πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 391 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4bc38197-3827-4c0e-a0a8-42d55f50605f
< 1.2.0
HIGH 7.2 The Uploading SVG, WEBP and ICO files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
4b8462ed-6228-42e8-be92-8e02ecd55ae5
< 1.7.6
HIGH 7.2 The SiteGround Email Marketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
4b24b3d2-589f-47b2-bcdd-bebc87cafeda
< 2.6.3
HIGH 7.2 The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up … wordfence
4af0e984-896d-4938-a870-8a50644d4823
< 2.1.5
HIGH 7.2 The WC Price History for Omnibus plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inclu… wordfence
4ad3ed6b-19d4-47c7-a56c-54092c767fe9
< 2.3.0
HIGH 7.2 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for … wordfence
4a3cae01-620d-405e-baf6-2d66a5b429b3
< 3.16.2
HIGH 7.2 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection v… wordfence
4a18cb4a-8458-4337-843e-c3278028230f
< 2.0.2
HIGH 7.2 The Lead Form Builder & Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
4a0e962b-b6a0-4179-91d0-5ede508a9895
< 1.5.0
HIGH 7.2 The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions … wordfence
49df1ed8-1c2b-4a04-b33a-1fe95fe12172
< 1.13.19
HIGH 7.2 The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.… wordfence
49dc267a-48cf-487f-bedc-fd892666e9a0
< 9.2.3
HIGH 7.2 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
49d3d11d-76b1-4242-921f-631e2e270ebe
< 1.11.5
HIGH 7.2 The Z-Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all … wordfence
499a1892-12b7-49d5-b65f-4f53a968a23a
< 3.3.18
HIGH 7.2 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e… wordfence
4973cef3-dddf-4eb5-99f4-c23a0e162fd6
< 6.7.25
HIGH 7.2 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … wordfence
495804c2-1870-4d64-9a5a-166b01ed7b0e
< 1.5.3
HIGH 7.2 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script… wordfence
49150180-9de0-4318-b21b-779daaeb7a52
< 18.3
HIGH 7.2 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and in… wordfence
48e3976a-5dfc-44f5-8d01-0bd1b68575be HIGH 7.2 A c GET parameter of the Comment Highlighter WordPress plugin through 0.13 is not properly sanitised, escaped or validat… wordfence
488bafe4-746a-4531-95ac-30d17ace2239
< 1.4.07
HIGH 7.2 The Calendar Event Multi View plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
487185ed-d5ff-4658-9210-958e3ba2fe91
< 8.0.4
HIGH 7.2 Multiple plugins and/or themes for WordPress are vulnerable to Remote Code Execution in various versions. This makes it … wordfence
4869dcd8-9b21-4751-8682-10f1aede14a3 HIGH 7.2 The Flickr Shortcode Importer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… wordfence
48421787-9dc1-48ea-892b-bb43b2a6c4da
< 1.3
HIGH 7.2 The Import Users from CSV plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… wordfence
481be4ab-f8df-4080-b87b-24e4d40f83b1
< 1.5.12
HIGH 7.2 The VOD Infomaniak plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
48075ef0-b3c5-487b-93c2-d3e630742fe4 HIGH 7.2 A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp… wordfence
47a10dd4-515c-42d9-82ea-c84f8f7574c5
< 5.0.11
HIGH 7.2 The RSS Aggregator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'template' parameter in … wordfence
47940179-1a34-48d3-a6fc-81f2d3cd2670 HIGH 7.2 The Arlo theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.3 due to… wordfence
47938357-7d51-4d62-a08c-4b2bf3f3a062
< 5.2.4
HIGH 7.2 The Wordfence Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '$_SERVER['HTTP_HOST']… wordfence
← Prev 388 389 390 391 392 393 394 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top