πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 360 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bce9ba42-f574-47c1-9ea5-1e56f9da8e71
< 1.0.16
HIGH 7.2 The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulne… wordfence
bcd50211-447c-4097-9281-551a3caad1a6
< 1.8.0
HIGH 7.2 The WangGuard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_ip' variable in version 1.… wordfence
bcb68038-96a6-40b6-a37c-757fc19cbe0c
< 13.1.6
HIGH 7.2 The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o… wordfence
bc972855-6bd5-43cd-96e6-3b1aa1c6255b
< 1.5.0
HIGH 7.2 The Easy WP SMTP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.9 via … wordfence
bc5f1b00-acee-4dc8-acd7-2d3f3493f253 HIGH 7.2 The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in vers… wordfence
bc5cd81b-3182-45fb-a93a-471ecf770e42
< 7.5
HIGH 7.2 The Team Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.4. This m… wordfence
bc38990f-0079-46de-8197-0187189d90d9
< 4.9.24
HIGH 7.2 The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … wordfence
bbe8c101-5e0a-4ba7-8ff7-4c8ed01e9ef5
< 2.1.3
HIGH 7.2 The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… wordfence
bbdca292-89b6-4e62-bc68-4fdcd57fd504
< 4.0
HIGH 7.2 process_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_fil… wordfence
bbd580fe-dba4-4662-b7d5-cf0298279079
< 1.1.9
HIGH 7.2 The BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net plugin for WordPress is vulne… wordfence
bbd48a92-dc8f-4f51-b799-f7cedac34661 HIGH 7.2 The Bakery Autoresponder Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
bbc1b46e-139a-4e1a-a0c7-e45e10adada5
< 2.6.7
HIGH 7.2 The get_reports() function in the Secure Copy Content Protection and Content Locking WordPress plugin before 2.6.7 did n… wordfence
bbaba6cb-a829-4c07-b068-bdcb6a646450
< 1.3.6.3
HIGH 7.2 The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via th… wordfence
bba8007f-7254-4201-8f94-7bf921a33a27
< 4.4.0
HIGH 7.2 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
bb927aba-a96d-47b9-ba35-60945ea5cfe5
< 1.8.97
HIGH 7.2 The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… wordfence
bb6f3607-d44f-452a-b3ad-55f036033480
< 1.6.7.43
HIGH 7.2 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to R… wordfence
bb1def67-ad83-4ad5-bb11-fbd1c02ece47
< 1.7.6.3
HIGH 7.2 The Propovoice CRM – Best CRM & Invoicing Plugin to Manage Leads, Clients and Billings automation plugin for WordPres… wordfence
bb14a79a-32ba-4d7a-b706-4e602a25e9cf
< 1.1.1
HIGH 7.2 The Enable SVG, WebP & ICO Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
bb03aeb8-32ab-4962-bc95-b10fb7bd7fcf
< 3.9.4
HIGH 7.2 The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m… wordfence
bad00612-d98e-4b5e-88e8-664064588bdd
< 3.0.7
HIGH 7.2 The Extensions For CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
bacfa993-2fc1-43bc-b4f0-f463ba28b4ed
< 1.5.2.1
HIGH 7.2 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… wordfence
bacd7942-99f6-46e0-85ef-863ab1bdfa6a
< 1.1.6
HIGH 7.2 The CP Contact Form with PayPal plugin for WordPress is vulnerable to SQL Injection via the 'cp_contactformpp_id' parame… wordfence
baa063b7-8b79-4de3-84b1-6dec024fa395
< 1.0.6
HIGH 7.2 The Event Management Tickets Booking By Event Monster plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
ba6312b9-1b66-4b4f-a78d-515fa4aab63b
< 2.12.4
HIGH 7.2 The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.… wordfence
ba5485be-7612-406d-870d-6827f6c7ea71 HIGH 7.2 The Sticky Anything plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
← Prev 357 358 359 360 361 362 363 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top