πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 365 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
adbc23b3-fa9d-4303-8283-1cabb2a6bb71
< 1.3.9
HIGH 7.2 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
adb87ef2-8741-4144-b414-56e82dd35c89
< 6.03.01
HIGH 7.2 The Event Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via attendees first and last na… wordfence
adab6dd8-3054-42ca-99ae-1fc65108f823
< 1.3.51
HIGH 7.2 The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection v… wordfence
ad85b322-204a-4d74-8dde-38571fb68dd0
< 1.3
HIGH 7.2 The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the s… wordfence
ad6747da-394a-4f63-864d-bd52813fad69 HIGH 7.2 The M-vSlider plugin for WordPress is vulnerable to blind SQL Injection via the β€˜rs_id POST’ parameter in versions u… wordfence
ad48145b-24c5-49ac-a192-08c496e08e00
< 2.6.1
HIGH 7.2 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.… wordfence
ad34d657-da59-46ff-a54a-64e6c8974b69
< 3.7
HIGH 7.2 The DoLogin Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header … wordfence
ad20ddd2-33d0-4d49-bca0-ea2a829da6c8 HIGH 7.2 The Radio Forge Muses Player with Skins plugin for WordPress is vulnerable to Cross-Site Scripting via an unknown parame… wordfence
ad159b18-0ad1-4cab-932e-6850cf7a867f
< 0.9.1
HIGH 7.2 The Link Whisper Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all… wordfence
ac9d2b64-aff6-418a-bfe7-ec91b177ad6b
< 1.7.9
HIGH 7.2 The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbit… wordfence
ac6f7b03-6527-4d10-9320-4f94ed386f54
< 2.7.0
HIGH 7.2 The Responsive Slider – Image Slider – Slideshow for WordPress plugin for WordPress is vulnerable to multiple SQL In… wordfence
ac0455a2-1fa8-4a37-a72f-9ed5cca1d9ee
< 1.0.23
HIGH 7.2 The Lucky Wheel Giveaway plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includin… wordfence
abc8ee11-c149-4a2b-a388-7bd234c2cc64
< 1.1.1
HIGH 7.2 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
abc056b0-55a2-439c-b7f6-4a2fc48c9823
< 1.0.10
HIGH 7.2 The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulne… wordfence
abac57e7-2256-4592-a85d-89b71c444fe2
< 8.8.6
HIGH 7.2 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
aaf0e58c-0430-44fe-980f-8ea469802c86
< 10.6.6
HIGH 7.2 The RSVPMaker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions u… wordfence
aade1230-bc25-4391-a85b-7bcf661f8213 HIGH 7.2 A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp… wordfence
aaa2f738-4764-467c-9544-889ca8ba73d1
< 2.1.8
HIGH 7.2 The DELUCKS SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saveSettings() function that h… wordfence
aa8daa65-dc64-4cbf-9b49-2db08b64b02e
< 3.5.17
HIGH 7.2 The Modal Dialog plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.5.1… wordfence
aa8c5c44-235a-4839-9dc4-064ef25abfac
< 1.1.2
HIGH 7.2 The CubeWP Forms – All-in-One Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ve… wordfence
aa4e18b0-f871-4476-af92-42e55aabdf93
< 3.7.4
HIGH 7.2 The Prismatic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'prismatic_encoded' pseudo-short… wordfence
aa1bac80-4927-4fee-942c-c23d51b18abd
< 4.5.0
HIGH 7.2 The GetGenie plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4.3 d… wordfence
a9f6ab26-f4e4-4774-8663-d003efe27762 HIGH 7.2 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
a9d11f3a-eb28-4a80-8970-8ad05284a5b4
< 1.9.1
HIGH 7.2 The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Open Redirect in all versions up to, and i… wordfence
a9cc5c6d-4396-4ebf-8788-f01dd9e9cfbc
< 7.13.0
HIGH 7.2 The Abandoned Cart Lite for WooCommerce and Abandoned Cart Pro for WooCommerce plugins for WordPress are vulnerable to S… wordfence
← Prev 362 363 364 365 366 367 368 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top