Unauthenticated Information Exposure LOW *-3.3.5 3.3.6 June 29, 2026
new-simple-gallery new-simple-gallery N/A New Simple Gallery <= 8.0 - Authenticated (Contributor+) SQL Injection LOW *-8.0 June 29, 2026
multi-step-form multi-step-form N/A Multi Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File Upload LOW *-1.7.25 1.7.26 June 29, 2026
mstw-league-manager mstw-league-manager N/A MSTW League Manager <= 2.10 - Cross-Site Request Forgery LOW *-2.10 June 29, 2026
mshop-naver-talktalk mshop-naver-talktalk N/A 코드엠샵 소셜톡 <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.2.1 June 29, 2026
media-author media-author
91
Media Author <= 1.0.4 - Missing Authorization LOW *-1.0.4 June 29, 2026
master-paper-collapse-toggle master-paper-collapse-toggle
91
Master Paper Collapse Toggle <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting LOW *-1.1 June 29, 2026
lingotek-translation lingotek-translation
91
Ray Enterprise Translation <= 1.7.1 - Missing Authorization LOW *-1.7.1 June 29, 2026
LOW

tutor

tutor

Score: N/A Tutor LMS <= 3.7.4 - Authenticated (Administrator+) SQL Injection Affected: *-3.7.4 Patched: 3.8.0 Updated: June 29, 2026
LOW

searchpro

searchpro

Score: N/A BerqWP <= 2.2.53 - Missing Authorization Affected: *-2.2.53 Patched: 2.2.54 Updated: June 29, 2026
LOW

product-tabs-for-woocommerce

product-tabs-for-woocommerce

Score: N/A Additional Custom Product Tabs for WooCommerce <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.7.3 Patched: 1.7.4 Updated: June 29, 2026
LOW

powerpack-lite-for-elementor

powerpack-lite-for-elementor

Score: N/A PowerPack Lite for Elementor <= 2.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url' Affected: *-2.9.4 Patched: 2.9.5 Updated: June 29, 2026
LOW

pixelines-email-protector

pixelines-email-protector

Score: N/A Pixeline's Email Protector <= 1.3.8 - Authenticated (Admin+) Stored Cross-Site Scripting Affected: *-1.3.8 Patched: 1.4.0 Updated: June 29, 2026
LOW

pdf-generator-for-wp

pdf-generator-for-wp

Score: N/A PDF Generator for WordPress <= 1.5.4 - Missing Authorization Affected: *-1.5.4 Patched: 1.5.5 Updated: June 29, 2026
LOW

my-tickets

my-tickets

Score: N/A My Tickets <= 2.0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.0.22 Patched: 2.0.23 Updated: June 29, 2026
LOW

include-me

include-me

Score: 93/100 Include Me <= 1.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-1.3.2 Patched: 1.3.3 Updated: June 29, 2026
LOW

football-pool

football-pool

Score: 93/100 Football Pool <= 2.12.6 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.12.6 Patched: 2.13.0 Updated: June 29, 2026
LOW

export-wp-page-to-static-html

export-wp-page-to-static-html

Score: 93/100 Export WP Page to Static HTML/CSS <= 4.1.0 - Missing Authorization Affected: *-4.1.0 Patched: 4.2.0 Updated: June 29, 2026
LOW

ebay-feeds-for-wordpress

ebay-feeds-for-wordpress

Score: 93/100 WP eBay Product Feeds <= 3.4.8 - Authenticated (Contributor+) Server Side Request Forgery Affected: *-3.4.8 Patched: 3.4.9 Updated: June 29, 2026
LOW

easy-appointments

easy-appointments

Score: 93/100 Easy Appointments <= 3.12.14 - Unauthenticated Arbitrary Shortcode Execution Affected: *-3.12.14 Patched: 3.12.14.1 Updated: June 29, 2026
LOW

dynamic-text-field-for-contact-form-7

dynamic-text-field-for-contact-form-7

Score: 93/100 Dynamic Text Field For Contact Form 7 <= 2.0.22 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.0 Patched: 1.1 Updated: June 29, 2026
LOW

advanced-settings

advanced-settings

Score: 97/100 Advanced Settings <= 3.1.1 - Cross-Site Request Forgery Affected: *-3.1.1 Patched: 3.2.0 Updated: June 29, 2026
LOW

automatorwp

automatorwp

Score: 93/100 AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress <= 5.3.6 - Missing Authorization To Authenticated (Subscriber+) Remote Code Execution via Automation Creation Affected: *-5.3.6 Patched: 5.3.7 Updated: June 29, 2026
LOW

automatorwp

automatorwp

Score: 93/100 AutomatorWP <= 5.3.7 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions Affected: *-5.3.7 Patched: 5.3.8 Updated: June 29, 2026
LOW

wilmer-core

wilmer-core

Score: N/A Wilmer Core <= 2.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Affected: *-2.4.5 Patched: 2.4.6 Updated: June 29, 2026
LOW

mikado-core

mikado-core

Score: N/A Mikado Core <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Affected: *-1.5.2 Patched: 1.6 Updated: June 29, 2026
LOW

wp-members

wp-members

Score: N/A WP-Members Membership Plugin <= 3.5.4.2 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names Affected: *-3.5.4.2 Patched: 3.5.4.3 Updated: June 29, 2026
LOW

doccure

doccure

Score: 93/100 Doccure Core <= 1.5.3 - Unauthenticated Arbitrary File Upload Affected: *-1.5.3 Patched: 1.5.4 Updated: June 29, 2026
LOW

zip-code-based-content-protection

zip-code-based-content-protection

Score: N/A ZIP Code Based Content Protection <= 1.0.0 - Authenticated (Administrator+) SQL Injection Affected: *-1.0.0 Patched: 1.0.1 Updated: June 29, 2026
LOW

wc-return-product

wc-return-product

Score: N/A WC Return products <= 1.5 - Reflected Cross-Site Scripting Affected: *-1.5 Patched: Updated: June 29, 2026
LOW

postie

postie

Score: N/A Postie <= 1.9.70 - Authenticated (Admin+) Stored Cross-Site Scripting Affected: *-1.9.70 Patched: 1.9.71 Updated: June 29, 2026
LOW

easy-woocommerce-customizer

easy-woocommerce-customizer

Score: 91/100 Easy Woocommerce Customizer <= 1.0.2 - Reflected Cross-Site Scripting Affected: *-1.0.2 Patched: Updated: June 29, 2026
LOW

categorify

categorify

Score: 91/100 Categorify <= 1.0.7.5 - Missing Authorization Affected: *-1.0.7.5 Patched: Updated: June 29, 2026
LOW

toast-responsive-menu

toast-responsive-menu

Score: N/A Toast Mobile Menu <= 1.0.8 - Unauthenticated Stored Cross-Site Scripting Affected: *-1.0.8 Patched: 1.0.9 Updated: June 29, 2026
LOW

u-design-core

u-design-core

Score: N/A UDesign Core <= 4.14.0 - Missing Authorization Affected: *-4.14.0 Patched: Updated: June 29, 2026
LOW

u-design-core

u-design-core

Score: N/A UDesign Core <= 4.14.0 - Reflected Cross-Site Scripting Affected: *-4.14.0 Patched: Updated: June 29, 2026
LOW

permalink-manager

permalink-manager

Score: N/A Permalink Manager Lite <= 2.5.1.3 - Unauthenticated Sensitive Information Exposure Affected: *-2.5.1.3 Patched: 2.5.1.4 Updated: June 29, 2026
LOW

recent-posts-widget-extended

recent-posts-widget-extended

Score: N/A Recent Posts Widget Extended <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via rpwe Shortcode Affected: *-2.0.2 Patched: Updated: June 29, 2026
LOW

skt-addons-for-elementor

skt-addons-for-elementor

Score: N/A SKT Addons for Elementor <= 3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets Affected: *-3.7 Patched: 3.8 Updated: June 29, 2026
LOW

admin-menu-editor

admin-menu-editor

Score: 97/100 Admin Menu Editor <= 1.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder Parameter Affected: *-1.14 Patched: 1.14.1 Updated: June 29, 2026
LOW

athemes-addons-for-elementor-lite

athemes-addons-for-elementor-lite

Score: 93/100 aThemes Addons for Elementor Lite <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget Affected: *-1.1.2 Patched: 1.1.3 Updated: June 29, 2026
LOW

smart-table-builder

smart-table-builder

Score: N/A Smart Table Builder <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter Affected: *-1.0.1 Patched: 1.0.2 Updated: June 29, 2026
LOW

streamweasels-kick-integration

streamweasels-kick-integration

Score: N/A StreamWeasels Kick Integration <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via vodsChannel Parameter Affected: *-1.1.5 Patched: 1.1.6 Updated: June 29, 2026
LOW

content-views-query-and-display-post-page

content-views-query-and-display-post-page

Score: 93/100 Content Views <= 4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Grid and List Widgets Affected: *-4.1 Patched: 4.2 Updated: June 29, 2026
LOW

optio-dentistry

optio-dentistry

Score: N/A Optio Dentistry <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.2 Patched: 2.3 Updated: June 29, 2026
LOW

html-social-share-buttons

html-social-share-buttons

Score: 93/100 Html Social share buttons <= 2.1.16 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.1.16 Patched: 2.2.0 Updated: June 29, 2026
LOW

zoom-image-shortcode

zoom-image-shortcode

Score: N/A Zoomify embed for WP <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.5.2 Patched: Updated: June 29, 2026
LOW

wpb-image-widget

wpb-image-widget

Score: N/A WPB Image Widget <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.1 Patched: Updated: June 29, 2026
LOW

wpb-elementor-addons

wpb-elementor-addons

Score: N/A WPB Elementor Addons <= 1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.6 Patched: Updated: June 29, 2026
LOW

wpa-seo-auto-linker

wpa-seo-auto-linker

Score: N/A SEO Auto Linker <= 1.5.3 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-1.5.3 Patched: Updated: June 29, 2026
LOW

wp-storymap

wp-storymap

Score: N/A StoryMap <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.1 Patched: Updated: June 29, 2026
LOW

wp-shortcm

wp-shortcm

Score: N/A short.io <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.4.0 Patched: Updated: June 29, 2026
LOW

wp-publication-archive

wp-publication-archive

Score: N/A WP Publication Archive <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-3.0.1 Patched: Updated: June 29, 2026
LOW

wp-notification-bell

wp-notification-bell

Score: N/A WP Notification Bell <= 1.4.6 - Authenticated (Author+) Stored Cross-Site Scripting Affected: *-1.4.6 Patched: 1.4.7 Updated: June 29, 2026
LOW

wp-mail

wp-mail

Score: N/A WP Mail <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.3 Patched: Updated: June 29, 2026
LOW

wp-likes

wp-likes

Score: N/A WP likes <= 3.1.1 - Cross-Site Request Forgery to Cross-Site Scripting Affected: *-3.1.1 Patched: Updated: June 29, 2026
LOW

wp-graphviz

wp-graphviz

Score: N/A WP-GraphViz <= 1.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.5.1 Patched: Updated: June 29, 2026
LOW

wp-github-gist

wp-github-gist

Score: N/A WP Github Gist <= 0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-0.5 Patched: Updated: June 29, 2026
LOW

wp-full-stripe-free

wp-full-stripe-free

Score: N/A WP Full Stripe Free <= 8.2.5 - Authenticated (Administrator+) SQL Injection Affected: *-8.2.5 Patched: 8.2.6 Updated: June 29, 2026
LOW

wp-email-template

wp-email-template

Score: N/A WP Email Template <= 2.8.3 - Cross-Site Request Forgery Affected: *-2.8.3 Patched: Updated: June 29, 2026
LOW

woocommerce-notify-updated-product

woocommerce-notify-updated-product

Score: N/A Woocommerce Notify Updated Product <= 1.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting Affected: *-1.6 Patched: Updated: June 29, 2026
LOW

woo-single-page-checkout

woo-single-page-checkout

Score: N/A WooCommerce Single Page Checkout <= 1.2.7 - Cross-Site Request Forgery Affected: *-1.2.7 Patched: Updated: June 29, 2026
LOW

woo-gift-product

woo-gift-product

Score: N/A Woocommerce Gifts Product <= 1.0.0 - Cross-Site Request Forgery Affected: *-1.0.0 Patched: Updated: June 29, 2026
LOW

wn-flipbox-pro

wn-flipbox-pro

Score: N/A WN Flipbox Pro <= 2.1 - Cross-Site Request Forgery Affected: *-2.1 Patched: Updated: June 29, 2026
LOW

widgetize-pages-light

widgetize-pages-light

Score: N/A Widgetize Pages Light <= 3.0 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-3.0 Patched: Updated: June 29, 2026
LOW

vipdrv-vip-test-drive

vipdrv-vip-test-drive

Score: N/A vipdrv <= 1.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-1.0.3 Patched: Updated: June 29, 2026
LOW

userswp

userswp

Score: N/A UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.44 - Authenticated (Subscriber+) SQL Injection Affected: *-1.2.44 Patched: 1.2.45 Updated: June 29, 2026
LOW

ultimate-ajax-login

ultimate-ajax-login

Score: N/A Ultimate AJAX Login <= 1.2.1 - Cross-Site Request Forgery Affected: *-1.2.1 Patched: Updated: June 29, 2026
LOW

ulimate-client-dash

ulimate-client-dash

Score: N/A Ultimate Client Dash <= 4.7 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-4.7 Patched: 4.7.1 Updated: June 29, 2026
LOW

trustmate-io-integration-for-woocommerce

trustmate-io-integration-for-woocommerce

Score: N/A TrustMate.io – WooCommerce integration <= 1.14.0 - Cross-Site Request Forgery Affected: *-1.14.0 Patched: Updated: June 29, 2026
LOW

translate-this-google-translate-web-element-shortcode

translate-this-google-translate-web-element-shortcode

Score: N/A Translate This gTranslate Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.0 Patched: Updated: June 29, 2026
LOW

themify-popup

themify-popup

Score: N/A Themify Popup <= 1.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.4.2 Patched: 1.4.3 Updated: June 29, 2026
LOW

stagtools

stagtools

Score: N/A Stagtools <= 2.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.3.8 Patched: Updated: June 29, 2026
LOW

ss-font-awesome-icon

ss-font-awesome-icon

Score: N/A SS Font Awesome Icon <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-4.1.3 Patched: Updated: June 29, 2026
LOW

smooth-accordion

smooth-accordion

Score: N/A Smooth Accordion <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-2.1 Patched: Updated: June 29, 2026
LOW

site-info-dashboard-widget

site-info-dashboard-widget

Score: N/A Site Info <= 1.1 - Authenticated (Editor+) Information Exposure Affected: *-1.1 Patched: Updated: June 29, 2026
LOW

simple-text-slider

simple-text-slider

Score: N/A Simple Text Slider <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.0.5 Patched: Updated: June 29, 2026
LOW

simple-price-calculator-basic

simple-price-calculator-basic

Score: N/A Simple Price Calculator <= 1.3 - Missing Authorization Affected: *-1.3 Patched: Updated: June 29, 2026
LOW

simple-link-list-widget

simple-link-list-widget

Score: N/A Simple Link List Widget <= 0.3.2 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-0.3.2 Patched: Updated: June 29, 2026
LOW

simasicher-dsgvo-cookie

simasicher-dsgvo-cookie

Score: N/A SimaCookie <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.3.2 Patched: Updated: June 29, 2026
LOW

simasicher-dsgvo-cookie

simasicher-dsgvo-cookie

Score: N/A SimaCookie <= 1.3.2 - Cross-Site Request Forgery Affected: *-1.3.2 Patched: Updated: June 29, 2026
LOW

showpass

showpass

Score: N/A Showpass WordPress Extension <= 4.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-4.0.3 Patched: 4.0.4 Updated: June 29, 2026
LOW

search-google

search-google

Score: N/A Search by Google <= 1.9 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-1.9 Patched: Updated: June 29, 2026
LOW

search-cloud-one

search-cloud-one

Score: N/A Search Cloud One <= 2.2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-2.2.5 Patched: Updated: June 29, 2026
LOW

salesforce-wordpress-to-lead

salesforce-wordpress-to-lead

Score: N/A To Lead For Salesforce <= 2.7.3.9 - Cross-Site Request Forgery Affected: *-2.7.3.9 Patched: Updated: June 29, 2026
LOW

responder

responder

Score: N/A Responder <= 4.3.8 - Cross-Site Request Forgery Affected: *-4.3.8 Patched: 4.4.0 Updated: June 29, 2026
LOW

quick-event-calendar

quick-event-calendar

Score: N/A Quick Event Calendar <= 1.4.9 - Cross-Site Request Forgery Affected: *-1.4.9 Patched: Updated: June 29, 2026
LOW

pushe-webpush

pushe-webpush

Score: N/A Pushe Web Push Notification <= 0.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting Affected: *-0.5.0 Patched: Updated: June 29, 2026
LOW

purge-varnish

purge-varnish

Score: N/A Purge Varnish Cache <= 2.6 - Cross-Site Request Forgery Affected: *-2.6 Patched: Updated: June 29, 2026
LOW

prettyphoto

prettyphoto

Score: N/A prettyPhoto <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.2.4 Patched: Updated: June 29, 2026
LOW

popping-sidebars-and-widgets-light

popping-sidebars-and-widgets-light

Score: N/A Popping Sidebars and Widgets Light <= 1.27 - Cross-Site Request Forgery Affected: *-1.27 Patched: Updated: June 29, 2026
LOW

payoneer-checkout

payoneer-checkout

Score: N/A Payoneer Checkout <= 3.4.0 - Missing Authorization Affected: *-3.4.0 Patched: 3.5.0 Updated: June 29, 2026
LOW

parallax-scrolling-enllax-js

parallax-scrolling-enllax-js

Score: N/A Parallax Scrolling Enllax.js <= 0.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-0.0.6 Patched: Updated: June 29, 2026
LOW

parallax-scrolling-enllax-js

parallax-scrolling-enllax-js

Score: N/A Parallax Scrolling Enllax.js <= 0.0.6 - Cross-Site Request Forgery Affected: *-0.0.6 Patched: Updated: June 29, 2026
LOW

Notification for Telegram

notification-for-telegram

Score: 97/100 Notification for Telegram <= 3.5.1 - Cross-Site Request Forgery Affected: *-3.5.1 Patched: 3.5.2 Updated: June 29, 2026
LOW

ninja-charts

ninja-charts

Score: N/A Ninja Charts <= 3.3.5 - Unauthenticated Information Exposure Affected: *-3.3.5 Patched: 3.3.6 Updated: June 29, 2026
LOW

new-simple-gallery

new-simple-gallery

Score: N/A New Simple Gallery <= 8.0 - Authenticated (Contributor+) SQL Injection Affected: *-8.0 Patched: Updated: June 29, 2026
LOW

multi-step-form

multi-step-form

Score: N/A Multi Step Form <= 1.7.25 - Authenticated (Admin+) Arbitrary File Upload Affected: *-1.7.25 Patched: 1.7.26 Updated: June 29, 2026
LOW

mstw-league-manager

mstw-league-manager

Score: N/A MSTW League Manager <= 2.10 - Cross-Site Request Forgery Affected: *-2.10 Patched: Updated: June 29, 2026
LOW

mshop-naver-talktalk

mshop-naver-talktalk

Score: N/A 코드엠샵 소셜톡 <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.2.1 Patched: Updated: June 29, 2026
LOW

media-author

media-author

Score: 91/100 Media Author <= 1.0.4 - Missing Authorization Affected: *-1.0.4 Patched: Updated: June 29, 2026
LOW

master-paper-collapse-toggle

master-paper-collapse-toggle

Score: 91/100 Master Paper Collapse Toggle <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting Affected: *-1.1 Patched: Updated: June 29, 2026
LOW

lingotek-translation

lingotek-translation

Score: 91/100 Ray Enterprise Translation <= 1.7.1 - Missing Authorization Affected: *-1.7.1 Patched: Updated: June 29, 2026

Showing 6501 to 6600 of 36189 results

Download: CSV JSON
Important: Review Required

Vulnerability data is aggregated from automated feeds and public sources. Results may include false positives or outdated information. Always verify details and apply updates in a staging environment before deploying to production.

Data updated daily from trusted sources. Last updated: June 29, 2026 at 13:22 UTC.