πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 348 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e11662b0-5f67-4c27-abdb-522204acb35e
< 2.88.3
HIGH 7.2 The WP-UserOnline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in … wordfence
e10e3382-8bb9-4bb3-b881-0aaabd2412a0 HIGH 7.2 The Mobile App Editor – WordPress to Android App Builder plugin for WordPress is vulnerable to arbitrary file uploads … wordfence
e10c0d8d-718d-45dd-9ac3-a2673a6a16af HIGH 7.2 The Super Simple Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'sscf_name' p… wordfence
e0d9b77d-d7b6-48cd-9db9-ba62bd97c7b3
< 4.2.1
HIGH 7.2 The TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Bui… wordfence
e0d6ef49-288b-47d9-bbf2-dc31a6e3621e
< 1.6.3
HIGH 7.2 Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in … wordfence
e0cf5711-a02b-4db7-9bf7-47d512680428
< 1.2
HIGH 7.2 The safe-editor plugin before 1.2 for WordPress has no se_save authentication, with resultant XSS. wordfence
e08c3db4-6353-4bca-ab89-af46e5a0a128
< 3.1.6
HIGH 7.2 The Similar Posts WordPress plugin through 3.1.5 allow high privilege users to execute arbitrary PHP code in an hardened… wordfence
e05d4320-01d0-40c4-9a9a-457171ef7f5c
< 1.23.0
HIGH 7.2 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPres… wordfence
e02e8d8d-5b20-420d-b213-eeb0ef8d20b7
< 5.1.8.9
HIGH 7.2 The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1… wordfence
dfe07cd7-e448-4468-8280-3514690d8648 HIGH 7.2 The Post Content XMLRPC WordPress plugin through 1.0 does not sanitise or escape multiple GET/POST parameters before usi… wordfence
dfcc3d8c-c36a-4994-aa79-99953d9adfc1
< 6.5.6
HIGH 7.2 The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5… wordfence
dfb2dda8-1389-4b19-a5cd-d6b3436ab3b6
< 1.3
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress al… wordfence
df97321f-4cd6-44c8-9017-7824c9ba150b
< 3.1.8
HIGH 7.2 The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin… wordfence
df657cdc-00fc-476a-a64f-abfdd6b30739
< 2.7
HIGH 7.2 The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header when "I'm behind a proxy" opti… wordfence
df406e59-94d9-4704-82a3-02c2c1773c82
< 2.1.8
HIGH 7.2 The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
dee712ce-d49c-4706-964a-b8885cb6546e
< 2.0.85
HIGH 7.2 The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerabl… wordfence
ded73f27-6b3a-435a-861f-5e10938d6d1a
< 2.2.5
HIGH 7.2 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Stored Cros… wordfence
dececd27-d311-41c0-a10c-3b9cc8b8f128
< 3.6.13
HIGH 7.2 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP … wordfence
de8ac20f-d6ae-4e55-9337-4fb5ebd4f24a HIGH 7.2 The WP Church Donation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several donation form submi… wordfence
de0c8922-b290-4582-9079-e79da684bcff
< 3.3.2
HIGH 7.2 The Use-your-Drive | Google Drive plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
de09c677-6399-4af3-a378-8dd16dcd2819
< 7.6.1
HIGH 7.2 The Jannah theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.0 due … wordfence
dd9f10c6-911e-41d2-b1fe-e0cce9c48b48
< 1.10.2
HIGH 7.2 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
dd7312ec-9654-4ddc-aec6-71c7e684fac0
< 0.9.6
HIGH 7.2 The Customizer Export/Import for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.9.5… wordfence
dd4f0925-e3bf-4014-af05-b0d193b06493
< 10.1.03
HIGH 7.2 The WP Google Maps Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
dd3fc3a4-ba32-4c05-bc93-ed7b86c426fa
< 1.8.4
HIGH 7.2 The Contact Form 7 extension for Google Map fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
← Prev 345 346 347 348 349 350 351 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top