ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 386 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5e911b0a-a236-4df3-b997-3631412a1b55
< 6.1.18
HIGH 7.2 The Fluent Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `fluentform_step_form_sav… wordfence
5e83b0ff-3628-47d7-92d0-429af92067bd
< 4.23.90
HIGH 7.2 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
5e6218e5-84d9-4180-8275-7da24c554c72
< 3.3.0
HIGH 7.2 The Unify plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to and includ… wordfence
5e49afbd-9038-4d1d-b545-4dc86bb1be61
< 1.1.1
HIGH 7.2 The Video Metabox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘video_url’ parameter in… wordfence
5e493f01-95db-48ba-8daf-d7ff69df29bf
< 2.2.1
HIGH 7.2 The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all ver… wordfence
5e441699-4c78-4277-8ac1-f33b810e78cb
< 7.34
HIGH 7.2 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
5e3bcd70-d19c-4c0f-80d0-a69e2ab947d2
< 13.1.6
HIGH 7.2 The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o… wordfence
5de24a9e-0af3-44d7-af0b-06689a3e3bc5
< 2.5.4
HIGH 7.2 The Booking and Rental Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
5db3fd96-28c5-431e-9e0d-2aaa57d9dce3
< 1.5.2
HIGH 7.2 The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in al… wordfence
5d479a7a-52a6-48bd-8216-935e22ddb3ed
< 3.15.1
HIGH 7.2 The Profile Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
5d350095-125a-4445-89c1-bce437e4098c
< 7.3.12
HIGH 7.2 The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… wordfence
5d2e0fc0-072b-4640-b538-61356fefa0d8 HIGH 7.2 The Ultimate Auction Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
5d281333-d9af-4eb7-bc5c-ea7ceeddac03
< 3.6.8
HIGH 7.2 The plugin WP All Import is vulnerable to arbitrary file uploads due to missing file type validation via the wp_all_impo… wordfence
5d266060-2491-4b0f-8961-955ed6ee2451
< 1.5.3.6
HIGH 7.2 The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress… wordfence
5d1fa835-1888-4758-97bf-f582e8ff3a04 HIGH 7.2 The Zarinpal Paid Download plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
5cbf597e-7a2f-416c-8969-3679b487f57a
< 6.2.1
HIGH 7.2 The WooCommerce plugin for WordPress is vulnerable to path traversal via the 'file_url' parameter found in the importers… wordfence
5cba9501-2eb1-4702-889c-d0f4777e72e9
< 6.9.8
HIGH 7.2 The Super Store Finder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and incl… wordfence
5c8aa2c9-d925-460c-ad91-6fd417be3fb1
< 1.0.62
HIGH 7.2 The Captcha.eu plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1… wordfence
5c6ac166-d8ad-4ee0-b637-91816cb41eca
< 2.3.6
HIGH 7.2 The Foxiz theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3.5. … wordfence
5bfedb93-76e6-4d3f-bf44-1e6d8947c7d1
< 4.5
HIGH 7.2 The WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-a… wordfence
5bf0267d-b84f-4ad2-8bb3-cc2aa4996af1
< 1.0.7
HIGH 7.2 The PostmagThemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and includ… wordfence
5bd6d250-b1c2-4c14-906d-6507ce39520f
< 2.3.3
HIGH 7.2 The Social Slider Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includin… wordfence
5bc531a3-e246-4f2e-8657-bbdfb91dbf39
< 8.28.0
HIGH 7.2 The Smart Manager – WooCommerce Bulk Edit Products, Orders, Coupons, Any WordPress Post Type (Advanced) plugin for Wor… wordfence
5ba48e88-6e32-428f-9592-bd955e176765 HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
5ba22ed2-4cc2-4e1e-a475-a697a8bb697d
< 2.2.1
HIGH 7.2 The Side Menu Lite – add sticky fixed buttons WordPress plugin before 2.2.1 does not properly sanitize input values fr… wordfence
← Prev 383 384 385 386 387 388 389 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top