πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 387 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5b97cb49-abcd-4e54-b78c-0009212ffe38 HIGH 7.2 The Podigee WordPress Quick Publish – now with Gutenberg support! plugin for WordPress is vulnerable to Server-Side Re… wordfence
5b7cc660-b430-4b0f-b2d1-68ba458de8a9
< 7.9.0
HIGH 7.2 TheStylish Cost Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email quote form submis… wordfence
5b783cc6-d79d-43ef-948a-a1953d383ca3
< 5.2.9
HIGH 7.2 The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, a… wordfence
5b0c8edd-b392-4d23-bde3-0521eeedc5a0
< 3.6.9.1
HIGH 7.2 The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3… wordfence
5aeb5f26-32a4-4eba-829d-759e4c92a034
< 1.1.7
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for Wor… wordfence
5a4e144a-3c84-4da3-8fa6-e5fe9c897efe
< 5.8.1
HIGH 7.2 The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 v… wordfence
5a425bf5-de09-4f8c-8766-c9912d337512 HIGH 7.2 The Quote-O-Matic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.5 due to ins… wordfence
5a355a83-fece-4303-af37-8c01d159776a
< 7.0.3
HIGH 7.2 The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi… wordfence
5a17ded3-340d-494f-be7e-2550dab360bc
< 4.3.3
HIGH 7.2 The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized modification of data tha… wordfence
5a081cbd-5cd9-4740-a720-0e4d8904fc4b
< 5.1.1
HIGH 7.2 The Document Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
59ec4bbd-5192-45f8-8cfc-d43858b46901
< 1.8.8
HIGH 7.2 The Redirect 404 Error Page to Homepage or Custom Page with Logs plugin for WordPress is vulnerable to SQL Injection in … wordfence
5954c682-c772-420a-a764-342418c1e71c
< 1.0.9
HIGH 7.2 The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpb_user_name' and 'wpb_user_ema… wordfence
592440ab-60ac-419f-b615-e5617460aea9
< 1.13.1
HIGH 7.2 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
58f9ba6c-1754-4da2-8bfd-b473c7928805
< 2.7
HIGH 7.2 The Editorial Calendar plugin for WordPress is vulnerable to SQL Injection via post start and end dates in all versions … wordfence
58c79117-3a36-4a23-9f3d-067094d13edf
< 5.1.4
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attac… wordfence
58ab78f2-199b-44e8-9213-8c46025b55fb HIGH 7.2 The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
5890c0f1-f549-4076-9d57-74f5eaffdcb3
< 2.9.31
HIGH 7.2 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in v… wordfence
5887cf20-dc15-45be-8573-e893d5367995
< 1.7.6
HIGH 7.2 The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and Java… wordfence
58492dbb-b9e0-4477-b85d-ace06dba954c
< 1.5.103
HIGH 7.2 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command inj… wordfence
57ebde8e-dd1f-4a33-9c7b-6c9e2060d1ef HIGH 7.2 The Cube Slider WordPress plugin through 1.2 does not sanitise and escape the idslider parameter before using it in vari… wordfence
57969f04-4758-4e62-8fbb-7b14629321d6
< 5.2.11
HIGH 7.2 The WordPress Zero Spam WordPress plugin before 5.2.11 does not properly sanitise and escape the order and orderby param… wordfence
572689c6-d7d6-46c3-9e96-b9185337e8ce
< 6.3.1
HIGH 7.2 The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… wordfence
56e8c682-f19e-4e2c-91a3-e866d44a98fb
< 5.2.2.6
HIGH 7.2 The Survey Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
56e6c5c3-fa8b-4ec6-b1aa-88a0f63c5eab
< 1.1.46
HIGH 7.2 The RSFirewall! plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.… wordfence
56e0565d-0720-4d85-b23e-49e807e8cf03 HIGH 7.2 The Bulk Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation… wordfence
← Prev 384 385 386 387 388 389 390 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top