πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 394 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3fffdda5-91ed-4b79-bc04-77a1c44e3b67
< 0.32.7
HIGH 7.2 The Rent Fetch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'keyword' parameter in all vers… wordfence
3fdc6a04-ef39-498a-b739-f40d5d8af47e
< 1.2.5
HIGH 7.2 The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… wordfence
3fbfb185-d901-4789-9a13-137f72234ed4 HIGH 7.2 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
3f8cbbbb-2089-4966-8fd3-da4f76fb2517
< 3.9.0
HIGH 7.2 The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plug… wordfence
3f7a5e27-af7e-4e32-be9b-08e1133bb323
< 2.5.4
HIGH 7.2 The Export and Import Users and Customers plugin for WordPress is vulnerable to PHP Object Injection in all versions up … wordfence
3f6291ab-99d1-41e2-9928-f31beee0df8b HIGH 7.2 The Wise Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… wordfence
3f1b63a2-31c7-4c76-8969-fee3f7138cfe
< 1.0.5
HIGH 7.2 The Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate plugin for WordPress is vulnerable to … wordfence
3f0866a4-0edf-4fb7-8628-4b8e18a2b4bb HIGH 7.2 The Simple Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maybe_do_import() function i… wordfence
3f04a742-56be-42e9-9080-2131c6e98325
< 1.0.2
HIGH 7.2 The Travel Map plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.0.1 due to… wordfence
3eedc57b-79cc-4569-b6d6-676a22aa1e06
< 4.1.5
HIGH 7.2 The Active Directory Integration plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and orde… wordfence
3eec5823-f1ee-464c-8344-eed3ee991602
< 1.1
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the skeltoac stats (Automattic Stats) 1.0 plugin for WordPress allows remote… wordfence
3ebdb591-4fd4-4ea3-a0db-b934c67176de
< 2.2.12
HIGH 7.2 The RapidLoad 2.2 – Speed Monster in One Plugin plugin for WordPress is vulnerable to Server-Side Request Forgery in a… wordfence
3ebac8bc-1dca-4bcd-a033-fb8ed210bf4e
< 1.33.0
HIGH 7.2 The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' param… wordfence
3e8a881d-d6d0-4bcc-9894-286ce0468393
< 1.6.9
HIGH 7.2 SQL Injection exists in the Tribulant Slideshow Gallery plugin 1.6.8 for WordPress via the wp-admin/admin.php?page=slide… wordfence
3e747b4b-3865-4e31-b584-e11e35d4c3c4 HIGH 7.2 The ThemeEgg ToolKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
3e63a70c-924b-4736-a712-80538bfd7ca7
< 0.7
HIGH 7.2 The supportflow plugin before 0.7 for WordPress has XSS via a discussion ticket title if 'run_wptexturize' is disabled. wordfence
3e62eba7-1ac9-4420-8692-58a169aa4330 HIGH 7.2 The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
3e619e8e-e04b-4e42-9cee-65e5dedff3b6
< 1.4.4
HIGH 7.2 Cross-site scripting (XSS) vulnerability in wpcommentremix.php in WP Comment Remix plugin before 1.4.4 for WordPress all… wordfence
3e292a1f-d475-4c52-b790-b5215e1870ad
< 1.2.2
HIGH 7.2 The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste… wordfence
3e1a84c6-e28b-42fe-a16a-aeb227cfe956
< 5.2.6
HIGH 7.2 The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for Wor… wordfence
3da5ddc2-2004-4abd-87ef-154121e37d57
< 4.1.08
HIGH 7.2 The WorkScout theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.1.07 … wordfence
3da37b4d-3dd7-450f-8169-28141eeb19c7 HIGH 7.2 The Game Server Status WordPress plugin through 1.0 does not validate or escape the server_id parameter before using it … wordfence
3d9f4fbe-6da6-4620-a071-00b7a462de45
< 3.7.6
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, a… wordfence
3d76a21c-bb79-4183-99ea-a07c18dfa180
< 7.3.11
HIGH 7.2 The Quiz And Survey Master plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
3d300517-8939-431d-b33b-e74806e5887c
< 6.5.1
HIGH 7.2 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-LSCACHE-VARY-VALUE' hea… wordfence
← Prev 391 392 393 394 395 396 397 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top