πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 370 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9c44b6e5-7fb2-402e-8c8c-79d811ff0e9a
< 3.2.7
HIGH 7.2 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to generic SQL Injection via the mul… wordfence
9c40773d-3a2f-46b6-861e-608d662250da
< 5.4
HIGH 7.2 The MonsterInsights – Google Analytics Dashboard for WordPress plugin is vulnerable to Cross-Site Scripting via the a… wordfence
9c2d97c4-b166-4d1f-8042-d0362e650c62 HIGH 7.2 The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution i… wordfence
9bd63003-d1d6-480a-8df7-878bcc89f1ee
< 3.31
HIGH 7.2 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored … wordfence
9bb5e60d-f7c9-4b47-ba6f-0f2d1d060263
< 6.7
HIGH 7.2 The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p… wordfence
9bac82ee-55bf-4381-b441-115a675e4834
< 9.1.12
HIGH 7.2 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
9b821fb6-abc5-411f-ad6b-00b20954142c
< 3.1.5
HIGH 7.2 The menu delete functionality of the Side Menu – add fixed side buttons WordPress plugin before 3.1.5, available to Ad… wordfence
9b7be8e8-264c-4c28-a419-3bbfea744f3a HIGH 7.2 The photography theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… wordfence
9b6cf4ab-9e4d-4fd7-9e9e-c678ccc4d810
< 5.2.6
HIGH 7.2 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to SQL Injection… wordfence
9b448712-b989-453f-9acb-5556e01e41a4 HIGH 7.2 The WP App Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'app-bar-features' parameter in… wordfence
9b350b48-05ba-4054-895f-36d7ad71459d
< 14.16.5
HIGH 7.2 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al… wordfence
9afe4620-2d23-438e-9b8e-003a3c132c85
< 2.3.20
HIGH 7.2 The Five Star Business Profile and Schema plugin for WordPress is vulnerable to Remote Code Execution in all versions up… wordfence
9ab883bf-d6b4-4b0e-b8f4-69e6c0f90c70
< 1.7.1
HIGH 7.2 Unvalidated input in the Contact Form Submissions WordPress plugin before 1.7.1, could lead to SQL injection in the wpcf… wordfence
9a41bc0e-0ab9-4cee-b3ca-d730c828782c
< 1.1.14
HIGH 7.2 The Lucky Wheel for WooCommerce – Spin a Sale plugin for WordPress is vulnerable to PHP Code Injection in all versions… wordfence
9a371489-031e-483e-9fde-3901b55710c6
< 1.6.0
HIGH 7.2 The Coming Soon Page plugin for WordPress is vulnerable to SQL Injection via the 'rem' parameter in versions up to, and … wordfence
9a353364-73a9-428c-b702-0183b29c7e3d
< 1.2.5
HIGH 7.2 The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up… wordfence
9a2ee9bb-ae20-47ae-b792-438bf7be6cc4
< 3.1.2
HIGH 7.2 The BSK PDF Manager WordPress plugin before 3.1.2 does not validate and escape the orderby and order parameters before u… wordfence
9a09af8e-8da6-46e4-90e5-6ce1f8bfd36b HIGH 7.2 The xtremelocator plugin 3.0.1 for WordPress has SQL injection via the id parameter for high-privilege (admin+) users. wordfence
99fc02ea-5399-4ff2-a5f9-27878cadf40d
< 1.2.23
HIGH 7.2 The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 … wordfence
99e0a243-3e0e-4e2b-82fd-95c3cfde8a1b
< 3.7.4
HIGH 7.2 wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remo… wordfence
99dfce3b-2b47-41bf-8b20-b53fb9f061a7
< 1.8.1
HIGH 7.2 The Login No Captcha reCAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$_SERVER['PHP_… wordfence
99dfacb4-f784-4e8d-b411-7cab7683c7c8
< 0.6.0
HIGH 7.2 The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header wordfence
99b2e3c3-b5e5-4648-81c8-da2f42ceec66
< 1.8.1
HIGH 7.2 The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient permi… wordfence
993175b7-832d-4d08-8056-1ab2b0b0f3f6
< 6.4.26
HIGH 7.2 The Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
98d33b73-9c4b-477c-9a1c-17c792df3b1b HIGH 7.2 The AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o plugin for WordPress is vulnerable to arbitrary… wordfence
← Prev 367 368 369 370 371 372 373 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top