πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 377 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7d7b2c79-c4f7-4611-a22a-685d4421a4ab
< 1.0.7
HIGH 7.2 The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi… wordfence
7d55c2b8-c05e-419b-8c2d-8c07c8655c17
< 1.0.25
HIGH 7.2 The Contact Form Builder plugin for WordPress is vulnerable to blind SQL Injection via the 'order_by' parameter in versi… wordfence
7d54a72c-8fd5-418f-8109-078d0d75138d
< 2.3.11
HIGH 7.2 The HollerBox β€” Fast & Effective Popups & Lead-Generation plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
7ce4050e-3563-4aac-b1c1-16cba20e1e86
< 8.9.3
HIGH 7.2 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting in… wordfence
7cda6aad-36e1-45c7-af46-a7b90bb2d339
< 1.12.21
HIGH 7.2 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
7cb9cc24-920f-402d-8a87-8b6c6a1b1a51
< 5.0.0
HIGH 7.2 The WP Data Access WordPress plugin before 5.0.0 does not properly sanitise and escape the backup_date parameter before … wordfence
7c94f47a-4a1b-434c-b446-0ff1a7290e16
< 1.2.5
HIGH 7.2 The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect ru… wordfence
7c500c5b-04b9-47d7-9296-dd5378cd5ab0 HIGH 7.2 The Event Banner WordPress plugin through 1.3 does not verify the uploaded image file, allowing admin accounts to upload… wordfence
7c4fc322-1f62-48e3-8177-4894c947624b
< 1.7.6
HIGH 7.2 The Shared Files – Advanced File Sharing & Download Manager with Frontend Uploads plugin for WordPress is vulnerable t… wordfence
7c3f7108-eb32-425a-a705-4f032e7da6b0
< 1.0.3
HIGH 7.2 The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t… wordfence
7c1c24cc-9388-4d91-8dc6-c67d3420cc94
< 1.0.64
HIGH 7.2 The 10WebMapBuilder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Plugin Settings Change in vers… wordfence
7bff8172-b879-40b0-a229-a54787baa38a HIGH 7.2 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' par… wordfence
7bf4fe42-435b-449e-bb8c-57cef3b93471 HIGH 7.2 The Conditional Payment Methods for WooCommerce plugin for WordPress is vulnerable to SQL Injection via an unknown param… wordfence
7bde6d5c-85a1-47d4-a017-23ce69a3bb5e
< 2.5.0
HIGH 7.2 The Gutenverse Form – Contact Form Builder, Block Form & Booking Form plugin for WordPress is vulnerable to Stored Cro… wordfence
7bd89bd9-4f99-4828-bacc-15d2cfe13066
< 2.9.29
HIGH 7.2 The Ninja Forms Contact Form plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including… wordfence
7bc2d608-637c-4098-8ac9-07997df3138a
< 3.4.2
HIGH 7.2 The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all ve… wordfence
7b4f63af-cb43-4287-8fdd-0ff1df70c6d6
< 3.2.2
HIGH 7.2 The Rencontre – Dating Site plugin for WordPress is vulnerable to SQL Injection via the 'activ' parameter in versions … wordfence
7b452283-9f0d-469b-b1b8-4bd253f9ea1d
< 1.7.6
HIGH 7.2 The URL Shortify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referrer header in versions u… wordfence
7b384246-7f6f-489f-897d-53f1b1ae51c3
< 8.10.8
HIGH 7.2 The Advanced IP Blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
7b2ebbb5-0590-4e4a-a9b6-abc80b220d18
< 4.6.60
HIGH 7.2 The Tradetracker-Store plugin for WordPress is vulnerable to generic SQL Injection via the β€˜test’ parameter in versi… wordfence
7b1019ef-02fd-4220-9dcf-e7776d40b3e7
< 10.9.3.2
HIGH 7.2 The Thrive Visual Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
7b049489-50b1-4199-9e66-0db5d745b968 HIGH 7.2 The Lawyer Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
7ae0710a-8c9b-41b0-860f-ae79b7ed1ee4
< 3.9.12
HIGH 7.2 The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up … wordfence
7adf3335-ed13-43f4-a5f3-05e89be44d2d
< 13.2.5
HIGH 7.2 The Widgets for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … wordfence
7adebd83-8186-402a-8327-c7f9c009ed62 HIGH 7.2 The Simple Schools Staff Directory WordPress plugin through 1.1 does not validate uploaded logo pictures to ensure that … wordfence
← Prev 374 375 376 377 378 379 380 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top