ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 347 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e4414b5d-9ce5-4378-ab41-c82ae3bebd6e
< 3.12.5
HIGH 7.2 The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) plugin for WordPress is vulnerable to SQL Injection via … wordfence
e4188b26-80f8-41b8-be19-1ddcbd7e39f5
< 4.0.52
HIGH 7.2 The Eventin – Event Manager, Events Calendar, Event Tickets and Registrations plugin for WordPress is vulnerable to un… wordfence
e411c319-3eb0-4a41-9ba7-9a6a4f203809
< 3.6.0
HIGH 7.2 The Real Estate 7 WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
e4077fda-3f39-4e17-b7b8-3f1b6bf0a9e1
< 4.5.5
HIGH 7.2 The ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via numerous parameters in versions u… wordfence
e3ce37e7-1dca-4f74-86ce-65bf29ef091e
< 3.1.6
HIGH 7.2 The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'loan-amount' and 'l… wordfence
e3a8f554-7cb6-40b7-b83c-819e7785058a HIGH 7.2 The HyperComments plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'xml' GET parameter in versions … wordfence
e39810d7-260f-4729-9b11-69dba0e16684 HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
e363c09a-4381-4b3a-951c-9a0ff5669016
< 6.0.8
HIGH 7.2 WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versio… wordfence
e349f07d-a520-4700-a6e0-25e68c1deeae
< 1.5.4
HIGH 7.2 The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authentic… wordfence
e340863f-c029-43c9-9e48-08cc5b93e400 HIGH 7.2 The Dinatur plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.18 due… wordfence
e32a4038-0f67-48b3-80c9-94d279752c31
< 1.6.8
HIGH 7.2 The Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to,… wordfence
e2d29afd-06e8-461a-918f-38228441a51a
< 6.6.16
HIGH 7.2 The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including,… wordfence
e2b4586a-f87d-4a51-8f4e-932d7254518e
< 1.8.9
HIGH 7.2 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema… wordfence
e2b16b9c-48c7-4370-839b-696797ff2101
< 4.24.9
HIGH 7.2 The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all … wordfence
e2960224-4446-4fc6-8d18-6f9911b4cbad
< 6.8.1
HIGH 7.2 The Rich Shortcodes for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the content… wordfence
e26b7e73-2d04-493a-a7d9-2276bc0e1ba8
< 1.3.6
HIGH 7.2 The Better Find and Replace WordPress plugin before 1.3.6 does not properly sanitise, validate and escape various parame… wordfence
e25f524e-360d-4c80-a0ab-90ee94825b1b
< 2.71
HIGH 7.2 The WP-Polls plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pollq_question and polla_answe… wordfence
e2521876-cd1c-4c4a-8486-b1c4da78ffdb
< 3.3.17
HIGH 7.2 The Instantio – WooCommerce Quick Checkout | Direct Checkout, Floating Cart, Side Cart & Popup Cart plugin for WordPre… wordfence
e2256157-e65f-46fb-b226-fa778ad3e69c
< 1.5.9
HIGH 7.2 The Fediverse Embeds plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
e1e973e3-f2a2-465c-aec7-5a7d4290c00b
< 3.5.2
HIGH 7.2 Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before … wordfence
e1cd9978-2d8d-4818-8baf-8f31e0212957
< 1.15.0
HIGH 7.2 The ACF City Selector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
e1c16bcb-c188-4e01-9d0b-e4e1a1ef82ee
< 2.1.10
HIGH 7.2 The HBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'hb_country_iso', 'hb_usa_state_iso'… wordfence
e18b3a85-9d4a-4af8-9a73-1f8794ad467b HIGH 7.2 The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms coun… wordfence
e1523ba0-9cac-43e2-9441-4d02fbaaf705
< 6.5.6
HIGH 7.2 The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5… wordfence
e11c9f2c-4ac6-4da2-9b4c-d393e2d3332b
< 1.6.12.4
HIGH 7.2 The Simply Schedule Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
← Prev 344 345 346 347 348 349 350 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top