πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 396 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
39487908-5cc5-42ac-8af4-65626694b1e4
< 1.2.5
HIGH 7.2 The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fi… wordfence
3940232c-b3d4-488b-830d-797bdab9cfbe HIGH 7.2 The WP RSS By Publishers plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in ver… wordfence
39075385-f8b8-4f40-9ec1-8f9f8d2bee0c
< 1.6.01
HIGH 7.2 The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.7.1041 … wordfence
38e40a74-c4b7-4960-880d-a14e77fe1904
< 1.1.7
HIGH 7.2 The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved v… wordfence
38da66f4-2db8-4e8e-819f-d7dd9533e045
< 2.13.11
HIGH 7.2 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
38ce5790-f6b8-43a0-a1a3-290a86eb49cb
< 5.4.3
HIGH 7.2 The Classified Listing – AI-Powered Classified ads & Business Directory plugin for WordPress is vulnerable to Stored C… wordfence
38a1fb65-b0f6-4d3a-9b07-c40f80de4685
< 2.2.5
HIGH 7.2 The Wholesale Suite – B2B, Dynamic Pricing & Wholesale Prices for WooCommerce plugin for WordPress is vulnerable to Pr… wordfence
3892579a-d7fd-4f11-88fd-7452fa312000
< 1.3.1
HIGH 7.2 The Best WordPress Shortcode Plugin in 2025 – AIO Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
3825c80c-e4b1-4dd8-be77-38f718920b9a
< 4.9.9.8
HIGH 7.2 The Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the logging functionality in all v… wordfence
38227a1c-30a7-436c-853f-7205e421bd19
< 2.8.18
HIGH 7.2 The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
381708ae-3180-4058-a6f4-e925bfc658ec HIGH 7.2 WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, inclu… wordfence
3816a6cf-8157-4ad9-83f6-93c9b6c6275f
< 2.6.1
HIGH 7.2 The Post SMTP plugin for WordPress is vulnerable to time-based SQL Injection via the log_id parameter in versions up to,… wordfence
37dc80d0-1834-40a7-9454-a8129d9b4cdd
< 18.1
HIGH 7.2 The WP Google Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
37bfb60d-8e2d-4c77-880c-3d17a6a434b8
< 2.6.0
HIGH 7.2 The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve… wordfence
37820930-4705-41af-9a9d-c99409d7bbe3
< 1.3.6
HIGH 7.2 The Beaver Builder Addons by WPZOOM plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an… wordfence
37734c25-cce3-41fb-babf-714ba7a4bced
< 2.2.9
HIGH 7.2 The Download Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
37725a72-0478-4f56-b87f-e427b1f5fb58
< 1.3.3
HIGH 7.2 The Ninja Job Board – Ultimate WordPress Job Board Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scri… wordfence
37471ecc-ee8f-4246-a126-b7b7013b5ceb
< 2.56.1
HIGH 7.2 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5… wordfence
3745b681-cb09-4a5b-a57b-c7f35b8c5133 HIGH 7.2 The WP RSS By Publishers plugin for WordPress is vulnerable to generic SQL Injection via an unspecified parameter in ver… wordfence
37441cc0-c43c-40e4-a170-1be59e112272
< 2.0.05
HIGH 7.2 The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all vers… wordfence
37198f2f-2b45-40d3-b4ae-aa94213996bd HIGH 7.2 The Link Fixer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via broken links in all versions up to,… wordfence
3718c252-2ca3-4f7d-b43a-3c1b2e6b34c0 HIGH 7.2 The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, a… wordfence
36c32212-0d52-435e-bb6a-39ea07363a86
< 4.4.4
HIGH 7.2 The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery Word… wordfence
36777e39-be45-41f2-beca-2971e15b77cd
< 10.44
HIGH 7.2 The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
366dfbf1-870c-4ce3-abc4-a2b2f4e72175
< 3.1.0
HIGH 7.2 The Post SMTP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the from and subject parameter in al… wordfence
← Prev 393 394 395 396 397 398 399 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top