πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 371 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
98cf616d-6c9a-4a86-937d-535211e32bf1
< 5.7.2
HIGH 7.2 The PhotoMe theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.1 due… wordfence
98adce63-69e6-4a3b-97fe-ecd0480659f4
< 2.8.7
HIGH 7.2 The Affiliates Manager WordPress plugin before 2.8.7 does not validate the orderby parameter before using it in an SQL s… wordfence
989b4b9d-e22e-46a7-8ebc-5c8b33f98111
< 2.5.2
HIGH 7.2 The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server… wordfence
97e68562-92b8-43ac-9a8c-778d2b61f889
< 4.1.18
HIGH 7.2 The Mailster WordPress Newsletter Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing fil… wordfence
979699fd-ff31-4cba-bbf2-03fa51554031
< 5.0.6
HIGH 7.2 The Multi Rating plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'from-date', 'to-date', and 'post… wordfence
97964ebd-be0b-4187-b393-17edf4ba5caf
< 1.13.2
HIGH 7.2 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
977d1ec4-327b-4563-a3b1-ac4fad195eb7 HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
9771d688-9c96-4ffb-823e-dcdf8b1cbc51
< 6.0.8
HIGH 7.2 The Awesome Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
975c02d9-3e70-4e58-a6bb-57d45282459b
< 1.2.63
HIGH 7.2 The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to… wordfence
9744055a-b199-4945-afcc-4f5b85f5f1e8
< 1.7.1058
HIGH 7.2 The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and incl… wordfence
970fc0af-d049-4aad-a439-7d1ea6bcca9b
< 3.9.3
HIGH 7.2 The Coaching theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.9.2 du… wordfence
96bc0d9b-1f03-48d4-aa99-954e92e77c04 HIGH 7.2 The Cyclone Slider Plugin is vulnerable to Remote Code Execution via the slider import functionality in versions up to, … wordfence
96b68824-3080-4959-a7d7-43d29c5c4119
< 4.4.5
HIGH 7.2 The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter bef… wordfence
9699118a-e12f-491f-b464-51129888fb1a
< 3.1.5
HIGH 7.2 The Two Way Chat plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.4 due … wordfence
95fde924-bba5-4b7d-8cee-50bb3d2b4134
< 1.0.232
HIGH 7.2 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Remote Code Execution … wordfence
95c47c7b-df83-43ee-9091-136b6622e88c HIGH 7.2 The WP Chinese Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
958a036e-2893-40c2-a542-7a33c12161e3 HIGH 7.2 The Helios Solutions Brand Logo Slider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … wordfence
95823720-e1dc-46c1-887b-ffd877b2fbe5
< 4.13.1
HIGH 7.2 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
954e7509-3ebf-429a-8c65-9825ea190d53
< 5.0.0
HIGH 7.2 The FluentForm plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.3.25 due to insuf… wordfence
952aec28-a380-4c6d-8391-b21cddf90a5c
< 3.3.2
HIGH 7.2 The Real Estate 7 Theme for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in versions … wordfence
952a61e8-4be1-4974-9076-4493708bf51e
< 2.13.11
HIGH 7.2 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
94dcaa35-f39f-4e8b-a57c-78343520cca6
< 2.6.5
HIGH 7.2 The Perfmatters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.6.… wordfence
94dbf144-4a8f-4d9a-ad32-703a91823acb
< 1.1.0
HIGH 7.2 The Limit Login Attempts Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via its lock logging fea… wordfence
94772de9-6ab8-45ff-8b56-19b50a81b66f
< 1.13.2
HIGH 7.2 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
941c9586-96a2-434e-af0d-c488e22ef97f
< 2.5.6
HIGH 7.2 The Breeze Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.5… wordfence
← Prev 368 369 370 371 372 373 374 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top