πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 382 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6c98430d-0881-4f45-b934-c393739ef71c
< 2.2.8
HIGH 7.2 The Cryptocurrency Donation Box – Bitcoin & Crypto Donations plugin for WordPress is vulnerable to SQL Injection via s… wordfence
6c8ed84e-3504-42e3-821d-794198d7adda
< 6.8.8.1
HIGH 7.2 The Auto Affiliate Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
6c6bc841-a168-475e-941b-a877a3a401f9
< 8.14.1
HIGH 7.2 The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to arbitrary file uploads due to … wordfence
6c5db375-e865-47ba-a3dd-462c55d066fd
< 4.19
HIGH 7.2 The eForm - WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
6c26270b-a0a7-4877-aa66-bffe260003df
< 2.11.10
HIGH 7.2 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜name’ parameter in… wordfence
6c18ab1b-02f1-4679-8cff-679d98dc9f4a
< 3.1.24
HIGH 7.2 The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in … wordfence
6c12bcf6-6297-457a-a807-28f5dbacb0eb
< 1.5.3
HIGH 7.2 The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in al… wordfence
6bf3591e-96a9-43ed-9a37-cd3d8f9a88ac HIGH 7.2 The Local Delivery Drivers for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions… wordfence
6bd92b9d-b4b7-4106-bee4-d12b0479d0c5
< 1.1.13
HIGH 7.2 The S2W – Import Shopify to WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, … wordfence
6b89b6ac-aa00-4ba6-a1e3-382e7b630fc8
< 1.8.2
HIGH 7.2 An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. It allows XSS. wordfence
6b30089a-2267-47b9-b0a5-d6eeadfe51d2
< 3.9.15
HIGH 7.2 The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in … wordfence
6b1da345-ddbb-48ad-b0c1-bb0cb3b0fc69
< 3.2.6
HIGH 7.2 The NinjaScanner – Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… wordfence
6a587455-fd93-4f28-902a-4d84d1253e64
< 9.2.3
HIGH 7.2 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
6a24378f-cf76-4937-99e5-a5fb2d206859
< 4.0.18
HIGH 7.2 The Brevo for WooCommerce plugin for WordPress is vulnerable to arbitrary file download and deletion in all versions up … wordfence
6a1de2d6-d4a0-4770-be38-9bd09b2243b7
< 1.11.0
HIGH 7.2 The Simple Newsletter Plugin – Noptin plugin for WordPress is vulnerable to CSV Injection in all versions up to, and i… wordfence
6a0a0395-c193-4686-ba97-73fdd40d3048
< 1.3.5.3
HIGH 7.2 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in… wordfence
69fed134-0978-44ea-a8d1-cb836e07d546
< 2.3.2
HIGH 7.2 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
69f861bf-933f-4413-a5c0-fd39ee78e594
< 12.6.7
HIGH 7.2 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP spoofing in versions up to, a… wordfence
69ed990e-6c40-49d5-859c-768a5a6a803f HIGH 7.2 A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list… wordfence
69a464f4-c357-446f-a5b8-0919d9af56c9
< 3.25.1
HIGH 7.2 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms … wordfence
6998cf4c-6086-402b-a95f-ee6a4980dffb
< 4.2
HIGH 7.2 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings set through a REST ro… wordfence
697f3432-63b7-42d6-b188-812165cd2020
< 3.5.13
HIGH 7.2 The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… wordfence
69618c44-5298-4b03-a63a-76f195206c8b
< 0.6.5
HIGH 7.2 The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in… wordfence
694d0b49-c4dd-40f0-99c9-5eb8c3c08ba9
< 2.4.44
HIGH 7.2 The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in… wordfence
69007bd5-cbfa-47f1-acef-29ff493959f0
< 8.6.1
HIGH 7.2 The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up… wordfence
← Prev 379 380 381 382 383 384 385 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top