πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 367 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a6a22af6-055c-4495-9246-1cb7caaf47b8
< 3.8.13.2
HIGH 7.2 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.13… wordfence
a69a5249-f9ab-4489-a032-33dd482fdc96 HIGH 7.2 The Master Slider Pro plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to… wordfence
a5f847d8-323f-47f9-ba10-df8173ff3018
< 6.6.4
HIGH 7.2 The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all ver… wordfence
a596c9c4-ceb4-470c-8ad5-986cd62da91e
< 2.7.11
HIGH 7.2 The Ad Inserter plugin for WordPress is vulnerable to Remote Code Execution in versions before 2.7.11 via the settings.p… wordfence
a57d218c-0aee-4764-9496-065e71448a9b
< 3.3.9
HIGH 7.2 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
a53a1178-7267-4d7f-ad9e-2906c05b8fe0
< 5.3.3
HIGH 7.2 The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
a50e7042-bf7b-49d8-8e62-d01ecdd769fd
< 2.10.1
HIGH 7.2 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10… wordfence
a50e2df0-b45e-4a0a-b6dc-f05b4286132a
< 7.1.3
HIGH 7.2 The Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP plugin for WordPress is vulnerable to Remote Code … wordfence
a4c8cf71-e9b0-4241-b975-f52aeb823318
< 1.0.16
HIGH 7.2 The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vu… wordfence
a4b46cb3-766f-4524-be04-e10dea3e5bfa
< 8.91.0
HIGH 7.2 The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to Stored… wordfence
a47a8d0e-598e-4674-bba7-41582481025d HIGH 7.2 The Zippy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
a453a38f-0ef5-446b-886f-c208c1baa648
< 4.2.1
HIGH 7.2 The Simple Payment Donations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
a4522102-5997-449e-81fe-446a5dac6e71 HIGH 7.2 The Ketchup Restaurant Reservations plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
a41c2ee9-2c9a-4b01-8594-fe608f9d2bf2
< 4.2.4
HIGH 7.2 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to Stored Cross-S… wordfence
a407d8b1-1d21-4b23-a8d6-a977544a19b4 HIGH 7.2 The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1… wordfence
a3c36821-f780-4944-95c9-bcf3bbb73da5
< 1.9
HIGH 7.2 The awesome-filterable-portfolio plugin before 1.9 for WordPress has afp_get_new_category_page SQL injection via the cat… wordfence
a33a846c-6489-4337-b59e-b969ff03dbcd
< 7.6.0
HIGH 7.2 The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
a328643a-ab12-427e-9bcd-2d40738afb61
< 2.9.4
HIGH 7.2 The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up t… wordfence
a317395b-32ab-4a00-9568-b87d7c4f69a6
< 2.8.7
HIGH 7.2 The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for… wordfence
a2f9d282-1bba-48d2-8f12-a5a4a58c77f6 HIGH 7.2 The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions… wordfence
a2f508f1-45a0-4cb4-9d67-51edd3d74abe HIGH 7.2 The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'U… wordfence
a2a58fab-d4a3-4333-8495-e094ed85bb61
< 3.1.4
HIGH 7.2 The "Survey Maker – Best WordPress Survey Plugin" plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
a251bcbf-68ec-4833-b21c-7a823ce65279
< 1.2.0
HIGH 7.2 The LetsRecover plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in versions up … wordfence
a2432a0a-d262-4460-bd2d-2cb200d51f6f
< 1.8.1
HIGH 7.2 The coreActivity plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown p… wordfence
a1ffb318-41b4-4b31-b170-387c368ae686
< 1.2.8
HIGH 7.2 The Cities Shipping Zones for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up … wordfence
← Prev 364 365 366 367 368 369 370 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top