ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 372 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9373c82d-15a8-495a-8290-1b85c096f7e5
< 0.9.5
HIGH 7.2 The W3 Total Cache plugin for WordPress is vulnerable to weak validation of Amazon SNS push messages in versions up to, … wordfence
936e753b-b3e9-43c9-8686-c610faa8b20e
< 5.4.3
HIGH 7.2 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… wordfence
9347dafb-1789-4855-b09e-2a1ef5f7f2c1
< 1.13.36
HIGH 7.2 The Form Maker plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in versions up to, and … wordfence
934545ff-8886-47c7-ad50-0e5ff513a26c
< 1.0.9
HIGH 7.2 The PWA for WP & AMP plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to… wordfence
931983c3-d704-4c95-8078-7db4d79e1e1c HIGH 7.2 The Newsletter by Supsystic plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘sidx’ para… wordfence
92e9af52-a9a8-4b68-8351-f1091855fedc
< 1.3.25
HIGH 7.2 The HTML Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.24 due to insuf… wordfence
92d94f9a-150f-40ca-88e1-57cbd6e6880a
< 5.2
HIGH 7.2 The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
9298820e-3753-41b3-8ba6-9fb494e215a8
< 1.2.9.2
HIGH 7.2 The WP Editor plugin for WordPress is vulnerable to arbitrary file update due to missing file path validation in all ver… wordfence
928b4c4f-0614-410a-857b-90037770cfbf
< 2.56
HIGH 7.2 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injec… wordfence
922c029e-57a9-4c18-8598-9ea3bbc2ab69
< 3.5.46
HIGH 7.2 The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up … wordfence
920e4111-ac5c-4562-8529-67b17ceeb506
< 3.3.8
HIGH 7.2 The Oshine Modules plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to 3.3.8 (exclus… wordfence
91f86c22-94db-4c43-985a-2f3dd96ece21
< 2.9.6
HIGH 7.2 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 2.9.5 (inclusive… wordfence
91e0b45c-e73f-408a-94b8-fdbc5da64b20
< 3.95.0
HIGH 7.2 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP… wordfence
91aa163b-ac5b-4737-afa7-be4b55cb1e90 HIGH 7.2 The Canonical Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
91699d32-1768-4d87-a4f2-91969b3e3355
< 5.3.0
HIGH 7.2 The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in… wordfence
9124240d-e540-4a59-a4c5-c4279bb39399
< 2.3.11
HIGH 7.2 The gigpress plugin before 2.3.11 for WordPress has SQL injection in the admin area, a different vulnerability than CVE-… wordfence
910d9b31-b63a-427e-830b-a4c6a7e77ade
< 1.10.14
HIGH 7.2 The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in al… wordfence
90ea5c51-e739-42c1-a276-851ad800ff00
< 2.15.1
HIGH 7.2 The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tr… wordfence
90ea439b-48a6-4b21-a277-35db458e5a7a
< 10.11.1
HIGH 7.2 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
90e39398-19d7-435d-b23f-e93b8cdbcae4
< 2.4.19
HIGH 7.2 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
90d0b748-a56a-4932-8e43-751ca363725c
< 1.14.0
HIGH 7.2 The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to arbitrary file uploads due to mi… wordfence
90c4441e-3578-4bb0-befe-cfedcb5c1a71
< 1.0.275
HIGH 7.2 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
90920df9-1362-466b-b14b-4714087f556b
< 5.3.4
HIGH 7.2 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fh` (fingerprint) para… wordfence
9085b3b8-ee5e-455c-af39-1cb674a44f61
< 94.3.6
HIGH 7.2 The Hostiko theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 94.3.6 due to insufficien… wordfence
907329af-2ff0-475e-b4b2-3ac7ae4b9ced
< 2.6
HIGH 7.2 The WP Post Statistics (Visitors & Visits Counter) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
← Prev 369 370 371 372 373 374 375 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top