VulnTitan Plugin

Scan WordPress with VulnTitan.

Free plugin for live checks. Pro adds scheduled scans, malware detection, integrity monitoring, alerts and guided remediation.

Free visibility. Pro automation. Download Free Upgrade to Pro
Live Database

Latest vulnerability records

Search by title, slug or version, then narrow the feed by asset type and severity.

36,410 results Updated continuously

Records stay compact by default so the feed is easier to scan. Expand any advisory when you need remediation and full version coverage.

  • Plugin Medium Patched: Yes CVSS 6.4/10
    Shariff Wrapper <= 4.6.20 - Authenticated (Contributor+) Cross-Site Scripting

    The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headline' parameter in the [shariff] shortcode in all versions up to, and including, 4.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability occurs because the plugin uses a custom wp_kses implementation with permissive allowed HTML tags, and then performs a str_replace operation that injects HTML after sanitization, allowing event handlers to be introduced through the %total placeholder in the style attribute.

    Published
    May 27, 2026
    Affected Product
    Shariff Wrapper
    Plugin · shariff
    Affected window
    Versions up to 4.6.20
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 4.6.21
    Recommended next step
    Update to 4.6.21
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 4.6.20
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    4.6.21
    Update to this version or a newer safe release.
    What to do

    Update to version 4.6.21, or a newer patched version

    Affected versions
    Versions up to 4.6.20
    Safe / patched versions
    4.6.21
  • Plugin Medium Patched: Yes CVSS 5.3/10
    Appointment Booking Calendar <= 1.6.11.8 - Missing Authorization to Unauthenticated Arbitrary Modification via Bulk Appointments REST API Endpoint

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.6.11.8 due to the plugin not properly verifying that a user is authorized to perform an action via the bulk appointments REST API endpoint. This makes it possible for unauthenticated attackers to modify arbitrary appointment records including customer PII, payment status, and meeting URL fields, and to expose full customer PII from existing appointment records via the bulk endpoint response. The public nonce is a static, user-independent value present in the HTML source of any page hosting the [ssa_booking] shortcode, meaning any visitor who has viewed such a page can obtain it and target any appointment in the system without authentication.

    Published
    May 27, 2026
    Affected Product
    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
    Plugin · simply-schedule-appointments
    Affected window
    Versions up to 1.6.11.8
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.6.11.9
    Recommended next step
    Update to 1.6.11.9
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.6.11.8
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.6.11.9
    Update to this version or a newer safe release.
    What to do

    Update to version 1.6.11.9, or a newer patched version

    Affected versions
    Versions up to 1.6.11.8
    Safe / patched versions
    1.6.11.9
  • Plugin Medium Patched: Yes CVSS 6.5/10
    Photo Gallery by 10Web <= 1.8.40 - Authenticated (Contributor+) SQL Injection via 'order_by' Shortcode Attribute

    The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'order_by' parameter in all versions up to, and including, 1.8.40 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is exploitable by embedding a malicious shortcode in a post or draft, allowing the injected SQL to execute when the shortcode is rendered.

    Published
    May 27, 2026
    Affected Product
    Photo Gallery by 10Web – Mobile-Friendly Image Gallery
    Plugin · photo-gallery
    Affected window
    Versions up to 1.8.40
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.8.41
    Recommended next step
    Update to 1.8.41
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.8.40
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.8.41
    Update to this version or a newer safe release.
    What to do

    Update to version 1.8.41, or a newer patched version

    Affected versions
    Versions up to 1.8.40
    Safe / patched versions
    1.8.41
  • Plugin Medium Patched: Yes CVSS 4.3/10
    Visualizer: Tables and Charts Manager for WordPress <= 3.11.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Chart Creation and Modification via renderChartPages() and uploadData() Functions

    The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is due to a missing capability check on the renderChartPages() and uploadData() functions, where the wp_ajax_visualizer-create-chart and wp_ajax_visualizer-edit-chart AJAX actions invoke renderChartPages() without any current_user_can() check, and wp_ajax_visualizer-upload-data invokes uploadData() which also lacks a capability check and validates its nonce without an action argument, making it trivially bypassable. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create arbitrary chart posts and access or modify chart data belonging to other users, including administrators.

    Published
    May 27, 2026
    Affected Product
    Visualizer: Tables and Charts Manager for WordPress
    Plugin · visualizer
    Affected window
    Versions up to 3.11.14
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 3.11.15
    Recommended next step
    Update to 3.11.15
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 3.11.14
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    3.11.15
    Update to this version or a newer safe release.
    What to do

    Update to version 3.11.15, or a newer patched version

    Affected versions
    Versions up to 3.11.14
    Safe / patched versions
    3.11.15
  • Plugin Medium Patched: Yes CVSS 4.3/10
    Equalize Digital Accessibility Checker <= 1.42.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Accessibility Issue Modification via edac_insert_ignore_data AJAX Action

    The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.42.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify the ignore state, ignore reason, and ignore comment of arbitrary accessibility issues across the entire site — including mass modification of all rows sharing an 'object' identifier when largeBatch=true is supplied — corrupting accessibility audit integrity by hiding or dismissing findings outside their authorization scope.

    Published
    May 27, 2026
    Affected Product
    Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance
    Plugin · accessibility-checker
    Affected window
    Versions up to 1.42.0
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.42.1
    Recommended next step
    Update to 1.42.1
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.42.0
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.42.1
    Update to this version or a newer safe release.
    What to do

    Update to version 1.42.1, or a newer patched version

    Affected versions
    Versions up to 1.42.0
    Safe / patched versions
    1.42.1
  • Plugin Medium Patched: Yes CVSS 4.3/10
    PDF Embedder <= 4.9.3 - Authenticated (Contributor+) Information Exposure via Block Editor Page

    The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration data. License key exposure occurs when the premium add-on is also installed and has saved a key; on Lite-only installations, the exposed data is limited to non-sensitive viewer configuration values such as width, height, toolbar settings, usage tracking, and plan.

    Published
    May 27, 2026
    Affected Product
    PDF Embedder
    Plugin · pdf-embedder
    Affected window
    Versions up to 4.9.3
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 5.0.0
    Recommended next step
    Update to 5.0.0
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 4.9.3
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    5.0.0
    Update to this version or a newer safe release.
    What to do

    Update to version 5.0.0, or a newer patched version

    Affected versions
    Versions up to 4.9.3
    Safe / patched versions
    5.0.0
  • Plugin Critical Patched: Yes CVSS 9.1/10
    GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters

    The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover $_SERVER), then passed through bare esc_sql() before being interpolated into unquoted numeric positions in the proximity-search query (HAVING/SELECT clause distance math, BETWEEN bounding-box pre-filter) built by gmw_locations_query() in plugins/posts-locator/includes/class-gmw-wp-query.php. Because esc_sql() only escapes string delimiters and these positions are numeric, payloads such as `1 OR SLEEP(3)` survived sanitization. Fixed in 4.5.5 by adding an upstream is_numeric() guard that short-circuits the WHERE clause to `AND 1 = 0` when either coordinate is non-numeric, and by replacing the three esc_sql() calls with (float) casts.

    Published
    May 27, 2026
    Affected Product
    GEO my WP
    Plugin · geo-my-wp
    Affected window
    Versions up to 4.5.4
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 4.5.5
    Recommended next step
    Update to 4.5.5
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 4.5.4
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    4.5.5
    Update to this version or a newer safe release.
    What to do

    Update to version 4.5.5, or a newer patched version

    Affected versions
    Versions up to 4.5.4
    Safe / patched versions
    4.5.5
  • Plugin Medium Patched: Yes CVSS 4.3/10
    PeachPay <= 1.120.46 - Cross-Site Request Forgery to Stripe Unlink

    The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.120.46. This is due to missing or incorrect nonce validation on the peachpay_stripe_handle_admin_actions function. This makes it possible for unauthenticated attackers to permanently delete all stored Stripe credentials — including publishable keys, secret keys, webhook secrets, and Apple Pay configuration — from the WordPress database, disabling Stripe payment processing for the store via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

    Published
    May 27, 2026
    Affected Product
    PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)
    Plugin · peachpay-for-woocommerce
    Affected window
    Versions up to 1.120.46
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.120.47
    Recommended next step
    Update to 1.120.47
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.120.46
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.120.47
    Update to this version or a newer safe release.
    What to do

    Update to version 1.120.47, or a newer patched version

    Affected versions
    Versions up to 1.120.46
    Safe / patched versions
    1.120.47
  • Plugin High Patched: Yes CVSS 7.5/10
    Appointment Booking Calendar <= 1.6.11.8 - Unauthenticated SQL Injection via 'append_where_sql' Parameter

    The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'append_where_sql' parameter in all versions up to, and including, 1.6.11.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The /appointments/bulk REST endpoint is reachable by unauthenticated attackers because its permission check accepts a public nonce that is embedded in the booking widget's frontend JavaScript (ssa.api.public_nonce) and visible to all site visitors; exploitation requires issuing the request as a PUT with an application/x-www-form-urlencoded body so that PHP's superglobals are not populated and the blocklist check silently passes.

    Published
    May 27, 2026
    Affected Product
    Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
    Plugin · simply-schedule-appointments
    Affected window
    Versions up to 1.6.11.8
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.6.11.9
    Recommended next step
    Update to 1.6.11.9
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.6.11.8
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.6.11.9
    Update to this version or a newer safe release.
    What to do

    Update to version 1.6.11.9, or a newer patched version

    Affected versions
    Versions up to 1.6.11.8
    Safe / patched versions
    1.6.11.9
  • Plugin High Patched: Yes CVSS 7.2/10
    SlimStat Analytics <= 5.4.11 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header

    The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in all versions up to, and including, 5.4.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The show_complete_user_agent_tooltip setting must be explicitly enabled by an administrator (disabled by default) for the stored payload to be rendered and executed.

    Published
    May 27, 2026
    Affected Product
    SlimStat Analytics
    Plugin · wp-slimstat
    Affected window
    Versions up to 5.4.11
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 5.4.12
    Recommended next step
    Update to 5.4.12
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 5.4.11
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    5.4.12
    Update to this version or a newer safe release.
    What to do

    Update to version 5.4.12, or a newer patched version

    Affected versions
    Versions up to 5.4.11
    Safe / patched versions
    5.4.12
Coverage Hubs

Browse high-interest plugin and theme vulnerability hubs.

Use hub pages to review all indexed records for a single WordPress plugin or theme instead of scanning the global feed one advisory at a time.

36,410 indexed records 14,621 tracked plugins 1,637 tracked themes
Security Guides

Start with the WordPress security topics already showing search demand.

Browse practical guides for WordPress security audit, WooCommerce security, hardening, brute force protection, monitoring, and incident response.

Browse Blog