2,567 new vulnerabilities
WordPress Vulnerability
Database
2,567 known vulnerabilities across plugins, themes and core. Updated daily from multiple sources.
2,567
Total vulns
193
Critical
755
High
1,395
Medium
75
Low
2,509
Plugins
52
Themes
6
Core
9
Closed plugins
| Severity | Title | Type | Slug | CVE | Fixed in | Published |
|---|---|---|---|---|---|---|
| MEDIUM CVSS 6.4 |
EUVD-2026-51984 (CVE-2026-12231) — The Exclusive Addons for Elementor plugin for WordPres… |
plugin | |
CVE-2026-12231 | — | Aug 2, 2026 |
| UNKNOWN | Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure |
plugin | gallery-for-google-photos |
CVE-2026-15236 | v1.2.1 | Aug 2, 2026 |
| UNKNOWN | Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and… |
plugin | simply-schedule-appointments |
CVE-2026-16540 | v1.6.12.6 | Aug 2, 2026 |
| UNKNOWN | WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & Licen… |
plugin | webtoffee-cookie-consent |
CVE-2026-13389 | v3.5.3 | Aug 2, 2026 |
| UNKNOWN | Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text |
plugin | charitable |
CVE-2025-15675 | v1.8.5.3 | Aug 2, 2026 |
| UNKNOWN | Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF |
plugin | frontend-file-manager-plugin |
CVE-2026-16292 | — | Aug 2, 2026 |
| UNKNOWN | ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR |
plugin | profilegrid |
CVE-2026-16291 | v5.9.9.8 | Aug 2, 2026 |
| UNKNOWN | WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download |
plugin | product-attachment-for-woocommerce |
CVE-2026-16285 | v2.3.3 | Aug 2, 2026 |
| UNKNOWN | Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification … |
plugin | event-booking-manager-for-woocommerce |
CVE-2026-16064 | v5.3.7 | Aug 2, 2026 |
| UNKNOWN | Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Con… |
plugin | event-booking-manager-for-woocommerce |
CVE-2026-16063 | v5.3.7 | Aug 2, 2026 |
| UNKNOWN | Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Eve… |
plugin | event-booking-manager-for-woocommerce |
CVE-2026-16062 | v5.3.7 | Aug 2, 2026 |
| UNKNOWN | Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta |
plugin | narrative-publisher |
CVE-2026-16273 | — | Aug 2, 2026 |
| UNKNOWN | Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover |
plugin | login-social |
CVE-2026-16261 | — | Aug 2, 2026 |
| UNKNOWN | LWS Optimize < 3.4 - Subscriber+ Cache Deletion |
plugin | lws-optimize |
CVE-2026-16042 | v3.4 | Aug 2, 2026 |
| UNKNOWN | Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation |
plugin | pouco-import-users |
CVE-2026-16256 | — | Aug 2, 2026 |
| UNKNOWN | Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API |
plugin | simple-restrict |
CVE-2026-15939 | v1.2.9 | Aug 2, 2026 |
| UNKNOWN | RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS |
plugin | rt-mega-menu |
CVE-2026-15385 | v1.5.2 | Aug 2, 2026 |
| UNKNOWN | Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data… |
plugin | element-pack-addons-for-elementor |
CVE-2026-14817 | v8.7.13 | Aug 2, 2026 |
| UNKNOWN | Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset |
plugin | lenxel-wp |
CVE-2026-12586 | — | Aug 2, 2026 |
| UNKNOWN | Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via sav… |
plugin | clever-mega-menu-for-visual-composer |
CVE-2026-11872 | — | Aug 2, 2026 |
| UNKNOWN | Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR |
plugin | meta-box |
CVE-2026-15248 | v5.13.1 | Aug 2, 2026 |
| UNKNOWN | ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_g… |
plugin | ai-chatbot-for-woocommerce |
CVE-2026-15241 | v4.8.4 | Aug 2, 2026 |
| UNKNOWN | SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover vi… |
plugin | sms-alert |
CVE-2026-15206 | v3.9.8 | Aug 2, 2026 |
| UNKNOWN | Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via r… |
plugin | five-star-restaurant-reservations |
CVE-2026-15151 | v2.7.23 | Aug 2, 2026 |
| UNKNOWN | FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR |
plugin | fluentboards |
CVE-2026-14938 | v1.95.3 | Aug 2, 2026 |
| UNKNOWN | JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode |
plugin | jetengine |
CVE-2026-14864 | v3.8.12 | Aug 2, 2026 |
| UNKNOWN | King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget |
plugin | king-addons-for-elementor |
CVE-2026-14841 | v51.1.76 | Aug 2, 2026 |
| UNKNOWN | CVE-2026-12586 — The Lenxel WP WordPress theme through 1.0.31 does not perform any author… |
theme | |
CVE-2026-12586 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51953 (CVE-2026-15236) — The Gallery for Google Photos WordPress plugin before… |
plugin | |
CVE-2026-15236 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2025-210588 (CVE-2025-15675) — The Charitable WordPress plugin before 1.8.5.3 does … |
plugin | |
CVE-2025-15675 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51951 (CVE-2026-16540) — The Simply Schedule Appointments WordPress plugin befo… |
plugin | |
CVE-2026-16540 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51952 (CVE-2026-13389) — The webtoffee-cookie-consent WordPress plugin before 3… |
plugin | |
CVE-2026-13389 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51945 (CVE-2026-16285) — The Product Attachment for WooCommerce WordPress plugi… |
plugin | |
CVE-2026-16285 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51946 (CVE-2026-16291) — The ProfileGrid WordPress plugin before 5.9.9.8 does … |
plugin | |
CVE-2026-16291 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51947 (CVE-2026-16292) — The Frontend File Manager Plugin WordPress plugin thro… |
plugin | |
CVE-2026-16292 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51948 (CVE-2026-16062) — The Event Booking Manager for WooCommerce WordPress p… |
plugin | |
CVE-2026-16062 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51949 (CVE-2026-16063) — The Event Booking Manager for WooCommerce WordPress p… |
plugin | |
CVE-2026-16063 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51950 (CVE-2026-16064) — The Event Booking Manager for WooCommerce WordPress p… |
plugin | |
CVE-2026-16064 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51942 (CVE-2026-16042) — The LWS Optimize WordPress plugin before 3.4 does not… |
plugin | |
CVE-2026-16042 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51943 (CVE-2026-16261) — The login-social WordPress plugin through 1.0.4 does n… |
plugin | |
CVE-2026-16261 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51944 (CVE-2026-16273) — The Narrative Publisher WordPress plugin through 1.0.7… |
plugin | |
CVE-2026-16273 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51936 (CVE-2026-15385) — The RT Mega Menu WordPress plugin before 1.5.2 does n… |
plugin | |
CVE-2026-15385 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51937 (CVE-2026-15939) — The Simple Restrict WordPress plugin before 1.2.9 does… |
plugin | |
CVE-2026-15939 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51938 (CVE-2026-16256) — The POUCO Import Users WordPress plugin through 1.0.0 … |
plugin | |
CVE-2026-16256 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51939 (CVE-2026-11872) — The Clever Mega Menu for Visual Composer WordPress plu… |
plugin | |
CVE-2026-11872 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51940 (CVE-2026-12586) — The Lenxel WP WordPress theme through 1.0.31 does not … |
plugin | |
CVE-2026-12586 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51941 (CVE-2026-14817) — The Element Pack Addons for Elementor WordPress plugi… |
plugin | |
CVE-2026-14817 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51933 (CVE-2026-15206) — The SMS Alert WordPress plugin before 3.9.8 does not … |
plugin | |
CVE-2026-15206 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51934 (CVE-2026-15241) — The AI ChatBot for WooCommerce WordPress plugin befor… |
plugin | |
CVE-2026-15241 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51935 (CVE-2026-15248) — The Meta Box WordPress plugin before 5.13.1 does not v… |
plugin | |
CVE-2026-15248 | — | Aug 2, 2026 |
…