πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 390 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5038d12a-e119-4ab7-aadc-69b765ae7027
< 3.1
HIGH 7.2 The Planyo Online Reservation System plugin for WordPress is vulnerable to Server-Side Request Forgery leading to Local … wordfence
501e9cd1-1187-4d01-a3cc-5edba64c391f
< 1.0.6
HIGH 7.2 The Image Compressor & Optimizer – iLoveIMG plugin for WordPress is vulnerable to PHP Object Injection in all versions… wordfence
4fa5b8a9-1683-4806-987d-527834f45d34 HIGH 7.2 The LifePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'n' parameter of the lp_update_m… wordfence
4fa453f3-d361-452c-940a-108252c9f302
< 2.5.2
HIGH 7.2 Unrestricted file upload vulnerability in WordPress 2.5.1 and earlier might allow remote authenticated administrators to… wordfence
4fa00dae-c51d-4586-81da-b568cd6d8124
< 6.6.13
HIGH 7.2 The Slider Revolution plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
4f77f4cd-f4b3-42bc-a1a9-e5df5daa42b7
< 6.6.12
HIGH 7.2 The CTX Feed – WooCommerce Product Feed Manager plugin for WordPress is vulnerable to unauthorized arbitrary plugin in… wordfence
4f3e3311-11d8-4e4f-9d99-36533fe44d56 HIGH 7.2 The Olive One Click Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
4f060807-cd59-4558-a30b-00b4b947f3f7
< 1.9.13
HIGH 7.2 The Everest Forms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
4f018e22-bf07-4371-afc1-3e664ea1c5a3
< 2.3.7
HIGH 7.2 The All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic plugin for WordPress… wordfence
4ebbe9a4-3769-4e05-9377-907b43e3fe10
< 2.67.3
HIGH 7.2 The WP-EMail plugin for WordPress is vulnerable to Cross-Site Scripting via several form fields in versions up to, and i… wordfence
4e3f4e4f-6781-4134-b0ba-3625d7009d0c HIGH 7.2 The Crazy Bone WordPress plugin through 0.6.0 does not sanitise and escape the username submitted via the login from whe… wordfence
4e3931c2-c9b4-412e-941d-840c5bb9be89
< 14.6
HIGH 7.2 The Online Booking and Scheduling plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and incl… wordfence
4e0baa10-f576-48f5-ad7f-2cbae9d0abd0
< 2.8.3
HIGH 7.2 The NPS computy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.… wordfence
4dc83aca-f533-4a8c-b12c-e21156ce6088
< 3.1.43
HIGH 7.2 The WP Event Manager plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.1.42… wordfence
4da167e0-c1cf-496f-9b14-35fc70386be1 HIGH 7.2 The AJS Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'note_list_class' and 'popup… wordfence
4d8d581c-8198-4431-a534-aac8f05750cb
< 1.7.7
HIGH 7.2 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to unauthorized modific… wordfence
4d6d394e-a8e7-4b12-b2ed-7d1495643106
< 1.8.8
HIGH 7.2 The Toolset Types plugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 1.8.8 due to insu… wordfence
4d162450-32e2-4366-b442-95f4f7b8f828
< 1.0.9
HIGH 7.2 The Toast Mobile Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
4d09e2fd-ccbb-49a8-9d34-8ede87429428
< 4.2.0
HIGH 7.2 The Houzez Theme - Functionality plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 4.2… wordfence
4cb5837a-665d-4edb-ac8c-a6499b510817
< 2.4.6
HIGH 7.2 The JobWP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.5 due … wordfence
4cb02d7c-5014-46e9-9d4c-c207e58a1b0b
< 1.7.3
HIGH 7.2 The Contact Form Submissions WordPress plugin before 1.7.3 does not sanitise and escape additional fields in contact for… wordfence
4ca4fa28-53b0-4bc4-99f8-fa6dfa14d500
< 2.4.7
HIGH 7.2 The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GE… wordfence
4c65519c-06f6-4303-9d22-980dbe36f0b6
< 2.0.2
HIGH 7.2 The Builderall Builder for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u… wordfence
4c4f2d9d-d34c-45dd-aff8-ca9bbe808b5a
< 11.2.0.1
HIGH 7.2 The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
4c437d0f-521a-431f-8c31-a73ff6e9367d
< 5.5.1
HIGH 7.2 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… wordfence
← Prev 387 388 389 390 391 392 393 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top