🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 369 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9f3b0637-b1ee-4e0b-95cd-11ac377805a7
< 1.2.0
HIGH 7.2 The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
9f2d8a68-4cb9-44bc-b4ae-43a8e8468634
< 4.2.2
HIGH 7.2 The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 v… wordfence
9ef3f7a2-4ed2-4235-8a6b-f2a5cf288029
< 3.0.6
HIGH 7.2 The Dynamic OOO widget for the Elementor Pro plugin through 3.0.5 for WordPress allows remote authenticated users to exe… wordfence
9eee9bec-609a-468b-8b44-ac4af409df93
< 5.2.6
HIGH 7.2 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection… wordfence
9ed25de7-f002-4108-b2c6-f790acbbe27b
< 111220
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers … wordfence
9ed23152-30bd-40ab-947b-f773eb2a6b4f
< 2.11.32
HIGH 7.2 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
9ea42fbc-ec08-4f67-90d0-506fc474a4a6
< 1.5.7
HIGH 7.2 The Kadence WooCommerce Email Designer for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… wordfence
9e56e1fe-bb53-422c-9219-b79e24f0f915 HIGH 7.2 The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter. wordfence
9e51c8b5-cbb9-48aa-9c99-69f1b39fb0b4
< 4.0.7.4
HIGH 7.2 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
9e34c3f6-cc84-4e45-9948-6f7fd5cba8cd
< 2.5.2
HIGH 7.2 The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/clas… wordfence
9e345e3a-a3d4-4533-b8bb-90795f991cbc
< 1.3.0
HIGH 7.2 The Contact Form Entries plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.2.9 whe… wordfence
9e2afd66-c896-47c8-bf56-84a086087d55
< 7.1.0.17
HIGH 7.2 The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘HTTP_REFER… wordfence
9e10e625-c444-487a-b0c3-1730fa727c89 HIGH 7.2 The Business Card plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
9df6d75b-a141-41a8-b965-6be7acee582d HIGH 7.2 The illi Link Party! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versi… wordfence
9dc20703-9d7d-498f-a531-4539b7848249
< 2.4.7
HIGH 7.2 The Simple Payment plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2… wordfence
9d8eae69-722a-45ea-a3ca-d4a39a63c4b3
< 1.0.4
HIGH 7.2 The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer header in versions up… wordfence
9d534a1e-280d-418d-b497-1f3e6f3a20fb HIGH 7.2 A pageid GET parameter of the GSEOR – WordPress SEO Plugin WordPress plugin through 1.3 is not sanitised, escaped or v… wordfence
9d4546b9-f974-4fe9-b981-9fe0c84f6a8b HIGH 7.2 The Staff Directory Plugin: Company Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all v… wordfence
9d2df49d-0276-403d-9fe8-00fdf7262818
< 3.4.18
HIGH 7.2 wordfence
9d1e8703-4ad3-42c5-a20d-f1bd31522a8b
< 1.1.5
HIGH 7.2 The Change WordPress Login Logo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the height and wid… wordfence
9d19be8b-3e0b-4d74-97e0-f17132d2d34c
< 8.4
HIGH 7.2 The NEX-Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.3.3 due to insuffi… wordfence
9cf12dc1-7b66-4c6e-8c3e-5915e1032303
< 5.6.3
HIGH 7.2 The Jock on air now plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings and 'show-… wordfence
9cd92993-1cda-46dc-8318-f2e938bff262
< 0.9.10b
HIGH 7.2 The incoming-links plugin before 0.9.10b for WordPress has referrers.php XSS via the Referer HTTP header. wordfence
9ca12315-380b-4251-b637-4e9d29df35e0
< 3.2.1
HIGH 7.2 The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & … wordfence
9c8b0de4-e3ee-4711-8f27-097dee843dd8
< 2.13.45
HIGH 7.2 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to una… wordfence
← Prev 366 367 368 369 370 371 372 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top