πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 380 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
73a1174d-fb5a-4cc0-ada0-dbf1e011619a
< 2.9.3
HIGH 7.2 The Pardakht Delkhah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'submitted_name' paramete… wordfence
739cfb80-da3d-41c8-a299-fd3f0168fb8d HIGH 7.2 The Theme Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
738c6c77-97ef-4e47-9f14-9b73ea425bc2
< 1.8.2
HIGH 7.2 The WordPress Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … wordfence
73809551-b925-4789-b059-b9e60743f693
< 11.4.3
HIGH 7.2 The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
736e0010-f1fc-42c4-8173-b81c5c78e34e
< 3.39
HIGH 7.2 The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
733ae8c8-fa52-418d-b42e-75516906fb66
< 1.7.3
HIGH 7.2 The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_p… wordfence
730d0ff6-9881-4d69-bdaf-924d3d9f522c
< 0.13.2
HIGH 7.2 The IndieBlocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
72fadfa8-4b53-4661-8b6c-69cdb79d3fd7
< 0.9.5
HIGH 7.2 The Customizer Export/Import for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.9.4… wordfence
72b777ac-1870-4588-82fe-da96a784ec81 HIGH 7.2 The Rapid Cache plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, and including, 1.2.3. This … wordfence
726f5063-e904-4512-bbdc-305049219003
< 2.5.0
HIGH 7.2 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio… wordfence
723bce00-e0d7-4802-8dde-7edb90015067
< 2.56.1
HIGH 7.2 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.56 du… wordfence
720be34d-3fe4-4395-a27b-d386f8612ba9
< 1.6
HIGH 7.2 The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… wordfence
71f7733a-1350-4e22-98d8-28be401aee69 HIGH 7.2 The Cleverwise Daily Quotes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and … wordfence
71e2db7c-53a7-4b17-b00a-ce71a00bf546
< 1.24.2
HIGH 7.2 An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the w… wordfence
71d657d4-b326-4655-808a-913bbc9a8d1d
< 0.7.9
HIGH 7.2 The Event List plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜id’ parameter in versions bef… wordfence
7179fe0d-8cfa-4b43-82d6-5523d65ff780
< 3.6.0
HIGH 7.2 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
7148e182-858c-42b1-b9db-9b7a267483e1
< 4.3.45
HIGH 7.2 The WPtouch plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.3.44 via dese… wordfence
712e9341-5bd5-4b9c-891c-048ccec1ba45
< 7.3.24
HIGH 7.2 The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Remote Code Execution i… wordfence
710b8e4e-01de-4e99-8cf2-31abc2419b29
< 1.0.77
HIGH 7.2 The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the… wordfence
70dfe9ca-77d5-4ab9-b251-360f89cc1de1 HIGH 7.2 The Processing Projects plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
70ca7ad4-6848-4f87-ae2d-4b9c2ffa668e
< 4.1.6
HIGH 7.2 The WC Fields Factory for WordPress is vulnerable to SQL Injection via the 'post' parameter in versions up to, and inclu… wordfence
70b18fd0-41e5-4679-a7a5-3dd6eaa29136
< 4.1.17
HIGH 7.2 The Podlove Podcast Publisher plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… wordfence
7082c181-88c7-40f0-b49c-ffc16ab41dcc
< 3.2.5
HIGH 7.2 The Zephyr Project Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
70570837-8c11-4361-96ce-7418106fb006
< 0.10.2
HIGH 7.2 The CodeColorer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.10… wordfence
6fbf8a8f-56f7-42ae-bf96-30a2df6da378
< 1.6.2
HIGH 7.2 The microblog-poster plugin before 1.6.2 for WordPress has SQL Injection via the wp-admin/options-general.php?page=micro… wordfence
← Prev 377 378 379 380 381 382 383 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top