πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 350 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d906992f-8675-4170-8643-48799ae7ac7c
< 1.6.8
HIGH 7.2 The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parame… wordfence
d8ceb4a1-9354-4ed3-9a8f-45ba2057a810
< 0.9.117
HIGH 7.2 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploa… wordfence
d8a81c01-495f-4861-b66f-000072e99512
< 2.7.5
HIGH 7.2 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app… wordfence
d8a4feb3-908f-4fff-84f2-099f56d46f5b
< 21.8.0.100
HIGH 7.2 The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to unauthorized modification of data … wordfence
d8624f48-9938-4114-a55a-e635ca0dff2c HIGH 7.2 The Buddybadges plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insu… wordfence
d8616189-5ab8-4db0-ab9e-768cc738aeb6
< 3.5.3
HIGH 7.2 The Jetpack plugin for WordPress, in versions up to 3.5.2, is vulnerable to DOM based Cross-Site Scripting via the file … wordfence
d8351204-da6d-443a-98b5-0608bfb1e9d0
< 14.15.5
HIGH 7.2 The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cr… wordfence
d7c0b933-469e-4f8b-94b2-8823568c5d45 HIGH 7.2 The Rough Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a Chart Data Label in versions up … wordfence
d77666b5-956d-420b-93ed-a15cdbfcced7
< 6.2.0
HIGH 7.2 The WooCommerce Product Add-ons plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… wordfence
d774af46-4928-4e86-b0e0-1a73f39a8f09
< 1.10.0
HIGH 7.2 The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… wordfence
d76229c9-39e6-48ab-b038-be40b36aa7bd
< 4.16.18
HIGH 7.2 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Cross-Site Scripting in version… wordfence
d759d7ab-74d5-4195-9258-7281f49b5132
< 0.4.2.6
HIGH 7.2 The FoxyPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the d… wordfence
d7576dd9-198b-49a7-950e-fc301e4bc5f8
< 5.4.5
HIGH 7.2 The Zero Spam plugin for WordPress is vulnerable to SQL Injection parameter in versions up to, and including, 5.4.4 due … wordfence
d71caa62-6f77-44a6-8645-a27a08a48a78 HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
d6e16234-ec7b-466f-bc11-e80e63dec49f
< 1.3.47
HIGH 7.2 The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
d6cbec61-cbe8-44a6-8cc8-8603393ed6b0
< 2.2.4
HIGH 7.2 The WooCommerce Beta Tester plugin for WordPress is vulnerable to SQL Injection in versions prior to 2.2.4 due to insuff… wordfence
d68e74c2-3732-40ae-b589-3a9159aff93d
< 2.9.0
HIGH 7.2 The Affiliates Manager WordPress plugin before 2.9.0 does not validate, sanitise and escape the IP address of requests l… wordfence
d678eca4-ad6d-4511-9f6d-37269dcf0ecb
< 3.4.6
HIGH 7.2 The WP-CRM System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4.5 via… wordfence
d66df15e-1a0a-49e9-bcf9-67091499b24e
< 2.6.4
HIGH 7.2 The plugin is vulnerable to PHP Object Injection in versions up to and including, 2.6.3 via deserialization of untrusted… wordfence
d667bafc-5f19-4889-a988-236df050c013
< 3.8.2
HIGH 7.2 The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post … wordfence
d62bd2bd-db01-479f-89e4-8031d69a912f HIGH 7.2 The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and includ… wordfence
d619d300-8bba-45a1-bd0a-d82e9066a43d
< 4.6.16
HIGH 7.2 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to mi… wordfence
d606cada-fd3d-4763-9751-5378e81969f0
< 6.5.38
HIGH 7.2 The YOP Poll plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.5.37 … wordfence
d5f372bf-6b13-4ba7-8b8b-9d3b500e4420
< 1.1.0
HIGH 7.2 The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions… wordfence
d57e4c3b-6e0d-40d5-bcf3-10af797d2f1b HIGH 7.2 The Shiny Buttons WordPress plugin through 1.1.0 does not have any authorisation and CSRF in place when saving a templat… wordfence
← Prev 347 348 349 350 351 352 353 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top