🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 399 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2eb4608f-fa4f-444c-a857-c9059777a70b
< 2.9.1.1
HIGH 7.2 The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
2ea5c0e4-afee-4fbd-8b2e-9befd16c7935
< 1.8.10
HIGH 7.2 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions … wordfence
2e8f224c-cd22-4926-be24-9da2f22afa50
< 3.2.6
HIGH 7.2 The WPML String Translation plugin for WordPress is vulnerable to SQL Injection via the ‘context’ parameter in versi… wordfence
2dfd592b-cbe9-460a-8b9a-148058d1bd58
< 5.7.5
HIGH 7.2 The BackWPup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.7.4 d… wordfence
2df059e6-a875-4e65-8cb4-bc409f450c09
< 11.11
HIGH 7.2 The Visitor Traffic Real Time Statistics pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versio… wordfence
2db4eb1d-3a82-4f0f-b4ff-a291b0289b7f
< 6.5.0
HIGH 7.2 The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all… wordfence
2d8e037e-c446-44ae-a5ee-bbba938e5edf
< 3.32.4
HIGH 7.2 The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
2d6a6159-5c8c-4d8f-9592-93b6ce74f082
< 6.6.43
HIGH 7.2 The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress i… wordfence
2d6304e5-7fbf-484d-b147-f2a6c2ee0658 HIGH 7.2 The Cincopa video and media plug-in plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cincopa Shortc… wordfence
2d5c6566-a890-4b95-b349-3874eb57b45a
< 1.3.38
HIGH 7.2 The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Message' field in vers… wordfence
2d32e6d1-67b4-44e1-b82a-78ce08aea1e6
< 1.4.9
HIGH 7.2 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
2d0e5d24-5d65-4ed5-8086-347969cbd3ec
< 3.8.1
HIGH 7.2 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via s… wordfence
2c7c2b11-750a-48de-b48b-dcc6fbb8e917 HIGH 7.2 The Note Press WordPress plugin through 0.1.10 does not sanitise and escape the ids from the bulk actions before using t… wordfence
2c648ea4-7df6-4a77-9bc5-bd3c18979250
< 2.53
HIGH 7.2 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to generic S… wordfence
2c535cea-dad6-440f-b37f-6d196b469214
< 1.69
HIGH 7.2 The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
2c314acf-d5bb-433a-8e2d-4ca333944bb6 HIGH 7.2 The WordPress Database Administrator plugin for WordPress is vulnerable to SQL Injection via an AJAX action in versions … wordfence
2c2f0e74-cdc0-4da9-bd79-8d09f5459be7 HIGH 7.2 The Timeline Calendar WordPress plugin through 1.2 does not sanitise, validate or escape the edit GET parameter before u… wordfence
2bf0832c-13ed-4e53-9847-d5d2110eb3f8
< 10.6.1
HIGH 7.2 The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
2baf528d-a24b-4cad-99c9-5fef9df3fe6d HIGH 7.2 Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize us… wordfence
2b80fb3b-c874-468f-860b-ea0f93bb95bd
< 6.5.1.2
HIGH 7.2 The wpDataTables (Premium) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
2b737a26-e4ae-4c9f-a98a-a22a31ac4f99
< 1.6.7
HIGH 7.2 The Transbank Webpay REST plugin for WordPress is vulnerable to SQL Injection via the ‘oderby’ parameter in versions… wordfence
2b5d64b8-c339-4bbc-b91e-4805428f7296 HIGH 7.2 The Newsletter Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nl_data’ parameter i… wordfence
2b4aa268-a1c9-4ab0-8db4-483adae1d45e
< 3.8
HIGH 7.2 The WooCommerce Vehicle Parts Finder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
2b1933a5-48f3-4707-8e3d-824b60ce2635
< 2.0.9
HIGH 7.2 The My Sticky Elements plugin for WordPress is vulnerable to SQL Injection via the 'delete_message' parameter in version… wordfence
2b0f887c-b9e5-4d3c-b354-ebf5741dc3ba
< 1.3.8
HIGH 7.2 The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, … wordfence
← Prev 396 397 398 399 400 401 402 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top