πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 376 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
824c5a51-68cc-4d03-87b5-2cb90763334e
< 2.3.3
HIGH 7.2 The Ocean Modal Window plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including,… wordfence
8230d5f8-01d9-465a-8a43-e9852248bb3d
< 1.15.36
HIGH 7.2 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc… wordfence
821462d6-970e-4e3e-b91d-e7153296ba9f
< 7.6.3
HIGH 7.2 The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to… wordfence
81fa4987-d019-4d0c-a002-eceef956161e
< 2.2.24
HIGH 7.2 The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the 'selected', 'post_type' parameters in versi… wordfence
81f993ec-9a7f-4e55-bc88-ea832ce49773
< 0.99
HIGH 7.2 An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page temp… wordfence
816fb31d-0b06-4a86-9534-81457903002e
< 1.1.2
HIGH 7.2 The Design Comuni Italia theme for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.1.1 due to insuff… wordfence
8139bc38-2b78-4b02-bce8-c28dd258ee49
< 1.4.4
HIGH 7.2 The Adminer plugin for WordPress is vulnerable to Cross-Site Scripting in the altar table versions up to, and including,… wordfence
80d976f3-cf78-498e-a3c3-a88624426414 HIGH 7.2 The Advanced XML Reader plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and… wordfence
80d3ceea-a7c4-4113-80a8-c19a580f2c4f
< 2.3.5
HIGH 7.2 The Mang Board WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
80848de3-a772-4078-aa04-29e1d6e3ff73
< 7.1.0
HIGH 7.2 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… wordfence
804cfd49-267e-4e84-ab01-f1b63a8332a5 HIGH 7.2 The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player plugin for WordPress is vulnerable to Server-Si… wordfence
804b42a0-1cea-4f68-bd4a-d292a9f23fbe
< 1.16.7
HIGH 7.2 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Re… wordfence
80153f79-0fb0-458b-a39b-c4cd726546f9
< 1.1.11
HIGH 7.2 The Abandoned Cart Recovery for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version… wordfence
7fdc5bc4-b5eb-4826-a7db-323c85e683a0
< 5.4.8
HIGH 7.2 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
7e89b33e-fc3c-44e9-823c-e9349147acf5
< 1.1
HIGH 7.2 The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privil… wordfence
7e898e40-2cc3-4b5a-833b-899e9c9f26d3
< 2.0.1
HIGH 7.2 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and… wordfence
7e8911a3-ce0f-420c-bf2a-1c2929d01cef
< 2.8.8
HIGH 7.2 The POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress plugin for WordPress… wordfence
7e7b24b5-13e4-4164-8462-fd81b1033f2c
< 2.51
HIGH 7.2 Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise … wordfence
7e78d678-1560-401d-a409-21207332e062 HIGH 7.2 The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing a high p… wordfence
7e6a0bf9-4767-4d4c-9a1e-adcb3c7719d9
< 4.3.1
HIGH 7.2 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
7e3ad5fd-e190-48c8-864f-11cc7342080a
< 1.6.11.0
HIGH 7.2 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
7e092d67-ab81-4366-824c-cfb240ba3042
< 4.35.0
HIGH 7.2 The Web Push Notifications – Webpushr plugin for WordPress is vulnerable to unauthorized modification of data due to a… wordfence
7dff5a77-a5d6-4aba-bf39-aa110a4f4996
< 3.7.8
HIGH 7.2 Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to i… wordfence
7d947023-60d3-4bd8-b45d-e1663326d6c1
< 1.8.6
HIGH 7.2 The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions … wordfence
7d81bc83-9e36-4fe9-8274-c65d17905f6e
< 1.1.1
HIGH 7.2 The Grimag theme for WordPress is vulnerable to Open Redirect in versions up to, and including, 1.1.0 via the 'go.php' f… wordfence
← Prev 373 374 375 376 377 378 379 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top