🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 351 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d56e8a6f-f6fb-4a34-becc-f1b7abed02ca
< 1.9
HIGH 7.2 The GD Security Headers plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
d5631826-6975-41e9-a896-f2aa0581334f HIGH 7.2 The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via… wordfence
d53161ad-cc5f-4433-b288-a8095cdfd7db
< 2.0.1
HIGH 7.2 The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via … wordfence
d5244db8-86b3-4d1d-8fd6-febfd5a7372e
< 19.6.2
HIGH 7.2 The Rehub theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 19.6.1. This m… wordfence
d522adb8-6a1f-4df7-8374-3f7491ed377c HIGH 7.2 The Fitness Zone WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
d5227269-4406-4fcf-af37-f1db0af857d6
< 3.3.3
HIGH 7.2 The AI Engine – The Chatbot and AI Framework for WordPress plugin for WordPress is vulnerable to arbitrary file upload… wordfence
d4c27c06-214a-4c20-80d0-b6b4d18737c3
< 5.7.0.1
HIGH 7.2 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nameservers' and '_msg' p… wordfence
d4bee7f0-ccbf-44b6-b853-f726d44fb83e
< 1.9.20
HIGH 7.2 The MoreConvert Wishlist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
d4aaca22-76b9-42ec-a960-65d44d696324
< 1.2
HIGH 7.2 The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to,… wordfence
d4a6c1e4-635f-4d4d-87a4-8eeded25f07f
< 1.7.4
HIGH 7.2 SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress… wordfence
d4a59aa8-db96-4487-97e9-e42aa57967fc
< 8.66
HIGH 7.2 The IdeaPush plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the idea_push_create_idea function in… wordfence
d46f1ecb-0a57-4fcb-93d4-2a41a344b4eb HIGH 7.2 The Live css plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3… wordfence
d4561441-d147-4c02-a837-c1656e17627d
< 2.0.8
HIGH 7.2 The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including… wordfence
d449a285-34f5-41ed-acfd-2a9acfb04271
< 3.1.1
HIGH 7.2 The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… wordfence
d4464bb1-273a-42c4-a7ec-8e123d286963
< 2.5.1
HIGH 7.2 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to PHP … wordfence
d4443759-af1c-409b-aa5f-3bfd55cb44a9 HIGH 7.2 The photography theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7… wordfence
d4096ad8-dc3c-4008-a035-2ba18044cf43
< 7.0.7
HIGH 7.2 The WooCommerce License Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
d3f8a294-3bb2-4d6b-b298-3844a6f51596 HIGH 7.2 The Total Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
d3c26454-a91d-4141-9b31-5c902c5e8eec HIGH 7.2 The pTypeConverter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.8.1 due to … wordfence
d392b84b-2a1f-430c-84a1-22431763a6a5
< 5.12.94
HIGH 7.2 The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that … wordfence
d342e8a3-d9fc-4ad1-ba82-ac9c4a37a78c
< 6.4.23
HIGH 7.2 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to Stored Cr… wordfence
d328e059-7235-496d-9c5a-c394df7ad235 HIGH 7.2 The AhaChat Messenger Marketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
d3034130-98f8-4907-862f-e04ff67b4d20
< 3.0.3
HIGH 7.2 The WP Custom Cursors plugin for WordPress is vulnerable to SQL Injection via the ‘edit_row’ parameter and potential… wordfence
d3027edb-770a-43d8-8abe-e9d9a51f4ab3
< 1.5.2
HIGH 7.2 The Dynamic Widgets plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.1 d… wordfence
d2c62f42-b649-4873-a330-4a0f268cab21 HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Comment Attachment plugin 1.5.5 and below for WordPress allows remote at… wordfence
← Prev 348 349 350 351 352 353 354 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top