πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 398 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
32c4cb55-855c-42ed-a9ac-90f92e8583e0
< 9.6.3
HIGH 7.2 The Salon booking system plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sms_prefix' paramete… wordfence
32658119-82e7-4302-9af9-728e054374ec HIGH 7.2 The Mollie for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.… wordfence
322e0a27-9119-4b46-a043-d3a68c4fcdc4
< 1.1.7
HIGH 7.2 The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin… wordfence
32179cca-2253-49c7-89f7-aa48bcfad716 HIGH 7.2 The ExportFeed WordPress plugin through 2.0.1.0 does not sanitise and escape the product_id POST parameter before using … wordfence
31f000d6-10ab-4dee-97fb-83d1d00595bb HIGH 7.2 The SpaLab | Beauty Salon WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, … wordfence
31c080b8-ba00-4e96-8961-2a1c3a017004
< 1.8.5.4
HIGH 7.2 The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all … wordfence
31a04983-a1d9-49b3-9f1f-06fb3480531b HIGH 7.2 The brickscore plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… wordfence
3150bdc4-fe5d-47ca-bb52-338853e3e23d
< 3.29.9
HIGH 7.2 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
313af4a0-f32b-443f-a976-e06499d3c94b HIGH 7.2 The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting people to a CSV file, lea… wordfence
310b9365-2c94-42b2-92ca-ab9a5eab3bfe
< 1.8.9
HIGH 7.2 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
30f791ef-3a97-4f89-b602-b42b726a8f70 HIGH 7.2 The Property Lot Management System plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, a… wordfence
30eda147-f02a-4b3c-a51c-665aa4c75c93
< 3.4.1
HIGH 7.2 SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote … wordfence
30ddd0e6-a9c2-4a71-b5ab-295d5c15cf47
< 1.0.5
HIGH 7.2 The Compress & Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
30741601-50b9-4799-a340-11f6ffa59553 HIGH 7.2 The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
306fa8e1-b62f-4514-8463-e696d043f6f5
< 1.8.1
HIGH 7.2 The Simple Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
306c98ad-0d42-4ad5-b82a-bf4579865aa9 HIGH 7.2 The QueryWall plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to insuffi… wordfence
3041bb06-504c-4de1-8a1a-12041e09400e HIGH 7.2 The WP-Cufon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions … wordfence
2fe467fb-f5b2-4e4b-8048-669dce354ace
< 2.5.0
HIGH 7.2 The Webhook Automator & Contact Form Integration to Automate 280+ Platforms – Bit Integrations plugin for WordPress is… wordfence
2fd2dffd-efc9-47f7-8495-50be2b80331f
< 2.8.3
HIGH 7.2 The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
2fca8dba-9fe7-4ce1-8903-589e42e5604d
< 3.5.3
HIGH 7.2 The Social Warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio… wordfence
2facf62b-33cf-4438-a501-f96730077fa2 HIGH 7.2 The Poll Plugin for WordPress is vulnerable to blind SQL Injection via the 'pollid' parameter in versions up to, and inc… wordfence
2f905c0b-6b70-42bf-bf48-6f4eb785bfb8 HIGH 7.2 The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id parameter before using it … wordfence
2f533b3a-6d25-4c74-929f-ee4ee3a62926
< 14.13
HIGH 7.2 The cformsII plugin for WordPress is vulnerable to generic SQL Injection via Delete Entries or Download Entries in versi… wordfence
2f3ad1e0-1ae3-44cd-aa2a-dbb3a1b531f9
< 3.1.13
HIGH 7.2 The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in… wordfence
2f3328c2-290f-410b-a6c8-2825d415f511 HIGH 7.2 The Web Instant Messenger and LocalWeb In One plugins for WordPress are vulnerable to Stored Cross-Site Scripting in ver… wordfence
← Prev 395 396 397 398 399 400 401 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top