🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 400 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2af996d2-7430-4367-8fd9-212df6106fb0
< 1.3.1
HIGH 7.2 The SiteGround Security plugin for WordPress is vulnerable to blind SQL Injection via some if its filtering and paging p… wordfence
2abd400b-c633-4b38-ad3e-c9ce602ff07f
< 4.3.4.3
HIGH 7.2 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
2ab8f440-2910-41a3-8bbc-afb4cafd33b5
< 5.6.3
HIGH 7.2 The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
2a541529-ef53-468c-a7f0-0cd6822bd17b
< 4.14.6
HIGH 7.2 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
29fee127-73f5-4cd5-9bfb-799f1c0a9f83 HIGH 7.2 The Add new scene functionality in the Responsive 3D Slider WordPress plugin through 1.2 uses an id parameter which is n… wordfence
29f835c8-769a-47c0-832f-622860b1c59c
< 1.8.3
HIGH 7.2 The Lenix Elementor Leads addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a URL form field i… wordfence
29ef1755-f1c4-4251-bd4c-2fe97f291994 HIGH 7.2 The Music Request Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
29d13457-ac60-4e3d-9d8b-0141e6f8f4f6
< 1.32.1
HIGH 7.2 The Name Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via double HTML-entity encoding in … wordfence
29b9cb4a-741d-4c38-b458-abd9900a8dce
< 2.3.6
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.3.6 for WordPress allows remote attackers to… wordfence
29b471ac-3a08-42da-9907-670c3b3bae92
< 1.12.7
HIGH 7.2 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin f… wordfence
29b1bab8-0620-4d4b-a3c7-dfadd3a156e1 HIGH 7.2 The Virtual Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
29a7aa52-ebbf-4185-a9ed-c24cb7d1f03b
< 0.21.4
HIGH 7.2 The Tainacan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 0.2… wordfence
294b2a7c-8b54-4022-a3af-9a3e3d1d4c11
< 3.3.9
HIGH 7.2 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Objec… wordfence
2942644d-c330-4ec0-ab1d-64b3044d5a87
< 2.2.7
HIGH 7.2 The Wholesale Suite – B2B, Dynamic Pricing & WooCommerce Wholesale Prices plugin for WordPress is vulnerable to Privil… wordfence
28dfc8c9-478c-48b2-8781-7e0787fd50fd
< 1.4.6.1
HIGH 7.2 The WPS Limit Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP address value that can … wordfence
28ca8dd9-2149-42b3-94fd-4a1fabc3e891 HIGH 7.2 The Do Lasso plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 358 due… wordfence
28bdad82-f09a-461f-b826-3f458f121fea
< 2.0.1
HIGH 7.2 The Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam plugin for Word… wordfence
289569f5-8a8d-4427-8ad4-e431c955311e
< 2.2.1
HIGH 7.2 Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti… wordfence
28624634-9161-4da7-89f3-88ce1d38c3ea
< 2.3.1
HIGH 7.2 The 404 to 301 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' and 'User-Agent' HTTP… wordfence
28174722-5936-47ea-9d7d-93da269bc26b
< 2.7.2
HIGH 7.2 The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.7.1… wordfence
27d26d1c-d027-4a22-af49-4d7684d36d40
< 1.1.6
HIGH 7.2 The WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms plugin for WordPress is vulnerable to … wordfence
279a02e1-7b61-4edd-ab67-6a7fed4e17c1
< 1.5.0
HIGH 7.2 The iPages Flipbook For WordPress plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in all v… wordfence
2799c74a-4ebf-4996-b681-08c32bf07114 HIGH 7.2 The Easy Newsletter Signups plugin for WordPress is vulnerable to SQL Injection via the 'nsl_id' parameter in all versio… wordfence
2783f62a-3b9a-45e1-8e90-121732dc17ec
< 5.1.4
HIGH 7.2 The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.1.3… wordfence
2768f926-16a8-4a7e-a022-a8bd638e1081
< 1.5.17
HIGH 7.2 The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to unauthorized modification of data that can … wordfence
← Prev 397 398 399 400 401 402 403 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top