πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 345 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ec2276d6-431f-428c-b1d1-3acbd60e0505 HIGH 7.2 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… wordfence
ebdac9a2-2114-4b3c-ab2f-bd461f2c648c
< 3.1.3
HIGH 7.2 The Rencontre – Dating Site plugin for WordPress is vulnerable to SQL Injection via a few parameters found in the inc/… wordfence
eb71befb-8b79-46b0-9d0b-0159542147c1
< 1.6.36
HIGH 7.2 The RapidLoad Power-Up for Autoptimize plugin for WordPress is vulnerable to SQL Injection via the rule_id parameter in … wordfence
eb367998-5c5c-4c4d-81cb-519023f028e6
< 0.9.5
HIGH 7.2 The W3 Total Cache plugin for WordPress is vulnerable to Authenticated Arbitrary Code Execution via settings import in v… wordfence
eadbfb77-fb9a-4363-acc8-8dd9b87820eb
< 3.7.40
HIGH 7.2 WordPress Core in versions up to 6.0.3 are vulnerable to Cross-Site Scripting via wp-mail.php. This is due to no validat… wordfence
ead4d41c-8cd7-4593-ad18-c32cb9053229
< 1.3.9.8
HIGH 7.2 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
eab98c41-f0f2-4953-b9b3-c08e1e92c03a
< .53.3
HIGH 7.2 The BulletProof Security plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, .5… wordfence
ea838c4c-d362-4653-8dc1-5c4dbec19eca
< 3.5.5
HIGH 7.2 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Directory Traversa… wordfence
ea7f654b-88d1-4ed8-bab0-701e2e66e060
< 1.20.19
HIGH 7.2 The E2Pdf plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.20.18 via d… wordfence
ea0ea17f-fe22-4749-851b-f13fc79de7d9
< 3.6.0
HIGH 7.2 The Magic the Gathering Card Tooltips plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions … wordfence
ea0d1acc-d2c9-4851-9753-d87587236d7e
< 3.8.1
HIGH 7.2 SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at… wordfence
e9fba508-9a18-4c02-8d3a-0bcf990c457d
< 1.0.9
HIGH 7.2 The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS. wordfence
e9c33bab-a27b-43b1-aa48-3f8c09a38528 HIGH 7.2 The Sticky Anything plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
e9ad533d-4ec0-42a0-99fc-75fc59498c94 HIGH 7.2 The Autochat Automatic Conversation plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
e99a7d46-a3be-4408-9000-fb43fe397dd9
< 3.3.8
HIGH 7.2 The InJob | Multi features for recruitment WordPress Theme for WordPress is vulnerable to both Reflected and Stored Cros… wordfence
e9960282-4730-4ee8-b338-adcc57f01cc6
< 5.2.6
HIGH 7.2 The Bus Ticket Booking with Seat Reservation – WpBusTicketly | WordPress plugin plugin for WordPress is vulnerable to … wordfence
e991fbdf-8e26-4d2e-8e3b-c8990914dcad
< 5.4.0
HIGH 7.2 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fh' (fingerprint) para… wordfence
e94e39d3-61da-4adb-a89a-97cda4c9203d
< 3.5.1
HIGH 7.2 The SyntaxHighlighter Evolved for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
e9388404-40b9-4d2c-b009-0417ff48e74c HIGH 7.2 The Perfect Survey WordPress plugin through 1.5.2 does not validate and escape the X-Forwarded-For header value before o… wordfence
e9274957-7584-4df6-bb2a-d745510f5033
< 2.15.20
HIGH 7.2 The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to ar… wordfence
e91922d7-5207-45e6-8e0f-071da23771e9
< 2.2.3
HIGH 7.2 The Property Hive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
e90ddedd-22ee-47ad-ac4c-337d26dbd5e2 HIGH 7.2 The WP Simple Pay Lite Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4… wordfence
e8fcc105-0b37-47a7-a726-fee33b86790e
< 2.0.10
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.0.9 and earlier allow remote attackers to inject arbi… wordfence
e8c939e9-2b72-460b-9e76-560762752c28
< 2.3.11
HIGH 7.2 The ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema plugin for WordPress is vulnerable t… wordfence
e8b47cc6-437b-45c9-b263-ee43c7ec7d14
< 3.82
HIGH 7.2 The Contact Form by BestWebSoft – Advanced Contact Us Form Builder for WordPress plugin for WordPress is vulnerable to… wordfence
← Prev 342 343 344 345 346 347 348 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top