πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 375 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
86f7eb83-8483-4c6b-993e-ce11084241e8
< 3.1.40
HIGH 7.2 The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue plugin for WordPress is vulnerable to Cross-Site… wordfence
86ee1acb-6f0c-40e6-80a0-fc93b61c1602
< 1.1.2
HIGH 7.2 The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, … wordfence
86df2310-aad5-48ef-ad31-1b5dbcbccb44
< 3.15.0.3
HIGH 7.2 The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
86c1b729-e8fe-46e8-8d57-c6312087c6b2
< 1.1.2
HIGH 7.2 The Under Construction, Coming Soon & Maintenance Mode Plugin for WordPress is vulnerable to Server Side Request Forgery… wordfence
869e57f8-7524-497a-8d24-bb9f2ee3898b HIGH 7.2 The AP Pricing Tables Lite plugin for WordPress is vulnerable to SQL Injection via the 'table_id' parameter passed throu… wordfence
868c178f-9389-4da0-8ebb-ee94f025039f
< 2.1.0
HIGH 7.2 The Cart Abandonment Recovery for WooCommerce – Recover Lost Sales with Automated Emails plugin for WordPress is vulne… wordfence
86600d3e-11db-4a94-adc6-7b02089c70fb
< 1.1.4
HIGH 7.2 The Better WishList API plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… wordfence
8641dec6-a754-446a-a011-9b4b0fc252c0
< 4.2.0
HIGH 7.2 The Speed Booster Pack PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_u… wordfence
863acd01-c9fa-44d5-afc4-1a6baefcf709
< 3.6.3
HIGH 7.2 The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plug… wordfence
86121a7c-906b-405d-bb4c-19982eeaec3b
< 2.18.1
HIGH 7.2 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
85fdd63e-a683-4bed-ac1a-3d8b8cbd67d2
< 9.18
HIGH 7.2 The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
8566a5ad-df8a-4843-82c9-05da9d44582d
< 2.0
HIGH 7.2 The Easy Quiz Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wp_quiz' parameter in ver… wordfence
855a06dc-5e92-4354-b4ab-456a224e2903
< 11.1.0
HIGH 7.2 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
850590a0-2bbc-45ff-8538-4d11b587383f
< 3.8.10.1
HIGH 7.2 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.10… wordfence
84fb53bb-cced-4585-bb0d-c09d89293300
< 4.1.4
HIGH 7.2 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
84dcc345-7075-45e8-b353-6ec72ffecb8d
< 1.1.1
HIGH 7.2 The Active Products Tables for WooCommerce. Use constructor to create tablesΒ  plugin for WordPress is vulnerable to Sto… wordfence
848b9c6d-e0db-43ad-ac6d-3674435339dd
< 8.1.3
HIGH 7.2 The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions… wordfence
840b2211-7061-4ab9-976f-2cb09a429eb5 HIGH 7.2 The Appointify plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all v… wordfence
83bf3f3d-49f1-473a-a9ee-d78eb8981ad3 HIGH 7.2 The CSV Me plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the … wordfence
839b68e6-0462-4f88-ac13-ed4b69887d6b
< 2.7.3
HIGH 7.2 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.2 due to insuffi… wordfence
8384d80b-6fe6-45ba-b28a-a0884280409a
< 10.7.1
HIGH 7.2 The Easy Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 10.7.1… wordfence
835f6efd-636e-411f-97a1-fa14b9a629b3
< 9.7.5
HIGH 7.2 The Quick Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'yourname' parameter i… wordfence
82ff0450-5a76-453e-bb27-45c11fff7419
< 4.16.5.1
HIGH 7.2 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
82f5456e-f2cc-47f3-a957-f85d26834031
< 3.9.16
HIGH 7.2 The FormCraft plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.9.15… wordfence
82f0b4c3-d0fb-4f3c-b8aa-c5f5ce6c3f16
< 11.1.3
HIGH 7.2 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
← Prev 372 373 374 375 376 377 378 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top