πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 359 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c0469ece-6f5f-4774-8094-f7f67702a775 HIGH 7.2 The Find And Replace content for WordPress plugin for WordPress is vulnerable to unauthorized Stored Cross-Site Scriptin… wordfence
c03ddcf0-6955-4645-b311-c3833ca61455
< 5.5.1
HIGH 7.2 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… wordfence
c033171a-d81f-4cae-830b-8bdc4017b85e
< 4.4.3
HIGH 7.2 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
c006b85d-fc05-41e7-93b2-5a09a21bec1a
< 2.68
HIGH 7.2 The Row Seats Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.66 via… wordfence
bff9e7d2-b9ad-403e-a361-3e95e2c7909f
< 4.9.32
HIGH 7.2 The ManageWP Worker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
bfcbf652-6cb4-4f3e-9032-ad262e8c8480
< 3.7.30
HIGH 7.2 WordPress before 5.2.3 allows XSS in stored comments. wordfence
bfcb0b1f-50fb-4cd8-8ca3-4338c0014cc7
< 19.6.25
HIGH 7.2 The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
bf8d34ea-cf05-4b20-9d1c-8cf0c608dfc3
< 1.5.122
HIGH 7.2 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code… wordfence
bf707d9b-2b96-4d1b-b798-38f7fe958eaf
< 2.0.3
HIGH 7.2 The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_… wordfence
bf527307-185b-4808-a3fc-d3ecafbd34e7
< 3.20
HIGH 7.2 The Media Library Assistant plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inclu… wordfence
bf4e3fc3-b9f4-4ae5-ad48-2f764879360a
< 3.7.0
HIGH 7.2 In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with mali… wordfence
bf26fc68-9fd4-4e4e-b34f-c947d95891f9
< 0.9.100
HIGH 7.2 WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and includi… wordfence
bef0eeb8-ed6d-46a3-91c5-84bdd88922b4
< 1.3.1
HIGH 7.2 The Really Simple CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
beceb218-34bf-4571-a07b-939abc7ead8e HIGH 7.2 The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI se… wordfence
bea1f918-d966-4214-8331-e389e4080ca5
< 1.9
HIGH 7.2 The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_portfolio_item_page SQL injection via t… wordfence
be6afae1-621a-4291-ae2c-793a60268fbf HIGH 7.2 The Time Sheets plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
be31866c-7490-4be2-9a4d-2a3771c6fea1
< 2.8.9
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remot… wordfence
be2579e3-8e40-4603-9ec1-38f43dc1aa29
< 0.9.78.07
HIGH 7.2 The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp… wordfence
be1bc322-1d42-4e33-adff-dbe706bb9f58
< 2.2.34.44
HIGH 7.2 The PiWeb Product Enquiry or product catalog for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
be0b26bc-ed97-42d8-985a-edb275dabfd5 HIGH 7.2 The bidorbuy Store Integrator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… wordfence
bd90e443-bedf-483b-84eb-3a447d79530e
< 3.7.2
HIGH 7.2 The Scheduled & Automatic Order Status Controller for WooCommerce plugin for WordPress is vulnerable to Open Redirect in… wordfence
bd8e86b0-5e06-44e0-a94c-b05581f46e5a
< 8.5
HIGH 7.2 The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page… wordfence
bd2f495e-63fd-49e4-9d6b-320ed007dacb
< 1.4.1
HIGH 7.2 The plugin Better Search Replace for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. Thi… wordfence
bd20e40c-cfec-4de6-a8a6-02850185003b HIGH 7.2 The Wow Countdowns WordPress plugin through 3.1.2 does not sanitize user input into the 'did' parameter and uses it in a… wordfence
bcf205a3-be7b-49e7-ba02-3f69632ed65f
< 2.3.4
HIGH 7.2 The User Activity Log Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent header in… wordfence
← Prev 356 357 358 359 360 361 362 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top