πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 361 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ba16b100-6ee7-46ec-8868-4467a29048ad
< 3.1.0
HIGH 7.2 SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execut… wordfence
ba0fdd81-767a-4858-acdb-e60fd5e15aab HIGH 7.2 The Active Directory Integration plugin for WordPress is vulnerable to SQL Injection via the β€˜userid’ parameter in v… wordfence
b9e67e3e-188c-4ca9-b846-d318859aeaf8
< 5.16.5
HIGH 7.2 Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly chec… wordfence
b9b8b08d-821b-41dd-aab3-c9f3423e0cc1
< 1.1.7
HIGH 7.2 The Range Slider Addon for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
b98f2a85-9535-4bf5-900c-f4f630c7b502
< 1.5
HIGH 7.2 The SMTP for SendGrid – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
b988f424-f649-4bf0-9f7f-88faa41c0029 HIGH 7.2 The Quotes Collection WordPress plugin through 2.5.2 does not validate and escape the bulkcheck parameter before using i… wordfence
b980bcd6-5ae3-4fa8-843b-652bd94d1dc6 HIGH 7.2 The Newsletter Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nl_data' parameter in al… wordfence
b97c6171-3842-4f2b-adf5-28fc4c0b24bf HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
b9790543-f4db-46a7-ad0d-3276dcf3a64a
< 1.4.4
HIGH 7.2 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
b97819de-4919-46b1-b0f9-ac09e1caa031
< 3.0.0
HIGH 7.2 The Colissimo shipping methods for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
b95b6c12-df45-4ef0-9312-81798346fd64 HIGH 7.2 The Silencesoft RSS Reader plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and … wordfence
b94facce-975f-4080-ad67-95d282b28d0d
< 4.7.4
HIGH 7.2 The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, an… wordfence
b93f66ac-5c9b-483a-a7ad-0a404d3935e0
< 2.0.0
HIGH 7.2 The WooCommerce Pre-Orders plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, … wordfence
b91b189d-c159-45c2-a75a-933a72706c47 HIGH 7.2 The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to PHP Object Injection in all versions u… wordfence
b9174903-5394-475b-b90f-66f97548e424
< 2.0.11
HIGH 7.2 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
b9083f58-bbb3-4ef2-96a4-cd61aae0f14a
< 2026.4
HIGH 7.2 The Stop Spammers Classic plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b901b3f8-8bbd-42ef-8e0c-de6d09c4950f
< 8.0.5
HIGH 7.2 The Quiz and Survey Master plugin for WordPress is vulnerable to iFrame Injection via the 'question[id]' parameter in ve… wordfence
b8cdd8b4-52e6-431b-b2f0-bfe1d0c1dd91
< 3.1.2
HIGH 7.2 cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to exe… wordfence
b8b1a124-ad3a-4f17-9913-88bfda26dca9
< 1.1
HIGH 7.2 Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to … wordfence
b8ab6dfa-3764-470f-aa49-1964f42d93de
< 27.3
HIGH 7.2 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
b88efc1b-dc2d-4fe2-ba2b-e29898ed1bc4 HIGH 7.2 The Paytm – Donation Plugin WordPress plugin through 1.3.2 does not sanitise, validate or escape the id GET parameter … wordfence
b8877261-c60c-4433-9a4d-f1a99cac66c0
< 5.0.7
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Easy MailChimp Forms plugin 3.0 through 5.0.6 for WordPress allows remot… wordfence
b83db6c7-09af-4707-a96b-ee551f27e3b7 HIGH 7.2 The GetContentFromURL plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
b7eb9e6e-52d7-41d2-b51f-5cc5b7f3dd40
< 9.0.48
HIGH 7.2 The Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.0.… wordfence
b7e2ca2e-c495-47f8-9c18-da5ba73d9e70
< 0.9.75
HIGH 7.2 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to deserialization of untrusted input via … wordfence
← Prev 358 359 360 361 362 363 364 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top