πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 368 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a1db940b-6cfc-4109-aa02-37ddadcc1f8b HIGH 7.2 The Onepage Builder – Easiest Landing Page Builder For WordPress plugin for WordPress is vulnerable to SQL Injection p… wordfence
a1c731b9-8862-4140-b5e8-58132113e22c
< 3.7.2
HIGH 7.2 Jetpack versions 3.7.0 and earlier are vulnerable to a Cross-Site Scripting vulnerability in the contact form due to imp… wordfence
a178115e-b719-4c7f-9164-a44bdd0fdd4b HIGH 7.2 The AcuGIS Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… wordfence
a139f0fc-f3e0-4759-aa8d-ba138e5ccc87
< 11.57
HIGH 7.2 The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This i… wordfence
a13322b6-782b-425d-a214-cd7780aa3375
< 3.1.5
HIGH 7.2 The grandblog theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.1.5 (exclusive). … wordfence
a121b74d-8f4d-43c4-9dbc-fba489242ede HIGH 7.2 The Photography theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.1… wordfence
a0d93ee4-63e1-4fa7-9346-f56354124b9a
< 5.4.4
HIGH 7.2 The Coupon Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wcu_coupons' parameter … wordfence
a0ccb39b-faf1-428b-bfa7-c30d402bd34d
< 5.9.8
HIGH 7.2 The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL state… wordfence
a0c68e1e-5255-4e79-a6d9-a2021836e584
< 5.2.3
HIGH 7.2 The Super Page Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Activity Log in all versi… wordfence
a0bc1909-5002-44ab-9a5e-694c4ef946e2 HIGH 7.2 An id GET parameter of the WordPress Membership SwiftCloud.io WordPress plugin through 1.0 is not properly sanitised, es… wordfence
a08ea797-a836-4a21-bfca-2c05810d25cd
< 2.10
HIGH 7.2 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injec… wordfence
a0850b88-09f0-4da8-a9be-1b4aacf610e0
< 1.0.1
HIGH 7.2 The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versi… wordfence
a07a8cd6-8b01-4f65-abbd-7c93560aa437 HIGH 7.2 The WP Less Compiler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… wordfence
a051d96a-fe82-4223-839b-24cbb5b300d1
< 1.2.47
HIGH 7.2 The WP Time Slots Booking Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
a0349613-d212-49a9-870d-42aa1ec3f975
< 5.0.7
HIGH 7.2 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
a02f4fc4-42ca-4f8e-9c28-bfa69644e7b6
< 3.2.9
HIGH 7.2 The Booking calendar plugin for WordPress is vulnerable to SQL Injection via the search functionality on multiple admini… wordfence
9fd615cc-dc7f-4d46-bae3-3c9862083881
< 1.8.7
HIGH 7.2 The SiteGuard WP Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
9fafe21a-a942-4356-90b3-1b6a45535949
< 3.3.2
HIGH 7.2 The YayCurrency – WooCommerce Multi-Currency Switcher plugin for WordPress is vulnerable to Remote Code Execution in a… wordfence
9f92219a-e07e-422d-a9f2-dbe4fbcd5f55
< 5.13.3
HIGH 7.2 The AdRotate Banner Manager – The only ad manager you'll need plugin for WordPress is vulnerable to arbitrary file upl… wordfence
9f8e32a0-c67c-41cc-97ba-920f3ea5ea93 HIGH 7.2 The Zynith SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7… wordfence
9f678700-f266-4740-a98d-19f8e9734563
< 1.6.0
HIGH 7.2 The ImageLinks Interactive Image Builder for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orde… wordfence
9f52ec39-18d8-41eb-8712-7369680b8a58
< 7.2.3
HIGH 7.2 The Directorist plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the… wordfence
9f48e35e-12fd-4f75-bcb1-6820846298a2
< 3.7.0
HIGH 7.2 The Tabs – Responsive Tabs with WooCommerce Product Tab Extension plugin for WordPress is vulnerable to arbitrary opti… wordfence
9f4344d6-7679-499a-8086-9ae34b29a913
< 8.5.4
HIGH 7.2 The Woodmart theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.5.3 du… wordfence
9f4210a0-5448-4ff6-876a-37db4ad9b23a
< 1.7.43
HIGH 7.2 The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-… wordfence
← Prev 365 366 367 368 369 370 371 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top