πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 341 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fa47a794-e5ce-491d-a10b-c7c5718aa853
< 2.2.5
HIGH 7.2 The FluentSMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to,… wordfence
fa37025a-7f20-4cfe-a7d0-38168f49b6d9
< 2.4.2
HIGH 7.2 The LWS Cleaner plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i… wordfence
fa1e6527-d874-4003-b36b-5769c2950864 HIGH 7.2 The Return and Warranty Management System for WooCommerce plugin for WordPress is vulnerable to stored Cross-Site Script… wordfence
fa15c0a4-c99d-40c9-a654-f3a910460502 HIGH 7.2 The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value… wordfence
f9f17c2b-ca63-4f71-af0f-7bce09ebeb9f
< 1.2
HIGH 7.2 The Answer My Question plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions bef… wordfence
f9e83561-aa71-4984-8a26-207e208d70e8
< 2.0.15
HIGH 7.2 The Advanced Ads plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.14 vi… wordfence
f9e45bc2-6db6-49cd-8a4a-58489a8ddac2
< 1.0.8
HIGH 7.2 The User Feedback plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user responses for surveys in ve… wordfence
f9d9e485-171f-4e36-943d-397d540e31f4
< 1.68.11
HIGH 7.2 The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the d… wordfence
f99a918d-53c1-46bd-8e55-9ba77a92efe8
< 2.1.6
HIGH 7.2 The Solid Mail – SMTP email and logging made by SolidWP plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
f9927487-99fb-46d9-a208-f19e0a371267
< 1.0.5
HIGH 7.2 The Easy PHP Settings plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0… wordfence
f96d99dc-df3a-4b01-b276-08a85860720e
< 8.2.8
HIGH 7.2 The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to… wordfence
f92784a7-f2b3-47f8-b03f-4e234b57e40a
< 2.3
HIGH 7.2 The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2 vi… wordfence
f9135799-00db-447d-b795-faafeafbce67
< 2.10.1
HIGH 7.2 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an… wordfence
f8b34144-5516-46df-b093-95f4bf76b896
< 5.98.0
HIGH 7.2 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'media[].… wordfence
f8aa8dd6-abff-4c37-98d5-39a924b15651
< 1.6.51
HIGH 7.2 The Charitable – Donation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
f8a87f7b-471b-44c0-a0bd-06a9ba24a566
< 11.0
HIGH 7.2 The WP Review Slider WordPress plugin before 11.0 does not sanitise and escape the pid parameter when copying a Twitter … wordfence
f8786695-adab-4d7c-8cc1-53f37c06de12
< 3.5.5
HIGH 7.2 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
f866ef19-2662-49c1-a90a-920403c8799d
< 3.8.10
HIGH 7.2 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.9.… wordfence
f85a0394-cd70-419d-97bd-c75d6f721714
< 3.2.3
HIGH 7.2 The MyBookTable Bookstore plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and in… wordfence
f8381866-d991-4638-ab4d-3b8697acf414 HIGH 7.2 The Content Syndication Toolkit plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,… wordfence
f8234ea2-ff80-425f-b83d-29c422b40c6a HIGH 7.2 The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in all versions up to,… wordfence
f7ad5d55-3964-4bb9-9f7b-496e99db80f4 HIGH 7.2 The Official Integration for Billingo plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … wordfence
f781db57-1015-439b-80b5-0e08df0bd05c
< 5.6.2
HIGH 7.2 The Grand Tour theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.6.2 due to insuffici… wordfence
f72b7973-2599-4833-abe1-783e2a285165
< 5.111.0
HIGH 7.2 The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
f6d39654-2c22-48c7-b545-7b02e5c4b43b
< 3.0.4
HIGH 7.2 The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
← Prev 338 339 340 341 342 343 344 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top