πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 352 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d2b7ed73-a654-40ef-8d80-6171393da8e7
< 5.4.8
HIGH 7.2 The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
d253a001-7023-4070-81c5-35d485ffd36c HIGH 7.2 The Advanced Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data parameter in all vers… wordfence
d21b09f2-6766-4f55-9745-ae9fd4a0d88c HIGH 7.2 The KKProgressbar2 Free – advanced progress bars plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
d2165d61-dc86-4893-91c4-85f0a577fc1c
< 13.1.6
HIGH 7.2 The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o… wordfence
d1e0d59b-903e-466b-9892-a2cee6f7a53f
< 7.7.5
HIGH 7.2 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
d1b4ea18-0937-4bd4-b161-a3780e6c6749
< 2.1.0
HIGH 7.2 The Easy Invoice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0… wordfence
d18d800b-647f-4706-9ec1-a8ea4e643965
< 3.3.20
HIGH 7.2 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to SQL Injection in the projects_list and … wordfence
d16363d6-ca4b-4de0-abae-a7b07803e2e3
< 2.4.1
HIGH 7.2 The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the … wordfence
d159130a-c99d-44d3-a130-aa0146f17157
< 5.1.13
HIGH 7.2 The Seamless Donations: A Platform for Global Fundraising and Rebuilding using Stripe and PayPal plugin for WordPress in… wordfence
d0e0d284-2056-414e-9069-d2302db0670d HIGH 7.2 The Live Chat Unlimited plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… wordfence
d0c9f4c5-a4f6-4cab-8531-5b88b3f347ea
< 2.9.10
HIGH 7.2 The PostX – Gutenberg Blocks for Post Grid plugin for WordPress is vulnerable to Cross-Site Scripting in versions up t… wordfence
d09985e9-ee18-41a0-94d0-05dd80a68ed9
< 8.2.0
HIGH 7.2 The Nelio A/B Testing – AB Tests and Heatmaps for Better Conversion Optimization plugin for WordPress is vulnerable to… wordfence
d070e12e-ec53-4574-ac37-dc8805d9a553
< 2.2.5
HIGH 7.2 The WPSchoolPress plugin for WordPress is vulnerable to time-based blind SQL Injection via the β€˜ClassID’ parameter i… wordfence
d056ad60-0102-490e-89a8-31fe6513645e
< 5.2.0.4
HIGH 7.2 The plugin WP phpMyAdmin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.… wordfence
d04f11b4-ee58-428b-aaa2-dc7d9f3e68e3
< 2.0.5
HIGH 7.2 The ShopWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST … wordfence
d0318ed9-a464-498b-a821-f7746740937c
< 2.8.2
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attacker… wordfence
CVE-2026-2365 HIGH 7.2 The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_sav… nvd
CVE-2026-2019 HIGH 7.2 The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl… nvd
CVE-2026-1945 HIGH 7.2 The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema… nvd
CVE-2026-1931 HIGH 7.2 The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers… nvd
CVE-2026-1216 HIGH 7.2 The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in … nvd
CVE-2025-14452 HIGH 7.2 The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param… nvd
CVE-2025-12886 HIGH 7.2 The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … nvd
cffaa829-3eee-4390-b3c0-5c0f04ff9e8f
< 1.15.15
HIGH 7.2 The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in … wordfence
cfc6b4a5-ff13-457f-9e06-de15e8cb5510
< 3.9.27
HIGH 7.2 The WP Import Export Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… wordfence
← Prev 349 350 351 352 353 354 355 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top