ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 388 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
568aa6d6-10a1-4653-ab95-845faf005b8e HIGH 7.2 The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, a… wordfence
5686bc0f-efe7-4268-a6e1-bec939504ab4
< 1.1.4
HIGH 7.2 The Hostel Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'contact_name' and 'contact_… wordfence
565b4026-0807-449d-a78e-798da53c3f52
< 3.5.1.11
HIGH 7.2 The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 … wordfence
56439ae3-bdbc-4c57-abf4-8c94dea8c6f5
< 3.2.0
HIGH 7.2 The "Shortcode Addons- with Visual Composer, Divi, Beaver Builder and Elementor Extension" plugin for WordPress is vulne… wordfence
55ed6e73-4e9a-4201-91c2-0f7153ec1cb7
< 1.5.3
HIGH 7.2 The WP User Merger plugin for WordPress is vulnerable to generic SQL Injection via 'user_id' parameter (in function 'wpu… wordfence
55b3e2dc-dc4f-408b-bbc6-da72ed5ad245
< 2.4.9
HIGH 7.2 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file uploads due to insufficie… wordfence
559a92e0-609e-415f-aab3-649a185eb431
< 1.2.7
HIGH 7.2 The Ninja Forms Google Sheet Connector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions … wordfence
5536a6fd-3df0-4595-b71d-b8bcdbb64a9f
< 1.43
HIGH 7.2 Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers… wordfence
54c94de4-59b4-4f0b-85db-2074a41d04f8 HIGH 7.2 The Who Hit The Page – Hit Counter plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
54bee415-b1f4-4176-a317-3e2a651298fb
< 4.1.2
HIGH 7.2 The LWS Optimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1… wordfence
54bdacd9-49e4-4f45-99bb-baa9eba97ecf
< 1.7.9.2
HIGH 7.2 The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrator… wordfence
54acaeeb-bc39-441a-b0bc-6005dc452d27
< 3.4.6
HIGH 7.2 The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vuln… wordfence
54897968-55fe-4542-bac8-190b29f68b0d
< 9.1.8
HIGH 7.2 The NEX-Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.1.7 … wordfence
542a4079-b1a2-49bc-9ddd-ba7978c9992e
< 2.10.2
HIGH 7.2 The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_… wordfence
541fbcd6-353f-4ef7-88f1-fc81a6b73e04
< 3.1.8
HIGH 7.2 The Gift Up Gift Cards for WordPress and WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery i… wordfence
5414259c-339d-41fe-a0dc-4d4e4d966e15
< 2.1.1
HIGH 7.2 The Debug Bar ElasticPress plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘query’ parameter in v… wordfence
53fb54bc-6eaa-4e99-a41c-e59a9bae81e5 HIGH 7.2 The Glossary by WPPedia – Best Glossary plugin for WordPress plugin for WordPress is vulnerable to PHP Object Injectio… wordfence
53a28cee-fda0-43eb-8012-5059bb061694 HIGH 7.2 The wp-stats-dashboard plugin through 2.9.4 for WordPress has admin/graph_trend.php type SQL injection. wordfence
539cd606-1884-48df-beae-f5686a4e2400 HIGH 7.2 The multimedial images plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0b due to… wordfence
5351212d-122e-4356-b6d1-86bd0cd2cc68
< 3.15.0.8
HIGH 7.2 The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
5350e519-3fa5-4463-b7b4-12bbe6fd5591
< 3.2.5
HIGH 7.2 Cross-site scripting (XSS) vulnerability in inc/admin/content.php in the Better WP Security (iThemes) plugin before 3.2.… wordfence
534e6f80-b162-4a4b-a979-72ed63a8b0dc
< 2.2.1
HIGH 7.2 The Paytm Payment Donation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in the i… wordfence
5340204a-8a4f-4e23-82a1-c228b884c34a
< 3.6.4
HIGH 7.2 The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which coul… wordfence
5339024c-afcc-4fdc-a14b-056068ff2f5b
< 6.79
HIGH 7.2 The CleanTalk Anti-Spam. Spam Firewall & Bot protection plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
5331c7cc-3854-4975-9f28-e9b0d6407227
< 2.1.1
HIGH 7.2 The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to authorization bypa… wordfence
← Prev 385 386 387 388 389 390 391 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top