🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 331 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
010f1cd4-da4c-4693-8d1a-a93e779e36f3
< 6.5.1
HIGH 7.5 The PDF for Gravity Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection in… wordfence
00e070b7-bdf6-4a80-a3ee-628243f1cc25
< 4.1.0
HIGH 7.5 The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all v… wordfence
00d8e7db-b1a4-4785-ba57-1dce0fd11dec
< 1.4.6
HIGH 7.5 The CMSMasters Content Composer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
007df869-dacb-4b0a-9c98-50586934cdab
< 3.9.7
HIGH 7.5 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coup… wordfence
0066b63b-42ff-4edb-b17d-2210babc3502
< 3.2.3
HIGH 7.5 The Bpost Shipping Platform plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.2 … wordfence
00612475-7efd-46f2-8196-666900ae7df3
< 1.3.0
HIGH 7.5 The WpBookingly plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.9. This… wordfence
00599865-9091-46e1-b2a9-78cbd10f6f22
< 0.9.2.5
HIGH 7.5 W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of d… wordfence
ff9cfa56-e178-4de7-9e6b-e0a520153eb2
< 1.37
HIGH 7.4 The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versio… wordfence
f0edfebc-bf6b-4346-9cd7-ce00007e3620
< 2.4.44
HIGH 7.4 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of … wordfence
ed037e94-68b4-4efc-9d1a-fffc4aff1c45
< 6.4.4
HIGH 7.4 The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.… wordfence
ecb86ea6-2aca-4f7c-be81-a572b53b7953
< 8.2.7
HIGH 7.4 The WP VR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up t… wordfence
e14f0fc6-fca4-4dd7-8f7b-ed5ed535c9af HIGH 7.4 The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp_ajax… wordfence
de2c2c90-52b6-4315-a8d1-6519a90f81e7
< 1.2.2
HIGH 7.4 The YourChannel plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on 'save', … wordfence
dc8d63ee-4929-4940-bc6a-931524e20272
< 2.1
HIGH 7.4 The SKT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Age Gate… wordfence
d6fc087b-c28d-4c6a-a59f-085773d542dd
< 1.2.7
HIGH 7.4 The Smoke Signal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text’ parameter in versi… wordfence
d33a77c6-9977-4d92-92c4-4273ee73452e
< 1.1.2
HIGH 7.4 An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lack… wordfence
cede59f9-611f-4da4-8140-181bd0a469d5
< 5.3.1
HIGH 7.4 The Contact Form by FormGet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘value’ parame… wordfence
c8fe569a-62dd-4be5-915d-de589663658f HIGH 7.4 The Craw Data plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.0.0 … wordfence
c12538bc-6e7d-4d47-8e5b-65574ed26ec4
< 1.8.2
HIGH 7.4 The Easy Coming Soon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'background_color' parame… wordfence
c0383bc6-919d-4858-a5b7-abe8a4a6c684
< 1.2.4
HIGH 7.4 The editor of the WP Page Builder WordPress plugin before 1.2.4 allows lower-privileged users to insert unfiltered HTML,… wordfence
aa309da6-6552-43e4-aeea-f822493dd029
< 1.4
HIGH 7.4 The Export Users Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.2. This allow… wordfence
a73f3d93-198c-484c-bed5-59e477f3833e
< 3.12.7
HIGH 7.4 The Leaflet Maps Marker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in… wordfence
a3e7460b-1ed4-4ff7-89c7-0bd2658a800d
< 1.11.3
HIGH 7.4 The Giveaways and Contests by RafflePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
9b320755-1255-4331-8176-ee67d8d4873e
< 2.4.4
HIGH 7.4 wordfence
9821e51c-1042-47b8-b104-32f5651c31c9
< 1.8.9
HIGH 7.4 The TextMe SMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up t… wordfence
← Prev 328 329 330 331 332 333 334 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top