🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 397 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
366b5051-d042-4425-9aad-b77d93bcd485
< 32.8.0
HIGH 7.2 The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST AP… wordfence
365b90dc-b9a1-4e04-9546-860f057f29f8 HIGH 7.2 The Woocommerce – Recent Purchases plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, a… wordfence
36304098-fea7-4e67-a138-5670761c6338
< 2.17.1
HIGH 7.2 The Age Gate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data imports in versions up to, and i… wordfence
3604b314-6b85-4d11-aa71-63f9198dbbdb
< 1.6.4.0
HIGH 7.2 The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up t… wordfence
35db7137-aba0-4299-ad8a-c650d6db5199
< 6.0.12
HIGH 7.2 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
35d8e0d9-08d5-4e39-a235-06e624f2e764
< 3.2.0
HIGH 7.2 The Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.1.0 d… wordfence
35ac717c-e299-4a56-bead-cb1d050da75c
< 1.5.1.3
HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers … wordfence
35ac7049-6453-4235-82bd-d2bc6ffccabe
< 4.6.4
HIGH 7.2 The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
353804e8-0d5a-4633-974c-6eb7a3eeba61
< 1.4.3
HIGH 7.2 The WP Super Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `$details[ ‘key’ ]` va… wordfence
352cd9e6-ef1e-4a6b-bedb-6cf8ce9d4270
< 2.7.3
HIGH 7.2 The Paytm Payment Gateway plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and inclu… wordfence
34fd5045-cd38-4eab-9e97-98f1e3d7423a
< 3.3.5
HIGH 7.2 The Wise Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-For header in all ve… wordfence
34d6ad4a-f27c-4775-a26d-adf2d4755862
< 3.1.58
HIGH 7.2 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to Server-Side Request Forg… wordfence
3486dc6f-d40a-426a-9d46-ded10789ec62 HIGH 7.2 The ListingHub plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.2.6 due to insuffic… wordfence
346a49ff-4e61-466b-b1fe-98cf5766accb
< 2.2.8
HIGH 7.2 The WordPress Calls to Action plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode’ … wordfence
34526c98-caf8-42d9-8782-7ea9b3a75e9d
< 2.6.8
HIGH 7.2 The Watu Quiz plugin for WordPress is vulnerable to SQL Injection via the 'quiz' parameter in versions up to, and includ… wordfence
33f17152-f273-46d0-ad37-55953adee919
< 2.3.2
HIGH 7.2 The Greek Multi Tool – Fix peralinks, accents, auto create menus and more plugin for WordPress is vulnerable to Stored… wordfence
33c16b47-3202-4f26-bf45-98172b8cac45
< 1.9.1
HIGH 7.2 The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions … wordfence
33c0838a-5f86-4368-8bf9-da0582acbabf
< 4.10
HIGH 7.2 The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9… wordfence
33727746-4481-4b7f-8d2a-100027b7d1c3
< 1.8.12
HIGH 7.2 The Blog Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_css' parameter in ve… wordfence
3352b264-eae8-4ce3-86ee-5febcd2e7fcc
< 2.3.7
HIGH 7.2 The Membee Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3… wordfence
332909d5-e3bf-42a7-af52-c4e50b05f97e
< 4.24.8
HIGH 7.2 The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom text fileds in al… wordfence
3320fe6a-dafc-4640-8d8b-7f62fc6e7753
< 4.2.8
HIGH 7.2 The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vu… wordfence
32fa4d64-0cdd-4c47-aaf7-816824b27175
< 1.2.12
HIGH 7.2 The Favicon Rotator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
32f47b68-e1ae-4ed1-9513-bba60aab65fb
< 1.3.7
HIGH 7.2 The WP CSV Exporter plugin for WordPress is vulnerable to generic SQL Injection via the $query_select value in versions … wordfence
32ccbde2-b6a9-4748-907d-b948937dad09 HIGH 7.2 The Piotnet Addons For Elementor Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u… wordfence
← Prev 394 395 396 397 398 399 400 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top