2,600 new vulnerabilities
WordPress Vulnerability
Database
2,600 known vulnerabilities across plugins, themes and core. Updated daily from multiple sources.
2,600
Total vulns
193
Critical
756
High
1,397
Medium
75
Low
2,542
Plugins
52
Themes
6
Core
9
Closed plugins
| Severity | Title | Type | Slug | CVE | Fixed in | Published |
|---|---|---|---|---|---|---|
| MEDIUM CVSS 6.4 |
EUVD-2026-51984 (CVE-2026-12231) — The Exclusive Addons for Elementor plugin for WordPres… |
plugin | |
CVE-2026-12231 | — | Aug 2, 2026 |
| UNKNOWN | Gallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token Disclosure |
plugin | gallery-for-google-photos |
CVE-2026-15236 | v1.2.1 | Aug 2, 2026 |
| UNKNOWN | Simply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and… |
plugin | simply-schedule-appointments |
CVE-2026-16540 | v1.6.12.6 | Aug 2, 2026 |
| UNKNOWN | WebToffee Cookie Consent < 3.5.3 - Consent Log Disclosure/Deletion, Page Creation & Licen… |
plugin | webtoffee-cookie-consent |
CVE-2026-13389 | v3.5.3 | Aug 2, 2026 |
| UNKNOWN | Charitable < 1.8.5.3 - Admin+ Stored XSS via Photo Field ALT Text |
plugin | charitable |
CVE-2025-15675 | v1.8.5.3 | Aug 2, 2026 |
| UNKNOWN | Frontend File Manager Plugin <= 23.6 - File Metadata Update via CSRF |
plugin | frontend-file-manager-plugin |
CVE-2026-16292 | — | Aug 2, 2026 |
| UNKNOWN | ProfileGrid < 5.9.9.8 - Subscriber+ Arbitrary Notification Deletion via IDOR |
plugin | profilegrid |
CVE-2026-16291 | v5.9.9.8 | Aug 2, 2026 |
| UNKNOWN | WooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media Download |
plugin | product-attachment-for-woocommerce |
CVE-2026-16285 | v2.3.3 | Aug 2, 2026 |
| UNKNOWN | Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ Arbitrary Post Modification … |
plugin | event-booking-manager-for-woocommerce |
CVE-2026-16064 | v5.3.7 | Aug 2, 2026 |
| UNKNOWN | Event Booking Manager for WooCommerce < 5.3.7 - Author+ Stored XSS via Event Timeline Con… |
plugin | event-booking-manager-for-woocommerce |
CVE-2026-16063 | v5.3.7 | Aug 2, 2026 |
| UNKNOWN | Event Booking Manager for WooCommerce < 5.3.7 - Contributor+ PHP Object Injection via Eve… |
plugin | event-booking-manager-for-woocommerce |
CVE-2026-16062 | v5.3.7 | Aug 2, 2026 |
| UNKNOWN | Narrative Publisher <= 1.0.7 - Contributor+ Stored XSS via narrative_post_script Post Meta |
plugin | narrative-publisher |
CVE-2026-16273 | — | Aug 2, 2026 |
| UNKNOWN | Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover |
plugin | login-social |
CVE-2026-16261 | — | Aug 2, 2026 |
| UNKNOWN | LWS Optimize < 3.4 - Subscriber+ Cache Deletion |
plugin | lws-optimize |
CVE-2026-16042 | v3.4 | Aug 2, 2026 |
| UNKNOWN | Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation |
plugin | pouco-import-users |
CVE-2026-16256 | — | Aug 2, 2026 |
| UNKNOWN | Simple Restrict < 1.2.9 - Contributor+ Restricted Content Disclosure via REST API |
plugin | simple-restrict |
CVE-2026-15939 | v1.2.9 | Aug 2, 2026 |
| UNKNOWN | RT Mega Menu < 1.5.2 - Subscriber+ Stored XSS via Menu Item CSS |
plugin | rt-mega-menu |
CVE-2026-15385 | v1.5.2 | Aug 2, 2026 |
| UNKNOWN | Element Pack Elementor Addons < 8.7.13 - Contributor+ DOM-Based Stored XSS via uikit Data… |
plugin | element-pack-addons-for-elementor |
CVE-2026-14817 | v8.7.13 | Aug 2, 2026 |
| UNKNOWN | Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset |
plugin | lenxel-wp |
CVE-2026-12586 | — | Aug 2, 2026 |
| UNKNOWN | Clever Mega Menu for Visual Composer <= 1.0.1 - Subscriber+ Menu Item Meta Update via sav… |
plugin | clever-mega-menu-for-visual-composer |
CVE-2026-11872 | — | Aug 2, 2026 |
| UNKNOWN | Meta Box < 5.13.1 - Contributor+ Arbitrary Attachment Deletion via IDOR |
plugin | meta-box |
CVE-2026-15248 | v5.13.1 | Aug 2, 2026 |
| UNKNOWN | ChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_g… |
plugin | ai-chatbot-for-woocommerce |
CVE-2026-15241 | v4.8.4 | Aug 2, 2026 |
| UNKNOWN | SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover vi… |
plugin | sms-alert |
CVE-2026-15206 | v3.9.8 | Aug 2, 2026 |
| UNKNOWN | Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via r… |
plugin | five-star-restaurant-reservations |
CVE-2026-15151 | v2.7.23 | Aug 2, 2026 |
| UNKNOWN | FluentBoards < 1.95.3 - Subscriber+ Cross-Board Task Disclosure via IDOR |
plugin | fluentboards |
CVE-2026-14938 | v1.95.3 | Aug 2, 2026 |
| UNKNOWN | JetEngine < 3.8.12 - Contributor+ Stored XSS via jet_engine Shortcode |
plugin | jetengine |
CVE-2026-14864 | v3.8.12 | Aug 2, 2026 |
| UNKNOWN | King Addons for Elementor < 51.1.76 - Reflected XSS via Posts Grid Widget |
plugin | king-addons-for-elementor |
CVE-2026-14841 | v51.1.76 | Aug 2, 2026 |
| UNKNOWN | CVE-2026-16063 — The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7… |
plugin | |
CVE-2026-16063 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-16062 — The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7… |
plugin | |
CVE-2026-16062 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-16042 — The LWS Optimize WordPress plugin before 3.4 does not perform a capabil… |
plugin | |
CVE-2026-16042 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-15939 — The Simple Restrict WordPress plugin before 1.2.9 does not enforce its c… |
plugin | |
CVE-2026-15939 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-15385 — The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capab… |
plugin | |
CVE-2026-15385 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-15248 — The Meta Box WordPress plugin before 5.13.1 does not verify that a user … |
plugin | |
CVE-2026-15248 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-15241 — The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not p… |
plugin | |
CVE-2026-15241 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-15236 — The Gallery for Google Photos WordPress plugin before 1.2.1 does not pr… |
plugin | |
CVE-2026-15236 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-15206 — The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile v… |
plugin | |
CVE-2026-15206 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-15151 — The Five Star Restaurant Reservations WordPress plugin before 2.7.23 do… |
plugin | |
CVE-2026-15151 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-14938 — The FluentBoards WordPress plugin before 1.95.3 does not verify that th… |
plugin | |
CVE-2026-14938 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-14864 — The JetEngine WordPress plugin before 3.8.12 does not escape a post meta… |
plugin | |
CVE-2026-14864 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-14841 — The King Addons for Elementor WordPress plugin before 51.1.76 does not … |
plugin | |
CVE-2026-14841 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-14817 — The Element Pack Addons for Elementor WordPress plugin before 8.7.13 do… |
plugin | |
CVE-2026-14817 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-13389 — The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perf… |
plugin | |
CVE-2026-13389 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-11872 — The Clever Mega Menu for Visual Composer WordPress plugin through 1.0.1 … |
plugin | |
CVE-2026-11872 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2026-12586 — The Lenxel WP WordPress theme through 1.0.31 does not perform any author… |
theme | |
CVE-2026-12586 | — | Aug 2, 2026 |
| UNKNOWN | CVE-2025-15675 — The Charitable WordPress plugin before 1.8.5.3 does not sanitise and es… |
plugin | |
CVE-2025-15675 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51953 (CVE-2026-15236) — The Gallery for Google Photos WordPress plugin before… |
plugin | |
CVE-2026-15236 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2025-210588 (CVE-2025-15675) — The Charitable WordPress plugin before 1.8.5.3 does … |
plugin | |
CVE-2025-15675 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51951 (CVE-2026-16540) — The Simply Schedule Appointments WordPress plugin befo… |
plugin | |
CVE-2026-16540 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51952 (CVE-2026-13389) — The webtoffee-cookie-consent WordPress plugin before 3… |
plugin | |
CVE-2026-13389 | — | Aug 2, 2026 |
| UNKNOWN CVSS 0.0 |
EUVD-2026-51945 (CVE-2026-16285) — The Product Attachment for WooCommerce WordPress plugi… |
plugin | |
CVE-2026-16285 | — | Aug 2, 2026 |
…