🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 383 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68e6ec3a-c5fd-4f63-a9a0-2c9ddfb96e2e
< 2.4.6
HIGH 7.2 The YaySMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and … wordfence
68d4aa8c-70f9-46ba-92ce-fbb427954e86
< 2.0.6
HIGH 7.2 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entr… wordfence
68b202f7-fff1-4056-9b5b-b42b25189706
< 2.5
HIGH 7.2 The Contact Form Integrated With Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
68774d9c-7abc-416d-8ab9-2713a1bad377
< 8.1.9
HIGH 7.2 The teachPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tab’ parameter in versions… wordfence
684253b3-0a96-4822-84c8-bde8ed45f35e
< 3.1.11
HIGH 7.2 The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin … wordfence
68110321-db1a-4634-98cd-0afd3ec933b8
< 8.0.9
HIGH 7.2 The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
67f143a4-2467-48cf-8024-8529ef4ed449
< 3.0
HIGH 7.2 The WPIDE plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6. This allows … wordfence
67b0ddc6-9381-4b18-b623-372a149ffa49
< 3.9
HIGH 7.2 The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenti… wordfence
67aee1ec-44af-4904-8a9b-ecfbb8d3b302
< 1.0.3
HIGH 7.2 The Check & Log Email WordPress plugin before 1.0.3 does not validate and escape the "order" and "orderby" GET parameter… wordfence
67aa489c-5c54-4163-bc32-5d3ac9ba4e33 HIGH 7.2 The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in… wordfence
67631693-ae8a-4532-a9e3-f21b385131a2
< 5.149
HIGH 7.2 Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated … wordfence
6755c415-427e-4572-908c-061ab8f7490a
< 5.9.13.27
HIGH 7.2 The Link Library plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[‘linkid’]" parameter in … wordfence
67176209-443c-4f66-b5a8-1dde2f7f0837
< 1.4.10
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Postie plugin before 1.4.10 for WordPress allows remote attackers to inj… wordfence
6713c2dc-fc7f-4992-bde7-cfb94c383664
< 3.6.9
HIGH 7.2 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
670f4e26-75c9-40cd-8088-2fa4c40f6feb
< 4.0.50
HIGH 7.2 The Brevo for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user_connection_i… wordfence
6709f9b0-0915-4361-9fb0-1f2696e26c2f
< 10.5.5
HIGH 7.2 The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'resend' parameter in versions up to, and inc… wordfence
66f73c3d-3937-4b9f-a7d6-29c249e46b92 HIGH 7.2 The Mapwiz plugin for WordPress is vulnerable to SQL Injection via the 'mid' parameter in versions up to, and including,… wordfence
66da0ad7-18a3-42b9-b59a-5927c6bc836b HIGH 7.2 The Order Your Posts Manually plugin for WordPress is vulnerable to SQL Injection via the 'sortdata' parameter in versio… wordfence
66cd0ed5-070a-4408-9faa-b3d840279f77
< 3.9.0
HIGH 7.2 The WordPress Announcement & Notification Banner Plugin – Bulletin plugin for WordPress is vulnerable to SQL Injection… wordfence
66bc8d9c-1a5f-4dca-b15f-8fdf821dbc6f HIGH 7.2 The WP RSS By Publishers plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in ver… wordfence
66a3abc1-0508-4ce3-952b-7dbf3738879a
< 1.8.97
HIGH 7.2 The "AI Power: Complete AI Pack" plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… wordfence
666b8b39-fab0-4e99-b365-a4ac9f964494 HIGH 7.2 The Symbiostock – Sell Photos Online For Free! plugin for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
66559c2a-1c8d-4861-8151-31972982683d
< 4.6.11
HIGH 7.2 The Ultimate Before After Image Slider & Gallery – BEAF plugin for WordPress is vulnerable to arbitrary file uploads d… wordfence
6635ff4d-cbb4-4e78-9df1-1274eaa737aa
< 7.41
HIGH 7.2 The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
66130071-668e-4692-afd3-5fcc9039f10f
< 1.9.12
HIGH 7.2 The Tutor LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several user profile parameters in v… wordfence
← Prev 380 381 382 383 384 385 386 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top