πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 340 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fec015e1-7f64-4917-a242-90bd1135f680
< 5.1.9
HIGH 7.2 The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a… wordfence
feab189a-bd89-461d-b553-f137b8032e94
< 1.2.4
HIGH 7.2 The Easy Social Icons plugin for WordPress is vulnerable to generic SQL Injection via the β€˜id’ parameter in versions… wordfence
fe98bd8c-6db3-4094-8ff2-ab21c8778698
< 3.1.0
HIGH 7.2 The Catch Themes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includi… wordfence
fe4774ee-16f2-478f-92e3-8a7da7b30336
< 4.1.1
HIGH 7.2 The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username i… wordfence
fdfa2336-dda2-4945-9278-1a85f8b5f88b
< 5.2.4
HIGH 7.2 The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['REQUEST_URI']' parame… wordfence
fdf18ae2-f0d4-44d4-9dd1-6ac36d859d68
< 1.4.4
HIGH 7.2 The Action Network plugin for WordPress is vulnerable to SQL Injection via the 'bulk-action' parameter in version 1.4.3 … wordfence
fd9a81eb-2211-42e9-a456-fb60f3ca2c0f
< 1.56.2
HIGH 7.2 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
fd903ec3-893e-4dd8-ad90-2e25a926ac4f
< 2.4
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in the WP-FeedStats before 2.4 plugin for WordPress allow remote att… wordfence
fd8fb3e9-34eb-4b37-9a7e-00309a1ca81d
< 1.1.9
HIGH 7.2 The Booking Ultra Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
fd2b816a-fbb1-4c6f-8f0a-4ef2e77f845e HIGH 7.2 The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the Update parameter before using it in a SQ… wordfence
fd12a952-2e99-41f7-b74c-55c2b7d8deed
< 2.3.2
HIGH 7.2 The Flexible Checkout Fields for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Plugin Set… wordfence
fcd02dfa-688e-4375-92cb-8d0e7cbaaa6e
< 18.5.8
HIGH 7.2 The Shield Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the getColumnContent_Page func… wordfence
fcb76d10-fc60-4b19-9b47-1b98f8400a96
< 2.5.9
HIGH 7.2 The bbPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bbp_mention_filter function in ver… wordfence
fcb4bd86-c187-4c73-be91-d0edbc5d9215
< 1.4.0
HIGH 7.2 The SureRank plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.2 d… wordfence
fc8b133f-d952-4776-80a2-c856bcb1ee89
< 2.2.13
HIGH 7.2 The WP Tabs plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.12 via dese… wordfence
fc6af287-4228-4f05-b439-fac6c057b0a5
< 1.23.1
HIGH 7.2 The Timber plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.23.0 via d… wordfence
fbc3643c-6116-42d3-b309-2e6aeedfbe4f
< 1.4.22
HIGH 7.2 The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
fbbe006c-1afc-4c8b-a9f3-ffb21cdabb54
< 8.0.10
HIGH 7.2 The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable… wordfence
fb7fc87c-4680-477e-94f5-9c502edce61d
< 4.16.4.5
HIGH 7.2 The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a speci… wordfence
fae9f282-eb67-4ad9-be2d-677238527934
< 3.1.2
HIGH 7.2 The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command lin… wordfence
fab8c244-9767-45ed-a6c8-85f66fa41122
< 3.0.6.8
HIGH 7.2 The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
faac4bcd-678a-4618-95ba-3e5567f0e971
< 3.3.6
HIGH 7.2 The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title attributes … wordfence
fa91912d-5794-4c96-8a13-bd54ce0f1deb
< 5.2.7
HIGH 7.2 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in a… wordfence
fa75366a-651c-43d0-a32b-cdabf5b07b66
< 2.7.8
HIGH 7.2 The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.7. T… wordfence
fa5c97bc-b06f-4ee8-bbc5-72c348d2c92a
< 1.4.1
HIGH 7.2 The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parame… wordfence
← Prev 337 338 339 340 341 342 343 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top