πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 354 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-2019 HIGH 7.2 The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl… nvd
CVE-2026-1945 HIGH 7.2 The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema… nvd
CVE-2026-1931 HIGH 7.2 The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers… nvd
CVE-2026-1216 HIGH 7.2 The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in … nvd
CVE-2025-14452 HIGH 7.2 The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param… nvd
CVE-2025-12886 HIGH 7.2 The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … nvd
cffaa829-3eee-4390-b3c0-5c0f04ff9e8f
< 1.15.15
HIGH 7.2 The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in … wordfence
cfc6b4a5-ff13-457f-9e06-de15e8cb5510
< 3.9.27
HIGH 7.2 The WP Import Export Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… wordfence
cfb53e44-7f9d-490f-b938-f428c20219d7
< 28.0
HIGH 7.2 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
cf992c75-a1ae-49c3-8110-2f3b31b23f6c
< 1.1
HIGH 7.2 The Zyrex Popup plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
cf902756-21f3-483b-a5d8-a9b4226bde22
< 1.18.11
HIGH 7.2 The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr… wordfence
cf803368-64ff-4dbe-85ae-af30e18bc833
< 2.6
HIGH 7.2 Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers… wordfence
cf3efda0-8609-4a75-a00b-735b49ef260b
< 1.9.15
HIGH 7.2 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Code Injection via the 't… wordfence
cf3c2031-06c7-42c9-a099-a798dc0cc3d0
< 1.7.0
HIGH 7.2 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… wordfence
cf346e71-9baa-473b-8a65-1f22dae8118f
< 6.0.12
HIGH 7.2 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Server-Side Requ… wordfence
cf0f5fd4-cd06-4d11-9f22-1f417b546afb
< 2.4.1
HIGH 7.2 The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜item’ pa… wordfence
cefcd612-0ba8-4225-8f23-817b7220ee7b
< 2.9.9.8
HIGH 7.2 The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Stored Cro… wordfence
cee6a100-cda5-48a6-9f9c-ea17f80c4165
< 2.3.8
HIGH 7.2 The Product Import Export for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi… wordfence
cec5bfa6-96ed-4a5a-be19-63434af32c89
< 4.0.4
HIGH 7.2 Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.1 allows remote attackers to i… wordfence
ce6cfed1-b19c-4000-81a1-fad13dc526d3
< 12.1.1.1
HIGH 7.2 The ICS Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 12.… wordfence
ce5c048a-0dbf-448d-bfca-aff347d9466b
< 3.10.01
HIGH 7.2 The ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor plugin for WordPress is vulnerabl… wordfence
ce489717-6489-40a7-9f69-74ba841ed235 HIGH 7.2 The Kush Micro News plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
ce4872f8-f589-4ae9-a5c5-4bb66043bfeb
< 4.7.8
HIGH 7.2 The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
ce330cae-c2f8-42f3-822b-ca24bf46e433
< 2.11.0
HIGH 7.2 The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t… wordfence
ce010c6f-16bd-4178-a621-31ba6378946a HIGH 7.2 The HTTP Headers plugin for WordPress is vulnerable to External Control of File Name or Path leading to Remote Code Exec… wordfence
← Prev 351 352 353 354 355 356 357 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top