πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 366 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a9c82154-d390-44ba-a54a-89f4bb69cdce
< 18.3
HIGH 7.2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions … wordfence
a9c4e296-f98a-4018-980d-173d5e7ade7b HIGH 7.2 The Donations Made Easy – Smart Donations plugin for WordPress is vulnerable to SQL Injection via an unknown parameter… wordfence
a9b5bf28-14fc-4a9f-909b-3374aca0f402 HIGH 7.2 The Qreatix theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.9.4 due… wordfence
a9b1445f-3b6b-40fa-9a12-f55d63668dda
< 3.1.3
HIGH 7.2 The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerab… wordfence
a9636b15-1259-4c6e-8691-b1d573ef0417 HIGH 7.2 The Theme Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation v… wordfence
a9511f60-b07d-4601-aa2f-25083b24d9aa
< 0.6.6
HIGH 7.2 The Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content plugin for WordPress … wordfence
a9384e78-fc46-4a3d-9a10-6d4fda17c698
< 1.9
HIGH 7.2 The NanoMag theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.8 due t… wordfence
a92e307d-b3c0-441a-abac-580a60dd44cf
< 3.7.7
HIGH 7.2 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the get_numbers… wordfence
a84afab9-83a2-40fc-99e4-cc332a8ab74a
< 5.2.10
HIGH 7.2 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
a8382051-ae17-4719-94b5-3cfb0b5e82b1
< 2.1.5
HIGH 7.2 The Video Gallery – YouTube Gallery plugin for WordPress is vulnerable to SQL Injection via 's' and 'orderby' in versi… wordfence
a831d5ae-cf20-4f6b-bc3c-214295ec8e2d
< 2.0.0
HIGH 7.2 The Anti Spam and list cleaner – AcyChecker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
a817c960-37e9-4f72-a2ef-845d9b898d48
< 2.0.7
HIGH 7.2 Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in Survey Maker WordPress plugin (versions <=… wordfence
a815496c-cd68-4ab4-a3bd-5fdcf59d02a6
< 1.6.1
HIGH 7.2 The Squeeze – Image Optimization & Compression, WebP Conversion plugin for WordPress is vulnerable to arbitrary file u… wordfence
a80007be-fb94-4460-91e8-f09b537580ca
< 1.8.3
HIGH 7.2 The FAQ Builder AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
a7f947ee-6bb0-455f-9824-effa1164c7b8 HIGH 7.2 An issue was discovered in the bestsoftinc Hotel Booking System Pro plugin through 1.1 for WordPress. Persistent XSS can… wordfence
a7adba0a-2f3b-43d8-b00a-8521dd0c6a2d
< 3.8
HIGH 7.2 The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_a… wordfence
a79f6657-31b1-48d5-99a9-fc39cc4d572a
< 2.4.7
HIGH 7.2 The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
a78b76d6-4068-4141-9726-7db439aa6a9f HIGH 7.2 The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insuf… wordfence
a75c179f-236b-4a1b-8566-b74e0c5fda27 HIGH 7.2 The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating t… wordfence
a73f806d-5d64-4df5-b032-3d3a149036ff
< 4.0.38
HIGH 7.2 The Events Calendar, Event Booking, Registrations and Event Tickets – Eventin plugin for WordPress is vulnerable to Se… wordfence
a71992e2-fdac-4e89-8867-4b771d9b4374
< 3.8.1
HIGH 7.2 The Blackhole for Bad Bots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent HTTP hea… wordfence
a6ede290-a6c4-4c13-872b-60c9601d39db
< 2.8
HIGH 7.2 The Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.7.… wordfence
a6c83a27-92fd-4b3e-9776-b0d110b5cb74 HIGH 7.2 The DriCub theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.9. T… wordfence
a6b46c65-b81c-4d3a-b0c8-b661745a9580
< 1.5.9
HIGH 7.2 The Fediverse Embeds plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
a6ae2701-4fd6-475b-a589-65d314981807 HIGH 7.2 The Everest Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
← Prev 363 364 365 366 367 368 369 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top