πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 379 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
772c9330-97d5-42d5-a49c-d9a86a14b235
< 2.8.11
HIGH 7.2 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
7721c49c-82e3-493d-9f53-187d7737ae93
< 1.6.2
HIGH 7.2 The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
76fb0ffd-32c1-483d-ae95-9bc70ba1c064
< 3.9.1
HIGH 7.2 The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the `tracking_pro… wordfence
76e468fe-437e-4ca7-9485-b97990af2d01 HIGH 7.2 The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
76c5559d-f9dd-43cf-8c8e-07188b4edf7f
< 4.7.4
HIGH 7.2 The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable t… wordfence
76c468cb-8ad6-4b62-8de5-dc8efd4b8e61
< 2.7.9.4
HIGH 7.2 The Groundhogg plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.9.3 due to ins… wordfence
76734ad0-e8e8-4106-858b-0f77d2ac17ec
< 2.2.0
HIGH 7.2 The Donation Block For PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'donner_name' pa… wordfence
7659ac9b-fa4e-4cb7-9887-38aa65b6d1c3
< 1.5
HIGH 7.2 The tagDiv Opt-In Builder plugin is vulnerable to Blind SQL Injection via the 'subscriptionCouponId' parameter via the '… wordfence
762fe5b1-6290-432f-904f-08dcf966e304 HIGH 7.2 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Sc… wordfence
762c45a4-e699-428c-ae0a-a5b6498e15c6
< 8.0.1
HIGH 7.2 The Hurrakify plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.… wordfence
75f01eb4-5d53-441d-9bee-e97857dadaf9
< 3.1.7
HIGH 7.2 The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'agents[]' parameter used in the set_add_ag… wordfence
75e9b879-a080-46b3-b97d-5e18faf863c7 HIGH 7.2 The CSV Mass Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
75e02357-391a-4f21-9024-ca4a0ea24d50
< 1.5.2
HIGH 7.2 The Easy WP SMTP plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.5.1 pos… wordfence
758e23e4-72e6-4dc1-94f9-d02b75bb9857
< 1.1.17
HIGH 7.2 The Ultimate Maps by Supsystic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1… wordfence
75388e1c-e1ad-4f65-9f5a-a5da8fd4ecc0
< 1.24.0
HIGH 7.2 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPres… wordfence
75324bf1-a00e-4da7-8d42-d224c39ceb79
< 2.11.2
HIGH 7.2 The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via… wordfence
74aad4b3-3e35-4abe-ba26-48334da0face
< 3.2.55
HIGH 7.2 The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
74831bf8-0a30-4758-bfe6-5a5b4ee7ec24
< 1.3.7
HIGH 7.2 The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and… wordfence
743f6e8b-4694-4d6a-94db-093162ba94b3
< 2.10.7
HIGH 7.2 The 'Shortcodes and extra features for Phlox theme' plugin for WordPress is vulnerable to PHP Object Injection in versio… wordfence
742d3b59-e533-4398-9c8c-4aa1e17129f6
< 3.0.12
HIGH 7.2 The AdForest Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
73f12f22-c0a4-4010-9634-ce7308254028
< 1.0.47
HIGH 7.2 The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the l… wordfence
73e4b097-a33b-47c4-8899-f14e2858a1d0
< 2.7.1
HIGH 7.2 The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' parameter in the 'ad… wordfence
73b6b22a-4699-4307-8a03-148dd9e95d36
< 2.13.10
HIGH 7.2 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
73ab9f95-05cc-47fc-bfcb-1787f6f80789
< 3.2.7
HIGH 7.2 The Read More & Accordion plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3… wordfence
73a9580c-d8fd-4720-8ea7-3308dc71b4d4
< 15.1.4
HIGH 7.2 The cformsII plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 15.1.3 … wordfence
← Prev 376 377 378 379 380 381 382 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top