🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 373 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
90552d5a-6103-48c7-ad44-52ee8ecac114
< 0.4.18
HIGH 7.2 The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJA… wordfence
90141b96-83cb-4c33-9ffe-ffda1b249acc
< 1.7.07
HIGH 7.2 The WorkScout-Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
8fc6c23c-1c5c-4fd8-aeea-8eb431e33b39
< 1.1.3
HIGH 7.2 The Contact Form to Any API plugin for WordPress is vulnerable to SQL Injection the 'form_id' parameter in versions up … wordfence
8fa97e67-08c1-4553-bada-e4c59f797207
< 1.7.9
HIGH 7.2 The Buddyboss Platform plugin for WordPress is vulnerable to SQL Injection via the BP_Notifications_Notification::get_or… wordfence
8f9615a9-e001-4a1f-a675-21515b4ba97f
< 1.2.0
HIGH 7.2 The LetsRecover plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in versions up … wordfence
8f840a96-8cda-4237-b445-284b88eaf623
< 2.5.0
HIGH 7.2 The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using… wordfence
8f740671-6316-4626-ac98-dfcfc8a9c88f
< 5.5.0
HIGH 7.2 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
8f5a3ed2-1db2-47e4-9aca-8fb197174342
< 1.6.3
HIGH 7.2 The Futurio Extra WordPress plugin before 1.6.3 is affected by a SQL Injection vulnerability that could be used by high … wordfence
8f1e3c0d-3b67-40e8-b233-e23e257982f4 HIGH 7.2 The Manual - Documentation, Knowledge Base & Education WordPress theme for WordPress is vulnerable to Stored Cross-Site … wordfence
8ef7c48b-e8f2-40bd-aa48-191059e15453 HIGH 7.2 The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for Word… wordfence
8ec5173b-7b0d-4887-8c13-f48137aa8593 HIGH 7.2 The Help Desk WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
8e958653-36c4-4979-89e1-d9411a35a92a
< 1.1.5
HIGH 7.2 The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inc… wordfence
8e12d132-c036-4665-bb8d-e31e2b155fbd
< 2.16.4
HIGH 7.2 The Relevanssi - A Better Search Free & Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th… wordfence
8dc41ac8-1126-4fcc-942e-89e15b1ebfb7
< 0.9.2
HIGH 7.2 The Exports and Reports plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 0.9.1 via … wordfence
8db71624-5394-417b-9cc4-ae7376a475c7 HIGH 7.2 The Improve My City plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
8dae13e5-cee7-4392-af71-7d466ba6f6c4 HIGH 7.2 The WP Report Post plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and i… wordfence
8d9fb215-4c00-4b73-824b-e2ee0b7294fe HIGH 7.2 The Contact Form vCard Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
8d5a1aec-11f5-4516-9454-651ca4cd6600
< 1.2.7
HIGH 7.2 The WP Editor plugin for WordPress is vulnerable to blind SQL Injection via the setting fields in versions up to, and in… wordfence
8c8f6f49-df06-48c5-885e-9a835dc5d87b
< 3.2.1
HIGH 7.2 The Advanced AJAX Product Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
8c83f430-8a4d-40fa-890c-387c787a3b55
< 6.0.9
HIGH 7.2 The Oxygen Theme theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
8c5642fa-d001-47c4-8acd-94ae944e5129
< 3.3.13
HIGH 7.2 The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing… wordfence
8c29046f-43f7-4198-9359-044bed598c66
< 3.6.1
HIGH 7.2 The picu – Online Photo Proofing Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
8bcd5259-2e35-41f6-b269-5b679e4eaab9
< 7.5.50.7212
HIGH 7.2 The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in… wordfence
8ba30cbb-7a20-47aa-bbd6-82fdb27d4705
< 2.0
HIGH 7.2 SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execu… wordfence
8b9fe020-1bec-4891-b2c5-a0a8f6349f0f
< 2.7.7
HIGH 7.2 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
← Prev 370 371 372 373 374 375 376 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top