🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 395 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3cf369f9-dfde-4df7-983f-0dfea85e1b99 HIGH 7.2 The Syndicate Out plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
3cbf77f4-59f5-49cd-ba2b-dc9de3d031b6
< 1.56.1
HIGH 7.2 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored C… wordfence
3c9de67e-24f7-4c4a-b187-405597b838c3
< 1.31.0
HIGH 7.2 The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name_directory_name' and … wordfence
3c6b80a2-783d-4689-9cba-65f89058958f
< 4.5.10
HIGH 7.2 The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in a… wordfence
3c476263-72b7-48f1-8ba3-91d69eae7b6a
< 3.5.25
HIGH 7.2 The WP User Frontend – Membership, Profile, Registration & Post Submission Plugin for WordPress plugin for WordPress i… wordfence
3c268a6d-dfb4-4a9d-802e-80e5c1c53ca2
< 5.3.15
HIGH 7.2 The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ paramete… wordfence
3bf669ed-ea31-4144-96b3-b1f29057b86d HIGH 7.2 The Lava Directory Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several fields when cre… wordfence
3bcd61d4-4775-4297-b7f5-664991fcd6d2
< 2.3.29
HIGH 7.2 The GeoDirectory plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up … wordfence
3bb4d37c-c4c2-4523-9b4e-73ffb7be81ea
< 20230811
HIGH 7.2 The User Submitted Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘user-submitted-con… wordfence
3b874721-6cb9-4ce4-a78e-a457596d15ff
< 2.8.4
HIGH 7.2 The Live Chat Unlimited plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
3b864ff8-83fb-40e2-9264-7c57115d50f2
< 1.80.4
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Share and Follow plugin 1.80.3 for WordPress allows remote attackers to … wordfence
3b5f1a1e-8066-4f20-af36-a778e50a3f64
< 1.45
HIGH 7.2 The Quotes and Tips by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… wordfence
3b56a793-2a20-4bd7-aefb-a8d012c56527
< 4.3.3.1
HIGH 7.2 The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_… wordfence
3b467d55-db84-488e-8e80-bcdf2b691c76
< 1.22.22
HIGH 7.2 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to PHP Object Injection in versions up to, … wordfence
3b0e83af-5abd-4b6e-b606-850c03b05036
< 3.7.6
HIGH 7.2 The Meta for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
3afbfa7c-a87f-4810-9356-374923ff2314
< 3.30
HIGH 7.2 The Leyka plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.29.2 due… wordfence
3ae77d0e-db36-4d9c-ad12-6bf1186f79e4
< 2.4
HIGH 7.2 The Penci Bookmark & Follow plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 2.4 due … wordfence
3ae6bf2e-b39a-4bb3-9203-22ff4c23ddf4 HIGH 7.2 The Shortcode IMDB plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and i… wordfence
3adea276-6b55-422d-adc9-a767f569181c HIGH 7.2 The Kanban Boards plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.21. … wordfence
3a63dd48-d643-41d0-84c3-2f2dbbe577dd
< 2.6.1
HIGH 7.2 The Flipbox – Awesomes Flip Boxes Image Overlay plugin for WordPress is vulnerable to arbitrary options updates in ver… wordfence
3a6242ab-eec1-4e3d-bd02-25381cd363b6
< 2026.1.1
HIGH 7.2 The WP REST Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 20… wordfence
3a096506-b18e-419c-808b-6099baa628ce
< 7.7.6
HIGH 7.2 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Inject… wordfence
399189a6-271b-4199-a758-e3cc5d6d90aa
< 2.3.5
HIGH 7.2 The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
395a8ca6-78b8-43f2-8e8c-896702b5da0d
< 1.4.8
HIGH 7.2 The WP Reroute Email plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, … wordfence
39564fad-a8cb-4a95-a893-d61e8ff91a53
< 1.0.11
HIGH 7.2 The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp-piw… wordfence
← Prev 392 393 394 395 396 397 398 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top