🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 217 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ac45d8fe-4b79-4b2c-998e-e51da7a37e40
< 2.0.25
HIGH 8.3 The Custom Community theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘settings[custom_css]’… wordfence
aa735320-f7fe-4e51-9f9a-f4c8f3ddc2e7
< 3.3.14
HIGH 8.3 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Cros… wordfence
9e6a1af3-d53c-4e23-95d2-3b799bc10827
< 4.3.13
HIGH 8.3 The Contact Form Plugin by FluentForm plugin for WordPress is vulnerable to CSV Injection in versions up to, and includi… wordfence
9132a605-7bed-4741-83f9-dfe8cbaf36cd
< 2.9.5
HIGH 8.3 The ListingPro Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2… wordfence
904e407c-5ec7-433f-9161-eb4d6d263a97
< 2.0.1
HIGH 8.3 The Canto plugin 2.1.1 for WordPress allows includes/lib/download.php?subdomain= SSRF. wordfence
900fcaab-2424-4ae8-af18-95659db0dbe3
< 2.05.03
HIGH 8.3 The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters su… wordfence
8a3da2af-2273-44ff-addd-1ac8a75e1c3d HIGH 8.3 The All in One Social Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl… wordfence
83bd221e-7d01-4cba-8577-ce0a69e4a75c HIGH 8.3 The WPsc MijnPress plugin for WordPress is vulnerable to Cross-Site Scripting via the 'rwflush' parameter in versions up… wordfence
80e85c7e-41e5-4b21-aa99-aa2097dfc4a9
< 1.4
HIGH 8.3 Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an … wordfence
7b035d17-303b-4a8b-a15e-615df6b605d1
< 3.3.0
HIGH 8.3 The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… wordfence
78fedd41-f0ab-4148-a798-88de62f27008
< 2.1.79
HIGH 8.3 The NextGen Gallery plugin for WordPress is vulnerable to SQL Injection via the ‘$container_ids’ string in versions … wordfence
6c3032ae-eb86-47d0-b160-320a67a380e1
< 1.2.9
HIGH 8.3 The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Re… wordfence
69ec31f3-8ec8-40ad-ba7f-77f9132ad51f
< 3.0.8
HIGH 8.3 The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Server-S… wordfence
6368c397-0570-4304-a764-869bacc526c7
< 2.25.2
HIGH 8.3 The GiveWP plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.25.1 via the 'print_c… wordfence
6299876c-9db4-4f8d-897d-9a013a67238c
< 1.8.1
HIGH 8.3 The Register IPs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ip_address’ parameter th… wordfence
5f7014fc-a502-4f72-899f-c21d3ca5e5b3
< 3.6.4
HIGH 8.3 The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter i… wordfence
5aacabb5-94af-485a-af24-e84db3e3726f
< 1.0.1
HIGH 8.3 The Mapplic and Mapplic Lite plugins for WordPress are vulnerable to Server-Side Request Forgery in versions up to, and … wordfence
57caddaa-c548-4f07-ab34-327df62951b5
< 1.7.5.9
HIGH 8.3 The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on… wordfence
5781420d-b1e0-435f-8bf2-193cc7b095ed
< 2.0.1
HIGH 8.3 The Canto plugin 1.9.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make… wordfence
5574f8ab-74b7-4f6c-b8db-901cb6e45cfb
< 1.2.2
HIGH 8.3 A stored Cross-Site Scripting (XSS) vulnerability in the TC Custom JavaScript plugin before 1.2.2 for WordPress allows u… wordfence
5494cac6-1b52-43a3-995d-fc2a150edfdb
< 4.15
HIGH 8.3 The Reviews and Rating – Google My Business plugin for WordPress is vulnerable to authorization bypass due to missing … wordfence
5097da41-b5e9-4e07-a135-83a7d889fe9b
< 2.5.13
HIGH 8.3 The bbPress plugin for WordPress is vulnerable to blind SQL Injection via the ‘anonymous_data’ parameter in versions… wordfence
506e4f47-e292-4d19-a7bb-b87d752f4007
< 2.8.4
HIGH 8.3 The Activity Log plugins for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.8.3. This allo… wordfence
5017c81f-91ee-421b-96db-c96eae56d032
< 2.0.22
HIGH 8.3 The Advanced Ads – Ad Manager & AdSense plugin for WordPress is vulnerable to Remote Code Execution in all versions u… wordfence
4fd6fa4f-8f4d-4d2f-ac67-98124cfa9592
< 3.24.0
HIGH 8.3 The Thrive Theme Builder theme for WordPress is vulnerable to unauthorized use of functionality due to missing capabilit… wordfence
← Prev 214 215 216 217 218 219 220 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top