πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 389 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
53124575-ca94-47d6-b0dd-033ac17c24ae HIGH 7.2 The SpiderCatalog WordPress plugin through 1.7.3 does not sanitise or escape the 'parent' and 'ordering' parameters from… wordfence
52efc168-fed9-45c6-9a2c-1e3a198f71f9
< 5.0.2.2
HIGH 7.2 The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using… wordfence
52d390e0-95ca-4570-8d4c-f679ee86ffea
< 4.1.2
HIGH 7.2 The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter… wordfence
52d1cf26-bfd2-402b-b51a-59ccadd19091 HIGH 7.2 The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
52c4c16f-2e6e-4cbd-b061-4324a6002eab
< 5.0.3
HIGH 7.2 The Product Catalog Mode For WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cust… wordfence
52b13188-5630-4ae9-9b2b-bd4dcadd240a
< 2.2.5
HIGH 7.2 The Everest Backup plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in t… wordfence
527c344e-870e-4bd9-b111-86cc2821367d
< 2.8.0
HIGH 7.2 The Redirection for Contact Form 7 plugin is vulnerable to Authenticated Privilege Escalation in versions up to, and inc… wordfence
52784505-a408-414f-a793-262d24f36546
< 2.0.5
HIGH 7.2 The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
526add70-4fcf-44d1-b4d8-4cc35652b1f0
< 3.1.68
HIGH 7.2 The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature… wordfence
5242f5e4-a436-4e8b-87eb-f012d65712d9
< 1.0.5
HIGH 7.2 The Download Monitor - WPForms Lock plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
521bcfd5-7bb2-4748-8440-9902181cbf7e HIGH 7.2 The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the id parameter before using it in various … wordfence
5219ef67-7a99-49da-810b-bbfe7b649145
< 3.5.1
HIGH 7.2 The Notification for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
51cbe19d-2af9-44e2-802e-243779b23ed3
< 2.0.13
HIGH 7.2 The Check & Log Email – Easy Email Testing & Mail logging plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
518f23c3-f3e3-4cff-bd30-a8211f74c3ce
< 1.3.2
HIGH 7.2 The HUSKY plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.1 via deseri… wordfence
517653e5-fdad-4360-82a5-32b16a6cd631
< 3.0.2
HIGH 7.2 The OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) plugin for WordPress is vulnerable to Cross-Site Scripti… wordfence
5151f429-b1f3-43d4-94cf-3ff382b80190
< 2.0.6.2
HIGH 7.2 The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is … wordfence
510c26b8-01d6-4d3c-91fd-15963152fdf1
< 7.5.18.727
HIGH 7.2 Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player W… wordfence
509097ae-5b20-4e91-9d82-cc6e3b64e518
< 3.9.002
HIGH 7.2 The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitr… wordfence
508225ab-beb7-40eb-a80b-de123650fcff HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in simple-visitor-stat.php in the Simple visitor stat plugin for Wor… wordfence
507f3071-3274-4d25-8ae2-53d909bd9daa
< 2.5.2
HIGH 7.2 The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
507b2e65-987b-4d4a-8a99-5366048d925e
< 3.3.0
HIGH 7.2 The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… wordfence
507513c4-e80c-4d9d-85ab-32a5e84cbafa HIGH 7.2 The ElementsCSS Addons for Elementor (Elementor Widgets Extender & Addons) plugin for WordPress is vulnerable to Server-… wordfence
5055cf24-14c7-4533-8900-a5f4c1435201 HIGH 7.2 The Amazon Products to WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up … wordfence
504aff5b-5951-4d07-9ff0-e6f7cfe5dc32
< 1.53.2
HIGH 7.2 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
50417068-339a-4ae5-9c90-8f08f54ce0af
< 4.2.3
HIGH 7.2 The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vu… wordfence
← Prev 386 387 388 389 390 391 392 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top