ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 392 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4757590a-f5dc-48d6-aef1-80158f728b6e
< 2.1.0
HIGH 7.2 classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash … wordfence
473ff00e-e045-4b66-b0af-89d666de4de8
< 1.1.2
HIGH 7.2 The Crelly Slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter found in the ~/wordpress/ad… wordfence
47337214-9cc3-4b12-bb71-9acbab3649b7
< 2.4.2
HIGH 7.2 The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
470d91c1-bcde-4497-a558-35bc0156ddca
< 4.1.5
HIGH 7.2 Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page with… wordfence
4707fcf6-ad11-4ffc-ba56-30f6571e3d9e
< 6.8.1
HIGH 7.2 The Simple:Press plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'postitem' parameter manipula… wordfence
4701d3b2-1bf4-430d-b8c8-95da5d699a89
< 1.6.7
HIGH 7.2 The CRT Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and in… wordfence
46c988ff-9cc5-4f2b-a3dd-06eaef5a7919
< 3.28.24
HIGH 7.2 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'acff' parame… wordfence
469a9c8a-0708-4c93-99d8-e9157a1f91f5
< 1.7.49
HIGH 7.2 The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-… wordfence
46706adb-fc2e-47d4-b1ff-748b89b1decf HIGH 7.2 SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote aut… wordfence
465f2fd1-9eb3-43ca-8acc-74acf6bcde1a HIGH 7.2 The Demo Import Kit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
465f29c0-99b9-4f7d-9817-3d3a49a2d943
< 1.4.7
HIGH 7.2 The 'Live Chat with Messenger Customer Chat' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
463d0ecd-408c-4ccf-9f2c-8bff3deca213
< 1.5.15
HIGH 7.2 The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file … wordfence
4624c43b-6c5f-48c5-bfe4-26ec6d7de418 HIGH 7.2 SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote a… wordfence
46150f65-e662-4539-ae99-eaee297a2608
< 1.5.1
HIGH 7.2 The Seriously Simple Stats plugin for WordPress is vulnerable to SQL Injection via the order_by parameter in versions up… wordfence
45ef9293-dd94-490a-8cb8-df6bccf4739a
< 5.0.0
HIGH 7.2 The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
45bfa9fb-f35b-4fd4-8553-cf87bf69df6b
< 5.1.57
HIGH 7.2 The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href para… wordfence
45690747-0b8d-4e2e-8dd0-07c12791c064
< 3.0.13
HIGH 7.2 The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to… wordfence
4550681f-d115-4451-9839-7862b84714fe
< 3.6.3
HIGH 7.2 The BSK Forms Blacklist plugin for WordPress is vulnerable to generic SQL Injection via the 'order' and 'orderby' parame… wordfence
4532cb38-453b-460c-879d-6f0e1caacafc
< 6.0.6.3
HIGH 7.2 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
4528f9a1-7027-4aa9-b006-bea84aa19c84
< 1.40.4
HIGH 7.2 The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the '… wordfence
44fde2c8-8012-4ede-8455-08b8e744ba36
< 3.1.15
HIGH 7.2 Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient inp… wordfence
44f3b2e4-c537-4369-b2d6-39fbc6cb8e08
< 5.2.2
HIGH 7.2 The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all v… wordfence
4483fb33-3815-4ec9-9df4-a971844f4855
< 2.0.6
HIGH 7.2 The Woocommerce Vietnam Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom shippi… wordfence
446b160a-299e-4f91-bd49-02a7a16b6e5f
< 2.5.9
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke… wordfence
44373541-adc5-4aa0-abde-0693f2760afb
< 9.9.4
HIGH 7.2 The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the ‘$email’ variable in versions up to, and i… wordfence
← Prev 389 390 391 392 393 394 395 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top