πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 346 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e8865a30-ecff-439b-ab96-4dba018046ae
< 1.4.4
HIGH 7.2 The Flipbook PDF Viewer & Embedder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up … wordfence
e826dcb4-7a92-43d9-a8ca-403b20521c5e HIGH 7.2 The Kids Life | Children School WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
e8214cdd-3a7d-40ce-9645-7dbd6e8f037f
< 4.5
HIGH 7.2 The GEO My WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
e7ba65ac-e568-4c13-961d-6453f281d9fc
< 1.3
HIGH 7.2 The SMTP for Sendinblue – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
e776101f-f8ff-4408-b0fe-9dd5849355c7
< 9.2.03.001
HIGH 7.2 The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
e7613875-b44e-4b91-9a5b-41ea0854cd61
< 2.0
HIGH 7.2 The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable to ar… wordfence
e75a96ab-499b-4f1d-a60b-a5aa9d804363
< 1.0.8
HIGH 7.2 The Plugin Logic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.7 due to insu… wordfence
e669ae60-c015-4b84-86a8-56aab9fe23bd
< 2.6.5
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) f… wordfence
e6361ada-f2ba-404e-b9d3-b169da44aa90
< 3.9.7
HIGH 7.2 The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions u… wordfence
e634dafc-8eb0-406f-93b1-ee1d2b44171d
< 3.2.0
HIGH 7.2 The wpForo + wpForo Advanced Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via media upl… wordfence
e62a77a4-d2c4-4043-99b2-0918ea18eeb5 HIGH 7.2 The Pray For Me plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
e61a5989-ea75-4c11-a937-66488ecdb10d
< 1.0.9
HIGH 7.2 The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before… wordfence
e5df0eea-6b09-4212-9a74-ae145763e972
< 1.14.0
HIGH 7.2 The Transbank Webpay plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.14.0 due to i… wordfence
e5aab86a-0fcd-4192-a5db-5da1b68e366a
< 5.5.80
HIGH 7.2 The WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards plugin for WordPress is vulnerable to St… wordfence
e57f4853-cade-4bb5-8f12-4a88a200921f
< 7.29
HIGH 7.2 The WP Custom Admin Interface plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… wordfence
e571ded0-ea7a-40ec-b90b-c5009b463d87
< 7.5.4
HIGH 7.2 The Directorist for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.5.3 via the file… wordfence
e56f8ce0-b6a2-4cef-9091-818528699892
< 1.7.1
HIGH 7.2 The Contact Form, Survey, Quiz & Popup Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
e560fb5f-0548-4b3e-9f8d-9e80af364c04
< 2.0.70
HIGH 7.2 The Contact Bank – Contact Form Builder for WordPress for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
e558100a-5866-4e7f-bae7-47a1f492ab27
< 1.14.12
HIGH 7.2 The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.14.… wordfence
e4c7d179-9b65-48da-b92e-11fb0629653a HIGH 7.2 The AIO Contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
e4b6a9cd-4d29-4bd8-afa3-b5d455ad8340
< 2.5.4
HIGH 7.2 The WP Coder – add custom html, css and js code plugin for WordPress is vulnerable to time-based SQL Injection via the… wordfence
e4b2178f-e4da-4bfb-9c27-8c1884499769
< 2.5.5
HIGH 7.2 The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and includi… wordfence
e4b10172-7e54-4ff8-9fbb-41d160ce49e4
< 4.3.6
HIGH 7.2 The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `list_type` parameter… wordfence
e44e4bdd-d84e-4315-9232-48a3b240242d
< 14.5.1
HIGH 7.2 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all … wordfence
e44dd0e8-e6e7-4a2d-b9ca-abd1de273092 HIGH 7.2 The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
← Prev 343 344 345 346 347 348 349 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top