🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1587 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2379a029-cc0d-4fa2-9aeb-47a4abd6b51a
< 2.25.2
MEDIUM 4.1 The GiveWP plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 2.25.1 vi… wordfence
0f5a48ec-da62-4a9d-a8a5-30da7b6d23f6
< 6.4.3
MEDIUM 4.1 The Advanced Custom Fields (ACF®) plugin for WordPress is vulnerable to HTML Injection in all versions up to, and inclu… wordfence
f24b3afe-5de3-464c-92af-a654e97f0945
< 1.1.0
MEDIUM 4.0 The Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab plugin for WordPress is vulnerable to Stored Cross-… wordfence
ee449645-44d1-4ce7-b74b-dcf446b5a9ab
< 1.11.7
MEDIUM 4.0 The Z-Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u… wordfence
d4cdf774-c93b-4b94-85ba-aa56bf401873
< 21.8
MEDIUM 4.0 The Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via service titles in versions up to, and i… wordfence
ba08dbad-15f9-43cf-b0d7-a2a4604cb4af
< 1.9.1
MEDIUM 4.0 The WP Bannerize Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via banner alt data in all versio… wordfence
6082f25f-b060-431b-a18c-65899851bf3b
< 4.4
MEDIUM 4.0 The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all … wordfence
5b25908a-d394-4ce8-b853-4bdf643b9b5b
< 1.7.1
MEDIUM 4.0 The YITH Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio… wordfence
51de575f-d458-4a7d-bc57-4a11e5124377
< 1.1.13
MEDIUM 4.0 The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Requ… wordfence
112ed4f2-fe91-4d83-a3f7-eaf889870af4 MEDIUM 4.0 WordPress Core, in all known versions is vulnerable to blind Server-Side Request Forgery in its pingback feature. This i… wordfence
eb0892fd-b5dd-4dc8-bc45-41c05f1c03cf LOW 3.8 The Piotnet Forms plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.30. Thi… wordfence
e615833a-0408-4e39-b63d-075bff39a9bf LOW 3.8 The DupeOff plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6 due … wordfence
e3dc1dd6-7f35-4771-a795-f0e37088dfda
< 1.1.3
LOW 3.8 The Image Gallery - Grid Gallery WordPress plugin through 1.1.1 does not sanitize and escape some of its Image fields, w… wordfence
d935f4c5-5d69-42d9-be22-7a44d9aa885a
< 2.17.5
LOW 3.8 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
ca7f72bf-5271-42a2-99cb-3021f10ea5f3
< 2.3.3
LOW 3.8 Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress. wordfence
c59a4802-ce4c-4f19-be7a-848862e1d3cf
< 3.2.1
LOW 3.8 The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable … wordfence
ab233ceb-270c-4694-9cf9-2de8ddfcbbfd
< 7.7.2
LOW 3.8 The Directorist plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 7.7.1. This allows… wordfence
9f47c6c4-2d74-4f37-8232-d54d5f0c24cf
< 1.0.3
LOW 3.8 The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
8c3e61e9-3610-41b5-9820-28012dc657fd
< 3.2.4
LOW 3.8 The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on th… wordfence
855f5cca-b0cc-4a1b-be33-d11776ad7c08
< 3.7.4
LOW 3.8 Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabl… wordfence
803c32e9-665c-40a0-b52d-f2c0b8fbe931
< 2.2.3
LOW 3.8 The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sending mail (thus adding the paylo… wordfence
72c16a66-05fa-4d47-937d-415f18cec0ab
< 1.1.82
LOW 3.8 The WP Time Slots Booking Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in v… wordfence
6b6fa5c6-e9a9-45c6-a02b-3630d8ef130e
< 5.4.5
LOW 3.8 The MonsterInsights - Google Analytics Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
67817d5a-2d7a-4b96-9c04-cd1ad9c90b29
< 1.2.2
LOW 3.8 The Ni Purchase Order(PO) For WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
63f38644-a021-407a-9882-2c8435849c08
< 1.5.0
LOW 3.8 The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version… wordfence
← Prev 1584 1585 1586 1587 1588 1589 1590 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top