VulnTitan Plugin

Scan WordPress with VulnTitan.

Free plugin for live checks. Pro adds scheduled scans, malware detection, integrity monitoring, alerts and guided remediation.

Free visibility. Pro automation. Download Free Upgrade to Pro
Live Database

Latest vulnerability records

Search by title, slug or version, then narrow the feed by asset type and severity.

36,110 results Updated continuously

Records stay compact by default so the feed is easier to scan. Expand any advisory when you need remediation and full version coverage.

  • Plugin High Patched: Yes CVSS 7.5/10
    Avada Builder <= 3.15.1 - Unauthenticated SQL Injection via 'product_order' Parameter

    The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter in all versions up to, and including, 3.15.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Note: The vulnerability can only be exploited if WooCommerce was previously used and then deactivated.

    Published
    May 12, 2026
    Affected Product
    Avada (Fusion) Builder
    Plugin · fusion-builder
    Affected window
    Versions up to 3.15.1
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 3.15.2
    Recommended next step
    Update to 3.15.2
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 3.15.1
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    3.15.2
    Update to this version or a newer safe release.
    What to do

    Update to version 3.15.2, or a newer patched version

    Affected versions
    Versions up to 3.15.1
    Safe / patched versions
    3.15.2
  • Plugin Medium Patched: Yes CVSS 6.5/10
    Avada Builder <= 3.15.2 - Authenticated (Subscriber+) Arbitrary File Read via 'custom_svg' Shortcode Parameter

    The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2 via the 'fusion_get_svg_from_file' function with the 'custom_svg' parameter of the 'fusion_section_separator' shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability was partially patched in version 3.15.2 and fully patched in version 3.15.3.

    Published
    May 12, 2026
    Affected Product
    Avada (Fusion) Builder
    Plugin · fusion-builder
    Affected window
    Versions up to 3.15.2
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 3.15.3
    Recommended next step
    Update to 3.15.3
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 3.15.2
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    3.15.3
    Update to this version or a newer safe release.
    What to do

    Update to version 3.15.3, or a newer patched version

    Affected versions
    Versions up to 3.15.2
    Safe / patched versions
    3.15.3
  • Plugin Medium Patched: Yes CVSS 5.3/10
    Tutor LMS <= 3.9.9 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Post Deletion via 'course' GET Parameter

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to and including 3.9.9. This is due to the `get_course_id_by()` function unconditionally trusting the user-supplied `course` GET parameter as the authoritative course ID for content ownership lookups, which is then consumed by `can_user_manage()`, the plugin's sole authorization gate for instructor-level operations, causing it to evaluate instructor membership against the attacker-controlled course rather than the course that actually owns the target content object. This makes it possible for authenticated attackers, with instructor-level access and above, to perform unauthorized operations on any other instructor's course content, including permanently deleting lessons, assignments, quizzes (with cascading deletion of all student attempt data), topics, announcements, and Q&A threads, as well as creating or modifying lessons, topics, and announcements in victim courses, manipulating student quiz grades, and reading unpublished lesson and quiz content.

    Published
    May 12, 2026
    Affected Product
    Tutor LMS – eLearning and online course solution
    Plugin · tutor
    Affected window
    Versions up to 3.9.9
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 3.9.10
    Recommended next step
    Update to 3.9.10
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 3.9.9
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    3.9.10
    Update to this version or a newer safe release.
    What to do

    Update to version 3.9.10, or a newer patched version

    Affected versions
    Versions up to 3.9.9
    Safe / patched versions
    3.9.10
  • Plugin High Patched: Yes CVSS 7.5/10
    JoomSport <= 5.7.7 - Unauthenticated SQL Injection via 'sortf' Parameter

    The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sortf' parameter in all versions up to, and including, 5.7.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published
    May 12, 2026
    Affected Product
    JoomSport – for Sports: Team & League, Football, Hockey & more
    Plugin · joomsport-sports-league-results-management
    Affected window
    Versions up to 5.7.7
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 5.7.8
    Recommended next step
    Update to 5.7.8
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 5.7.7
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    5.7.8
    Update to this version or a newer safe release.
    What to do

    Update to version 5.7.8, or a newer patched version

    Affected versions
    Versions up to 5.7.7
    Safe / patched versions
    5.7.8
  • Plugin Medium Patched: Yes CVSS 5.3/10
    ilGhera Support System for WooCommerce <= 1.3.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure

    The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket content, including sensitive customer information and private communications, by providing a ticket ID.

    Published
    May 12, 2026
    Affected Product
    ilGhera Support System for WooCommerce
    Plugin · wc-support-system
    Affected window
    Versions up to 1.3.0
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.3.1
    Recommended next step
    Update to 1.3.1
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.3.0
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.3.1
    Update to this version or a newer safe release.
    What to do

    Update to version 1.3.1, or a newer patched version

    Affected versions
    Versions up to 1.3.0
    Safe / patched versions
    1.3.1
  • Plugin Medium Patched: Yes CVSS 6.4/10
    Cost of Goods: Product Cost & Profit Calculator for WooCommerce <= 4.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

    The Cost of Goods: Product Cost & Profit Calculator for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'alg_wc_cog_product_cost' and 'alg_wc_cog_product_profit' shortcodes in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published
    May 12, 2026
    Affected Product
    Cost of Goods: Product Cost & Profit Calculator for WooCommerce
    Plugin · cost-of-goods-for-woocommerce
    Affected window
    Versions up to 4.1.0
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 4.1.1
    Recommended next step
    Update to 4.1.1
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 4.1.0
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    4.1.1
    Update to this version or a newer safe release.
    What to do

    Update to version 4.1.1, or a newer patched version

    Affected versions
    Versions up to 4.1.0
    Safe / patched versions
    4.1.1
  • Plugin Medium Patched: Yes CVSS 6.5/10
    Charitable <= 1.8.10.4 - Authenticated (Custom+) SQL Injection via 's' Search Parameter

    The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 1.8.10.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with access to the donation management admin area (requiring the edit_others_donations capability) and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published
    May 12, 2026
    Affected Product
    Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More
    Plugin · charitable
    Affected window
    Versions up to 1.8.10.4
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.8.10.5
    Recommended next step
    Update to 1.8.10.5
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.8.10.4
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.8.10.5
    Update to this version or a newer safe release.
    What to do

    Update to version 1.8.10.5, or a newer patched version

    Affected versions
    Versions up to 1.8.10.4
    Safe / patched versions
    1.8.10.5
  • Plugin Medium Patched: Yes CVSS 4.3/10
    Broadstreet <= 1.53.1 - Missing Authorization to Authenticated (Subscriber+) Advertiser Creation

    The Broadstreet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the create_advertiser AJAX action in all versions up to, and including, 1.53.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create advertisers.

    Published
    May 12, 2026
    Affected Product
    Broadstreet
    Plugin · broadstreet
    Affected window
    Versions up to 1.53.1
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.53.2
    Recommended next step
    Update to 1.53.2
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.53.1
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.53.2
    Update to this version or a newer safe release.
    What to do

    Update to version 1.53.2, or a newer patched version

    Affected versions
    Versions up to 1.53.1
    Safe / patched versions
    1.53.2
  • Plugin Medium Patched: Yes CVSS 5.3/10
    Broadstreet <= 1.53.1 - Authenticated (Subscriber+) Information Disclosure

    The Broadstreet plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.53.1 via the get_sponsored_meta() AJAX action. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected and private business details.

    Published
    May 12, 2026
    Affected Product
    Broadstreet
    Plugin · broadstreet
    Affected window
    Versions up to 1.53.1
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.53.2
    Recommended next step
    Update to 1.53.2
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.53.1
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.53.2
    Update to this version or a newer safe release.
    What to do

    Update to version 1.53.2, or a newer patched version

    Affected versions
    Versions up to 1.53.1
    Safe / patched versions
    1.53.2
  • Plugin Medium Patched: Yes CVSS 4.4/10
    Broadstreet <= 1.53.1 - Authenticated (Admin+) Stored Cross-Site Scripting

    The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.53.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.

    Published
    May 12, 2026
    Affected Product
    Broadstreet
    Plugin · broadstreet
    Affected window
    Versions up to 1.53.1
    Expand for exact coverage and remediation detail.
    Patch status
    Patched release available
    Fixed in 1.53.2
    Recommended next step
    Update to 1.53.2
    Move to a safe release and validate after update.
    Detailed remediation and version lists stay hidden until expanded.
    Affected if you're using
    Versions up to 1.53.1
    Check the full report if you need exact branch-by-branch coverage.
    Patch available
    Yes
    A fixed release is listed for this issue.
    Fixed in
    1.53.2
    Update to this version or a newer safe release.
    What to do

    Update to version 1.53.2, or a newer patched version

    Affected versions
    Versions up to 1.53.1
    Safe / patched versions
    1.53.2
Coverage Hubs

Browse high-interest plugin and theme vulnerability hubs.

Use hub pages to review all indexed records for a single WordPress plugin or theme instead of scanning the global feed one advisory at a time.

36,110 indexed records 14,529 tracked plugins 1,633 tracked themes
Security Guides

Start with the WordPress security topics already showing search demand.

Browse practical guides for WordPress security audit, WooCommerce security, hardening, brute force protection, monitoring, and incident response.

Browse Blog