🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 384 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
660058f0-ccd9-4bb9-9e11-f1e1d1100ef2 HIGH 7.2 The Edit Role functionality in the Display Users WordPress plugin through 2.0.0 had an `id` parameter which is not sanit… wordfence
651fa700-2462-4c9c-bd13-85f3a53a64df
< 2.10.1
HIGH 7.2 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10… wordfence
64f879af-aa8f-4edf-8369-ca032603d529
< 2.4.7.1
HIGH 7.2 The WC Vendors Marketplace plugin for WordPress is vulnerable to SQL Injection via search date parameters in versions up… wordfence
64f07bca-5d04-4b28-b775-f47ed692575e
< 2.7.2
HIGH 7.2 The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions … wordfence
64cf0ae2-8d66-40d1-8bb6-0cab1dafab0d
< 6.1.1
HIGH 7.2 The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and i… wordfence
64be6e85-00c9-49f5-9ee2-08dbe434a848
< 1.6.3
HIGH 7.2 The User Activity Log plugin for WordPress is vulnerable to SQL Injection via several parameters like 'userrole', 'useri… wordfence
64b10a7d-ca11-47ec-ba8a-e2b838fd8a2a HIGH 7.2 The check_order function of The Sorter WordPress plugin through 1.0 uses an `area_id` parameter which is not sanitised, … wordfence
645ad965-4da3-45e4-aa9e-d5f5f8c9f087 HIGH 7.2 The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2c… wordfence
644c8702-08ad-4048-ae91-041f1771f1dc
< 3.3.4
HIGH 7.2 The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserial… wordfence
644a0628-2401-4581-a3a2-463dc2172808
< 8.2
HIGH 7.2 The NEX-Forms LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 8.2 due to insuff… wordfence
643f92e2-b14e-4056-97fc-1c631027c54f
< 6.2.12
HIGH 7.2 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
643b8b82-c4e1-4b81-a7e0-aee0f9270702
< 1.6.1
HIGH 7.2 The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable… wordfence
63f86449-144c-494f-85d8-ce7c8d7d65d3
< 1.6.4
HIGH 7.2 The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead valu… wordfence
63f6ca11-abfb-4f87-a9f7-0321f1de9abe
< 3.10
HIGH 7.2 The Formidable PRO2PDF plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to, and… wordfence
63df43cc-7f84-4316-80fc-b0242b9f454c
< 4.1.0
HIGH 7.2 The Careerfy theme for WordPress is vulnerable to Multiple Cross-Site Scripting in versions up to, and including, 4.0.0 … wordfence
63d49d5e-5562-4803-9e2c-429acd4ca75d
< 5.1.7.7
HIGH 7.2 The Survey Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 5.1.7.7 … wordfence
63af91ef-54ef-4322-9931-a0d29dbd2aec HIGH 7.2 The Email Artillery (MASS EMAIL) plugin for WordPress is vulnerable to various SQL Injection via the 'post_id' and 'emai… wordfence
63af403f-facd-40e3-94bf-12f211d0c7ed HIGH 7.2 The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
63a2d09d-9cb8-47ba-8e40-5b43894552e3
< 3.8.3
HIGH 7.2 The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wfwhois’ parameter… wordfence
63973f61-81f0-4fc8-810c-a15734ff824e
< 2.10.1
HIGH 7.2 The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to an… wordfence
637af5d1-eed3-4216-8d47-e68f83c63f43 HIGH 7.2 The MicroCopy plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and incl… wordfence
635e19ba-da98-459c-ab91-ff969b0812fd
< 6.2.8
HIGH 7.2 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
634d4062-7004-4e89-89a8-323c939aae93
< 1.2.7
HIGH 7.2 The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2… wordfence
6334b02e-ffab-49f9-969b-d015c2babc29
< 5.0.5
HIGH 7.2 The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the 'misc[limit_results]' parameter in ve… wordfence
63323552-354b-44b6-81a4-0b6e82480910 HIGH 7.2 The Simply Poll for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘question’ parameter in versions … wordfence
← Prev 381 382 383 384 385 386 387 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top