🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 381 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6fb07b77-3d8a-42c6-b62b-9567226333c5 HIGH 7.2 The WordPress & WooCommerce Scraper Plugin, Import Data from Any WebSite. plugin for WordPress is vulnerable to Server-S… wordfence
6f781533-b633-4452-95bd-c32ed0de2ea9
< 1.8
HIGH 7.2 The Simple Membership WP user Import plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter… wordfence
6f4ea8c9-4e4b-41a7-a2ca-826cbd7d8c23
< 250424
HIGH 7.2 The s2Member plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 250419 via the… wordfence
6ef8bf27-3b20-4d90-8d29-b9713d2c41d6
< 1.7.31
HIGH 7.2 The Contact Form Maker plugin for WordPress is vulnerable to blind SQL Injection via the ‘form_id’ parameter in vers… wordfence
6ee675dd-5b43-439f-9717-6c531e9bf066
< 5.3.3
HIGH 7.2 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' par… wordfence
6ecd0fa6-4fdb-4780-9560-0bb126800685
< 2.5.8
HIGH 7.2 The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, an… wordfence
6eb19d3a-b180-4141-8c9b-bec436eeea6b
< 2.0.5
HIGH 7.2 The Ocean Extra plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.4 via … wordfence
6e8d9f73-8460-4bcb-a9f8-08eb058bcc09
< 3.4.2
HIGH 7.2 The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include… wordfence
6e8646f0-8bd1-4cfd-85bb-86a054ab297f
< 1.2.13
HIGH 7.2 The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0]… wordfence
6e81cbe3-1310-4f6f-ae42-8d09b321657a
< 2.8
HIGH 7.2 Redirection version 2.7.3 contains a ACE via file inclusion vulnerability in Pass-through mode that can result in allows… wordfence
6e349cae-a996-4a32-807a-a98ebcb01edd
< 1.5.9
HIGH 7.2 The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable … wordfence
6e15a7b0-2b0e-468d-a245-cec2ed77d73b HIGH 7.2 The Menu Item Visibility Control plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and incl… wordfence
6e0384c0-9b34-4af8-af86-75ef1e8d933b
< 21.0426
HIGH 7.2 The ReDi Restaurant Reservation WordPress plugin before 21.0426 provides the functionality to let users make restaurant … wordfence
6dda19a3-277e-49e6-b6fb-c4dd2df4aa38
< 3.5.4
HIGH 7.2 The AliExpress Dropshipping Plugin for WooCommerce – AliNext plugin for WordPress is vulnerable to Open Redirect in al… wordfence
6dc69491-0f40-4bab-9215-b25f72110e26
< 1.3.19
HIGH 7.2 The AIO Forms – Craft Complex Forms Easily plugin for WordPress is vulnerable to arbitrary file uploads due to missing… wordfence
6da7046e-2717-4a3c-bba9-88f27de29ede
< 2.5.2
HIGH 7.2 The PublishPress Capabilities plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… wordfence
6d5ef392-6aea-4fab-95ce-d36d1cd17026
< 3.1.0
HIGH 7.2 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary… wordfence
6d374ccc-74f2-4064-8801-4adfcb200eb2 HIGH 7.2 The EP4 More Embeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi… wordfence
6d2aa302-aaab-4bf1-9a79-144290b967de
< 2.6
HIGH 7.2 The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param… wordfence
6d1b255f-d775-4bd5-892e-42bf82dd5632
< 2.13.4
HIGH 7.2 The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic… wordfence
6d0d4d06-95f7-4ecd-84a7-2d3996b16b1c HIGH 7.2 The WP Mega Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.2 via … wordfence
6ce177e7-a009-4b5d-ba4c-971de5496dca
< 4.6.0
HIGH 7.2 The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin fo… wordfence
6cd9cbba-10b0-4fb0-ad49-4593a307a615
< 9.2
HIGH 7.2 The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logg… wordfence
6cc83edb-44ce-4dc9-8cba-734775a94779
< 3.3.1.0
HIGH 7.2 The fetch_product_ajax functionality in the Product Feed on WooCommerce WordPress plugin before 3.3.1.0 uses a `product_… wordfence
6cbaa1eb-5e16-4b39-b7fc-9ed8967274c8
< 4.1.4
HIGH 7.2 The Personal Portfolio Resume Theme | Kerge theme for WordPress is vulnerable to Server-Side Request Forgery in all vers… wordfence
← Prev 378 379 380 381 382 383 384 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top