🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 378 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7a9e81bc-0258-4daf-b583-eeec6bfb9b48
< 1.4.21
HIGH 7.2 The Blog Floating Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
7a600f11-03c3-4777-b1fe-212b085bacba HIGH 7.2 The SimpleMap Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
7a480473-ceae-4621-9b13-e0f0543c57e3 HIGH 7.2 The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ pa… wordfence
7a0a9ff8-ed93-4de9-ba49-730b2253c6a4
< 1.1.9
HIGH 7.2 The WP Test Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to… wordfence
79d91300-b6b7-4c3f-89b1-c48b9e47c415 HIGH 7.2 The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
79d4d776-411e-45ec-aff7-23453e686bf2
< 2.1.1
HIGH 7.2 The StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart plugin for … wordfence
79a41b84-2e19-46eb-9f6b-5155da0b15cc
< 1.15.1
HIGH 7.2 The Google Tag Manager for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $_SERVER[… wordfence
799087f0-d9da-4061-a29f-5bd634147b2e
< 3.2.2
HIGH 7.2 The Search & Replace plugin for WordPress is vulnerable to SQL Injection via the select_tables parameter in all version … wordfence
795c1fd6-137b-4414-8d6b-30053bfb5924
< 1.7.17
HIGH 7.2 The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a… wordfence
79289ad7-f289-4472-973d-d0ec2996c5c5
< 2.8.3
HIGH 7.2 The Visual Form Builder plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2.… wordfence
7927edf2-b092-4b56-83aa-038f99ea658e
< 4.3.0
HIGH 7.2 The WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels plugin for WordPress is vulnerable to ar… wordfence
791ef534-3191-4788-beb7-f5a0e83ffc4b
< 3.9.6
HIGH 7.2 The tagDiv Cloud Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
791a7063-fb1e-4147-b253-8baf889307c6
< 4.4.3.4
HIGH 7.2 The MainWP plugin for WordPress is vulnerable to SQL Injection via the 'tags' parameter in versions up to, and including… wordfence
790a2c64-b358-41ed-be17-f2b99d294617 HIGH 7.2 The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including… wordfence
78ec499e-5edd-4f11-9090-f79868864fee
< 2.8.12
HIGH 7.2 The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all vers… wordfence
78bb5e18-5535-4cee-a38b-e38802059ef7
< 2.0.6
HIGH 7.2 The Paid Memberships Pro plugin for WordPress is vulnerable to an open redirect vulnerability in versions up to, and inc… wordfence
78b8e9f7-969f-42fa-8544-0ac4089aa35b HIGH 7.2 The Omnichannel for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
78ac91af-4d71-43f4-b9fc-cf5e6874e7de
< 1.9
HIGH 7.2 The SMTP for Amazon SES – YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in … wordfence
788e1c5c-67a9-4b06-a2cf-15c980e83618
< 1.2.2
HIGH 7.2 The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste… wordfence
784e3b21-08f5-4cbc-b726-fe60e1faefea
< 1.4.96
HIGH 7.2 The "Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin" plugin for WordPress is… wordfence
781c3b84-df80-470e-8bcb-3305a8bbb64a HIGH 7.2 The ProjectList plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
7804c518-d0d6-474e-9a56-daf6a6eecccc HIGH 7.2 The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter. wordfence
77582ba1-98b0-41c1-a665-e49704313823
< 2.3.3
HIGH 7.2 The Translate Multilingual sites WordPress plugin is vulnerable to an authenticated SQL injection in versions up to, and… wordfence
77537eb8-1c84-4702-aba1-727b0de1c3e1
< 0.3.2
HIGH 7.2 The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up t… wordfence
77328e35-b6e6-40eb-8c85-896d54419aef
< 4.4.11
HIGH 7.2 The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title… wordfence
← Prev 375 376 377 378 379 380 381 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top