πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 364 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b15b10a4-04fd-4860-9cc9-cefcdbbbf507
< 1.0.8
HIGH 7.2 The User Rights Access Manager plugin for WordPress is vulnerable to Access Restriction Bypass via the 'page' parameter … wordfence
b100ba5a-8aad-4aa1-98bf-a09c5bde7bc1 HIGH 7.2 The Resume Submissions & Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
b0e582e3-9ca3-4601-81f2-cb6ef827a468
< 1.7.2
HIGH 7.2 The Contact Form to DB by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in versi… wordfence
b0c12678-1d91-4916-aa11-20292d9e384b
< 5.2.2
HIGH 7.2 The Meta pixel for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
b0c01e62-7a31-49de-851c-f52ce578bd95
< 8.1.00
HIGH 7.2 The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log co… wordfence
b06201bd-4f8e-41e5-89e1-b1f47757799b
< 5.6.8
HIGH 7.2 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
b034605b-284c-478a-baec-224c4533b2e0
< 3.5.9
HIGH 7.2 The Proxy & VPN Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
b02ab0cf-8bdf-4415-bae3-2193c3d75741 HIGH 7.2 The Giveaway WordPress plugin through 1.2.2 is vulnerable to an SQL Injection issue which allows an administrative user … wordfence
afe6d4ac-1712-415e-9995-cb7c8fe4e1a0
< 5.0.9
HIGH 7.2 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Server… wordfence
afc6aec8-e486-4c35-9e58-da6e04d88c25
< 4.0.0
HIGH 7.2 The Login by Auth0 plugin before 4.0.0 for WordPress allows stored XSS on multiple pages, a different issue than CVE-202… wordfence
afbfef8e-cdea-4ca0-bd28-08cc30eeec6e
< 4.0.9
HIGH 7.2 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored … wordfence
afbfabfc-b923-4fe9-9e8f-0cf159f488db
< 5.3.5
HIGH 7.2 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' and 'resource' … wordfence
af7dbb61-90b1-4a61-819e-bcef88b12b7f
< 1.7.26
HIGH 7.2 The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via… wordfence
af6a7052-6dab-42f0-a2af-0cf459d309d7
< 2.1.5.2
HIGH 7.2 The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.… wordfence
af5ed47e-f183-4e72-a916-15020e2bc91e
< 1.0.229
HIGH 7.2 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection i… wordfence
af187180-0f10-4fc0-8376-0e224a44d7eb
< 4.0.13
HIGH 7.2 The Easy Form Builder by WhiteStudio – Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
aefa868e-64ee-4852-bdbc-2de118b9e991
< 5.1.0
HIGH 7.2 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
aef312be-85d6-45e7-a34f-7f7cc415df3b
< 1.5.3
HIGH 7.2 The WP User Merger plugin for WordPress is vulnerable to generic SQL Injection via 'reassign_user' parameter versions up… wordfence
aebdd464-10b9-4d43-bf38-f0e8ae25625f
< 14.0.1
HIGH 7.2 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scrip… wordfence
ae9df4e5-b1d2-400b-89c7-eac5fbf2a8d5 HIGH 7.2 The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerabil… wordfence
ae9cd51f-e6c8-4aec-a044-376075e9540a
< 0.8.8.7
HIGH 7.2 The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters … wordfence
ae603b13-dc09-4f83-8741-943d62615b3c
< 2.0.1
HIGH 7.2 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo… wordfence
ae058c5b-b90b-4a1e-9f56-d56dbd2d3607
< 2.1.10
HIGH 7.2 The Pretty Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via various IP headers as well as the… wordfence
ade73ae0-4193-47e3-a545-2563fd19fb54
< 1.2.7
HIGH 7.2 The Geeky Bot – AI Sales Assistant for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
ade06c00-43b7-48b3-9c9d-4921fb52cc66 HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
← Prev 361 362 363 364 365 366 367 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top