πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 342 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f6c302d8-ab4f-474c-98ad-356c61c01adc
< 2.4.4
HIGH 7.2 The Homey Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.3… wordfence
f67b5cd8-bae8-48ca-87d5-7445724791f6
< 20240223
HIGH 7.2 The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting v… wordfence
f64336f7-ab2a-4e22-a76f-d077c51f9c57
< 1.52.2
HIGH 7.2 The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1… wordfence
f6424fc9-f118-4654-89a7-1f7e6efa2c02
< 1.9
HIGH 7.2 The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
f5e6cb50-8262-406b-b01e-37d62a4bd394
< 4.11.1
HIGH 7.2 The Ajax Search Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
f58b3971-e1e4-4337-82a3-99c9079c6696
< 7.2.5
HIGH 7.2 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ve… wordfence
f5863132-90a7-414f-abcb-e8b6a9d229c5
< 2.0.2
HIGH 7.2 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
f56a632d-4c5f-4d89-9cd9-8fc3697ff3ca HIGH 7.2 The Membership by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'sidx' and 'sea… wordfence
f56494b7-0552-42d3-b3c6-fe26096f6cf5
< 1.26.3
HIGH 7.2 The Import and export users and customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up … wordfence
f5524582-5aac-48b4-ad67-7c4829d63ed0
< 2.4.3
HIGH 7.2 The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injecti… wordfence
f54527ce-8137-4ba9-b4e6-52cea6cfe2da HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
f509f1c6-6094-434d-8e70-ad8419250aa2
< 7.6.57
HIGH 7.2 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Web… wordfence
f4e3b796-af9a-4403-8d9a-1b56d7253b45 HIGH 7.2 The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress … wordfence
f4e25aa6-8028-4c85-98c4-6f47a1502427
< 1.4.113
HIGH 7.2 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
f4daf910-1768-4cfd-af92-66a2ee7f52a5 HIGH 7.2 The Ultimate Auction Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
f4d421df-310b-4a83-b521-c0d00045df52
< 2.1.5
HIGH 7.2 The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the… wordfence
f4c3f9c5-5086-416b-a601-2890f52547c0
< 1.70
HIGH 7.2 The Advanced Woo Search plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.6… wordfence
f49e48cb-7d0b-4bcf-9090-869472b8442a
< 3.5.20
HIGH 7.2 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Database m… wordfence
f45b4c43-c6c4-41da-bd59-9a355800815a
< 2.1.4
HIGH 7.2 The Import XML and RSS Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
f444568c-fe4c-4fa6-9b83-2d069f851360
< 6.0.0
HIGH 7.2 The Advanced Page Visit Counter WordPress plugin through 5.0.8 does not sanitise and escape some input before outputting… wordfence
f436ab65-a59c-4b2a-abc8-a7fc038678dd
< 1.6.22
HIGH 7.2 The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versi… wordfence
f432f32c-9ebb-4444-baf0-d523b1ceba02
< 15.0.7
HIGH 7.2 The Simple Link Directory Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and i… wordfence
f4213452-33f7-46d4-ab4a-544a9bef475a
< 1.4.30
HIGH 7.2 The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
f419eceb-a3e7-4cf7-a37e-dcc57a26d7f5
< 2.35.1
HIGH 7.2 The AffiliateWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.35… wordfence
f40dde67-b6af-4a57-a067-09adcbb981ac HIGH 7.2 The REAL WordPress Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and … wordfence
← Prev 339 340 341 342 343 344 345 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top