πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 343 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f3fddcb8-b56f-4d5d-8843-fb78064e9cbb HIGH 7.2 The Oxygen theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.8.… wordfence
f3ebbf7f-61f2-403f-8131-8cedeb13c2d4
< 2.1.4
HIGH 7.2 The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to SQL Injection via several parameters in all v… wordfence
f3c4ba08-a9fa-439a-a887-b8c113f78e20 HIGH 7.2 The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and… wordfence
f3ba06f9-de51-49ea-87c1-4583e939314b
< 1.13.0
HIGH 7.2 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
f3ae3bca-d363-4c4b-809f-0625385bc9a6
< 7.3.15
HIGH 7.2 The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin … wordfence
f367a3d2-8ee6-4897-b7bf-a44f57142347
< 1.1.9
HIGH 7.2 The Portfolio Gallery – Photo Gallery for WordPress is vulnerable to SQL Injection via the 'search_events_by_title' pa… wordfence
f3584b5b-ff93-4a47-b6e6-f95335ee88b6
< 2.4.9
HIGH 7.2 The Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the administration interface in versi… wordfence
f3555702-4427-4569-8fd6-f84113593e9d
< 1.2.9.1
HIGH 7.2 The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' para… wordfence
f324b272-1e2f-4951-a8ae-5210a8d4dcbd
< 2.9.3
HIGH 7.2 The HandL UTM Grabber / Tracker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
f315fff8-d616-4a5c-91bc-d8b0ec0f028f
< 5.2.3
HIGH 7.2 The Wordfence plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer Header in versions up to… wordfence
f2d97646-27a8-4302-be70-7b4fb1a12300
< 2.2.4
HIGH 7.2 The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss… wordfence
f2a6f8ec-6a3e-453d-9ef4-794b5791ac2b
< 1.5.3
HIGH 7.2 The WP User Merger plugin for WordPress is vulnerable to generic SQL Injection via 'user_id' parameter (in function 'wpu… wordfence
f25cd403-77a4-437b-b9ba-93137bf9c936
< 2.7.1
HIGH 7.2 The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress… wordfence
f1b14fa8-04a0-43e3-a908-db98cb2c5e16
< 2.5
HIGH 7.2 The CF7 Auto Responder Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
f1abab37-7397-407c-bcbb-4597b289ce80
< 1.7.1
HIGH 7.2 The Kapee theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1 due to insufficient i… wordfence
f18daec4-0b1f-48d8-b6f2-788c8caad17f HIGH 7.2 The Bulk Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
f10a11d8-1ef8-427b-b256-ffe8769d61bb
< 3.2.1
HIGH 7.2 The One Click Demo Import plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… wordfence
f105f6bf-3224-4f5c-8334-1a53ff9af9c0
< 3.6.4
HIGH 7.2 The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versi… wordfence
f0e6b405-0843-4469-ae60-7023dea0786f
< 5.3.9
HIGH 7.2 The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to S… wordfence
f0d05295-182c-4c4a-bb0d-15831fe7e691
< 6.5.7
HIGH 7.2 The CTX Feed – WooCommerce Product Feed Manager Plugin plugin for WordPress is vulnerable to unauthorized modification… wordfence
f093dfc8-8a2f-4614-b7c1-4fbf1afa9589
< 5.4
HIGH 7.2 The Demon image annotation plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up t… wordfence
f08ad322-6458-4608-b53a-6aaed38a9ef2
< 6.8
HIGH 7.2 The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET pa… wordfence
f082a21e-0239-45fc-a7f2-9600f215783a
< 2.8.9
HIGH 7.2 The Ezoic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in versions up to, and includin… wordfence
f05a55ba-8068-4f6e-a7b1-f3d5d17e54ee
< 2.12.4
HIGH 7.2 The Registrations for the Events Calendar – Event Registration Plugin plugin for WordPress is vulnerable to Stored Cro… wordfence
f041dbd3-c053-4720-955d-327863275286
< 1.1.45
HIGH 7.2 The Hydra Booking β€” Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
← Prev 340 341 342 343 344 345 346 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top