πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 393 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
437423f0-978f-4c7c-9ec3-40668c630c93
< 1.4.7
HIGH 7.2 The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to Server-Side Request Forgery in al… wordfence
436dc261-66b8-4b6c-9932-82513c3e5461
< 1.6.1
HIGH 7.2 SQL injection vulnerability in content-audit-schedule.php in the Content Audit plugin before 1.6.1 for WordPress allows … wordfence
431bcb93-396f-470b-94c9-66a9a2973552 HIGH 7.2 The Iconize plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.2.4. Thi… wordfence
431a83b3-4dc9-4090-ae49-1c283d24fc2e
< 3.2.9
HIGH 7.2 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
430a82be-79dd-4819-a608-3a05a6a62018 HIGH 7.2 The Artale | Wedding Photography WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
42f94f80-6157-4778-ad69-184943134fd2
< 1.13.2
HIGH 7.2 The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and… wordfence
42f37a41-deff-4b17-94d8-4e0fd1ce22c2
< 1.7.8.4
HIGH 7.2 The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi… wordfence
42de4318-0f10-4236-bd1f-06eea84acc9e
< 5.7.2
HIGH 7.2 The PhotoMe | Photography Portfolio WordPress theme for WordPress is vulnerable to Server-Side Request Forgery in all ve… wordfence
427034cf-81b4-4648-9630-5448b6d2b2f7 HIGH 7.2 The Edubin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 9.2.0… wordfence
424cab53-d7dd-4fd6-974a-5432256cfad1
< 1.2.6
HIGH 7.2 The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up… wordfence
41c2ec31-360d-4145-b0b4-77d4d1d4b8a1
< 5.2.7
HIGH 7.2 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
41985e86-eda4-4914-a7f8-3758afcc6193
< 6.0.0.2
HIGH 7.2 The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … wordfence
419270e7-c781-41fe-9893-473074825b36 HIGH 7.2 SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticate… wordfence
418a6ed7-a19e-4741-a6db-f1016156a468
< 19.6.25
HIGH 7.2 The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
416ecce7-e2ca-4b73-90ff-85c6fdd94251
< 2.0.74
HIGH 7.2 The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerabl… wordfence
416e39c1-863a-42a1-8c6c-43ea87f29191
< 2.9.7
HIGH 7.2 The TranslatePress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.6 vi… wordfence
413962b8-09ac-4b5d-a52d-5ca832bba9f2
< 3.2
HIGH 7.2 The WP ULike plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user supplied IP HTTP Headers paramet… wordfence
412c39e9-9378-4c2c-817c-8d37f156af6e HIGH 7.2 The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0… wordfence
40fa29f5-525a-4986-91f9-0210a7594e46
< 7.8
HIGH 7.2 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/noti… wordfence
40d80e47-3411-4e70-8a20-2e698daad6e7
< 1.16.59
HIGH 7.2 The UpdraftPlus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.16.56 via… wordfence
40abaa5e-7dd5-4a4e-877c-0a56386f5ffe
< 3.7.8
HIGH 7.2 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.7.7 … wordfence
407f7165-242d-462a-88c4-3f3eb062dc27 HIGH 7.2 The Sticky Button – Click to Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up… wordfence
40682959-6cb0-4ffb-9338-519e82eb746e
< 3.7.3
HIGH 7.2 The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
4062f981-a1d2-4e54-8fd9-f8855af0a7db
< 2.5.1
HIGH 7.2 The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter befor… wordfence
4057bfcf-eb96-4610-93ed-8ff1cca7506d HIGH 7.2 The Intelligent WordPress Live Chat Support Plugin | Utilities plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
← Prev 390 391 392 393 394 395 396 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top