πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 385 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
630516a5-9b73-48f7-9deb-1771b67e76b6
< 4.6.1
HIGH 7.2 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to… wordfence
62fd472e-208b-48db-8f98-3d935c7a678c
< 1.11.17
HIGH 7.2 The Broken Link Checker plugin for WordPress is vulnerable to deserialization of untrusted input via the '$log_file' val… wordfence
62d81e01-9b6e-48e9-b9da-85444a3694e7
< 1.5.7
HIGH 7.2 The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Local File Inclusion in… wordfence
62c46925-8e97-4989-8c2c-56223d6911a2
< 3.1.3
HIGH 7.2 The Advanced Database Cleaner plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in version… wordfence
621ef583-bf99-4b81-ae9c-b4f1c86b86aa
< 3.8.4
HIGH 7.2 The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.… wordfence
6208b87a-496c-404c-ac2e-0cc709cc5a5c HIGH 7.2 The Booking Calendar Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… wordfence
61ce76cc-4895-46f7-b6c9-5bc652b1c73c
< 2.9.2
HIGH 7.2 The Maspik – Spam blacklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
61a93e58-09e2-4a84-b6ad-853f5c8b5a79
< 2.15.4
HIGH 7.2 The Contact Form to Chat Apps | Click to Chat to Order – FormyChat plugin for WordPress is vulnerable to Stored Cross-… wordfence
61a63ba6-129a-4ce2-be40-89c2fa44a670
< 2.1.6
HIGH 7.2 The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cros… wordfence
61a4aea3-88a0-428c-8eba-78c9c3397ac9 HIGH 7.2 The Dokan Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 … wordfence
61a3c83f-1910-4c25-9b79-293c75d06e5a HIGH 7.2 The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in… wordfence
618854b9-fa85-4302-9a38-ae5cbd7c7b9f
< 5.17.3
HIGH 7.2 The Site Reviews WordPress plugin before 5.17.3 does not sanitise and escape the site-reviews parameter of the glsr_acti… wordfence
615beb4d-c2df-4e1a-8e6b-a393c0fe4834
< 3.3.3
HIGH 7.2 The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to arbitrary file upl… wordfence
61584724-fa1d-4823-af3d-d44501dc1f60
< 2.3
HIGH 7.2 The Chat Bubble plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2 … wordfence
60b16755-ac0e-4069-b21a-cca003fecbdc HIGH 7.2 The FlightLog WordPress plugin through 3.0.2 does not sanitise, validate or escape various POST parameters before using … wordfence
60a574c7-47de-4427-8d38-d510ea996f75
< 2.0.7
HIGH 7.2 The Monolit theme for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified parameters in versions up t… wordfence
6077a093-b2ec-4491-a4a7-d70b2858d772
< 4.5.11
HIGH 7.2 The nelio-ab-testing plugin before 4.5.11 for WordPress has SSRF in ajax/iesupport.php. wordfence
5fd495e8-d7e8-4949-b7aa-43ef40063ca1
< 2.3.2
HIGH 7.2 The FooGallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' and 'extension' par… wordfence
5fd449d7-d14e-46d6-851c-828207c3c302
< 3.2.4
HIGH 7.2 The Sprout Clients – CRM and Lead Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
5fb4f619-7fc8-482d-862f-ebb02c3870f8
< 2.2.4
HIGH 7.2 The Property Hive plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
5fb3a347-e124-484b-9eff-281a10c25a5c
< 5.4.2
HIGH 7.2 The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
5f837ba2-64a2-4d8e-8212-b646cb94b0d7
< 1.4.4
HIGH 7.2 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
5f0795f7-6eba-4ff0-b0da-5d2b544adf14
< 0.8.4
HIGH 7.2 The WordPress Importer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … wordfence
5ef2196d-3617-44ba-a8c5-dc1b45408293
< 1.8.0
HIGH 7.2 The Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
5ecc0811-916d-4c60-9047-a09242de36bd
< 3.0.6.2
HIGH 7.2 The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin. wordfence
← Prev 382 383 384 385 386 387 388 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top