🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1259 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0a5a547c-6b24-4cb6-ad0e-b12a8f37472a MEDIUM 4.9 The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to downl… wordfence
07dc60e0-a0b4-4db6-8033-ebd01fb697d0
< 3.0.0
MEDIUM 4.9 The Mailing Group Listserv plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.9 d… wordfence
0747c996-982c-42a9-942e-2fa7056127f8
< 5.2.5
MEDIUM 4.9 The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.4 due to insuf… wordfence
05ff1b1e-f7ba-485d-9421-9bb38f6831ef
< 1.0.4
MEDIUM 4.9 The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to SQL Injection via the 'id' par… wordfence
059e358d-422d-48e8-a11e-fed52770f4d9 MEDIUM 4.9 The Contact Form 7 Database – CFDB7 plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
059c2d6d-1296-4463-96ae-a95ba7dad70a
< 3.5.1.37
MEDIUM 4.9 The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1… wordfence
0540f70d-009a-4776-8717-f096e30a11d3
< 3.1.3
MEDIUM 4.9 The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all version… wordfence
04bc4a20-0136-4fb4-9489-07140b2b86aa
< 2.2.24
MEDIUM 4.9 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' para… wordfence
04641506-5b0e-48bc-ad50-c81dda996ecf
< 1.5.1
MEDIUM 4.9 The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and '… wordfence
0424e4af-5225-45ed-8bc6-40654851e44f MEDIUM 4.9 The Pay with Contact Form 7 plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.4 … wordfence
03cb41d2-67c8-457f-8d85-7aede8e12d44
< 6.4.3
MEDIUM 4.9 The ShortPixel Image Optimizer plugin for WordPress is vulnerable to Arbitrary File Read via path traversal in the 'load… wordfence
03bf84e2-c101-416d-a953-c63ecd1dba7d
< 5.1.5
MEDIUM 4.9 The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and includin… wordfence
03258713-0a63-4469-ba44-b25998d2411f
< 1.4.3
MEDIUM 4.9 The Integration for Contact Form 7 HubSpot plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… wordfence
01a52285-2d0c-4b29-8dab-18a3e3640e5c
< 6.0.14
MEDIUM 4.9 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traver… wordfence
013f6ad0-6ef1-44a1-9925-c60c61314f70 MEDIUM 4.9 The WPMU Prefill Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.02 due to … wordfence
0101113b-70c2-4db4-b6b1-b2412f6e1214
< 6.2.2
MEDIUM 4.9 The Fluent Forms plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 6.2.1. This i… wordfence
fe708e03-334f-4c72-ace9-b5d065ee8c9d MEDIUM 4.8 Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress p… wordfence
fd67e334-88fd-49c7-a20c-9c2f95e9950c
< 3.5.6
MEDIUM 4.8 The WP Customer Reviews WordPress plugin before 3.5.6 did not sanitise some of its settings, allowing high privilege use… wordfence
fb6719d8-18d2-4fa3-9b52-ba11cf567bb2
< 2.5.1.9
MEDIUM 4.8 These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4… wordfence
fa63a325-9e0e-4ce2-996d-37a0637b0471 MEDIUM 4.8 Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating … wordfence
f9ae88f8-88c1-4bb0-af9f-330f9760de1f
< 5.22.2
MEDIUM 4.8 The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting th… wordfence
f85f2fbb-5bd5-4508-abb0-36543b8ddaa2
< 7.0
MEDIUM 4.8 The Custom Dashboard & Login Page WordPress plugin before 7.0 does not sanitise some of its settings, allowing high priv… wordfence
f4198c51-4a26-4a50-b2c5-0467f8008b5b
< 2.2
MEDIUM 4.8 The WP Social Buttons WordPress plugin through 2.1 does not sanitise and escape its settings, allowing high privilege us… wordfence
f371feb6-93ae-4759-ab44-d58106093290
< 1.0.14
MEDIUM 4.8 The Sign-up Sheets WordPress plugin before 1.0.14 did not sanitise or escape some of its fields when creating a new shee… wordfence
f3543ce7-328e-4db8-8993-8cd78af997de
< 1.7.0
MEDIUM 4.8 The SEUR Oficial WordPress plugin before 1.7.0 does not sanitize and escape some of its settings allowing high privilege… wordfence
← Prev 1256 1257 1258 1259 1260 1261 1262 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top