Vulnerability alerts
When a vulnerability is disclosed in a widely used plugin or theme, this page explains what it means and what to do about it. Updated daily.
An entry is listed when it affects 10,000 or more sites, or is estimated likely to be exploited (EPSS 1% or higher), or is known to be exploited (listed in the CISA KEV catalog).
- Pods – Custom Content Types and Fields — CVE-2026-76573
- Post Grid — CVE-2024-11080
- Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel — CVE-2026-85414
- Unlimited Elements For Elementor — CVE-2026-75586
- W3 Total Cache — CVE-2026-78438
- Spam protection, Honeypot, Anti-Spam by CleanTalk — CVE-2026-77830
- Welcart e-Commerce — CVE-2026-19887
- Ninja Forms – The Contact Form Builder That Grows With You — CVE-2026-19769
- SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz — CVE-2026-18406
- DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer — CVE-2026-8625
- DearFlip – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer — CVE-2026-8623
- Theme My Login — CVE-2026-83628
- Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN — CVE-2026-83627
- iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more — CVE-2026-77263
- iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more — CVE-2026-77233
- Social Chat – Click To Chat App Button — CVE-2026-18404
- Events Manager – Calendar, Bookings, Tickets, and more! — CVE-2025-14945
- LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — CVE-2026-82024
- LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — CVE-2026-82023
- GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor — CVE-2026-2573
- Jetpack – WP Security, Backup, Speed, & Growth — WF-72f4776f-5450-4022-92dd-47ddaa91a5cd
- Jetpack – WP Security, Backup, Speed, & Growth — WF-eda9ae01-cdc4-43e0-8a4c-1ec365939fa8
- Jetpack – WP Security, Backup, Speed, & Growth — WF-f72c0a27-9602-4465-a14a-15c2a34e578b
- JetFormBuilder — Dynamic Blocks Form Builder — WF-b0fe7d29-118f-42fb-9e48-6217faaa689b
- SEOWriting — CVE-2026-75134
- Broken Link Checker — CVE-2026-75528
- Simple Membership — CVE-2026-77194
- Welcart e-Commerce — CVE-2026-19914
- Live Composer – Free WordPress Website Builder — CVE-2026-16788
- Live Composer – Free WordPress Website Builder — CVE-2026-16786
- Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) — CVE-2026-77189
- BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot — CVE-2026-75980
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor — CVE-2026-75964
- Blocksy Companion — CVE-2026-18488
- LearnPress – WordPress LMS Plugin for Create and Sell Online Courses — CVE-2026-77823
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor — CVE-2026-75965
- Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits — CVE-2026-75921
- Live Composer – Free WordPress Website Builder — CVE-2026-16787
- Live Composer – Free WordPress Website Builder — CVE-2026-13203
- WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode — CVE-2026-75865
- Booking for Appointments and Events Calendar – Amelia — CVE-2026-9055
- miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) — CVE-2026-82229
- Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress — CVE-2026-66047
- WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode — CVE-2026-82970
- Customer Reviews for WooCommerce — CVE-2026-76585
- Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) — CVE-2026-81766
- User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor — CVE-2026-76548
- bbPress — CVE-2026-74010
- WCFM Marketplace – Multivendor Marketplace for WooCommerce — CVE-2026-83562
- SAML Single Sign On – SSO Login — CVE-2026-75807
- Customer Reviews for WooCommerce — CVE-2026-6176
- Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI — CVE-2026-5096
- Envira Gallery – Image Photo Gallery, Albums, Video Gallery, Slideshows & More — CVE-2026-3423
- GiveWP – Donation Plugin and Fundraising Platform — CVE-2026-5510
- Booking for Appointments and Events Calendar – Amelia — CVE-2026-6286
- wpForo Forum — CVE-2026-5097
- Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization — CVE-2026-77365
- TranslatePress – Translate Multilingual sites with AI Translation — CVE-2026-76053
- LiteSpeed Cache — CVE-2026-3129
- One User Avatar | User Profile Picture — CVE-2026-18983
- LiteSpeed Cache — CVE-2026-18978
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder — CVE-2026-18324
- Tutor LMS – eLearning and online course solution — CVE-2026-16759
- Smart Slider 3 — CVE-2026-15798
- GiveWP – Donation Plugin and Fundraising Platform — CVE-2026-82222
- Greenshift – animation and page builder blocks — CVE-2026-5092
- WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards — CVE-2026-3235
- Reviews and Rating – Google Reviews — CVE-2026-2388
- Gutenverse – WordPress Blocks, Page Builder & Site Editor — CVE-2026-3002
- Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More — CVE-2026-18331
- WP Fastest Cache – WordPress Cache Plugin — CVE-2026-19760
- TranslatePress – Translate Multilingual sites with AI Translation — CVE-2026-19632
- ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution — CVE-2026-75971
- All-in-One WP Migration and Backup — CVE-2026-19949
- Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin — CVE-2026-18547