πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 401 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
273e25aa-4c00-4463-afc5-d8b2433af064
< 12.5.0.2
HIGH 7.2 The PixelYourSite Pro – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Server-Side Request Forge… wordfence
26e7c3fa-7ae7-4343-8494-2955cb755c6d
< 3.7.6
HIGH 7.2 The WPtouch plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.7.5.3 due to … wordfence
26926973-36b7-4ad2-8267-2de4749159ab
< 3.8.2
HIGH 7.2 The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records … wordfence
2672ce58-3358-4ae9-a2f9-0652012b6c2e
< 1.6.5
HIGH 7.2 The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
266bbcab-7d41-4c38-b136-24da61728977 HIGH 7.2 The AmpedSense – AdSense Split Tester plugin for WordPress is vulnerable to unspecified Cross-Site Scripting via an un… wordfence
2630dbfe-2e11-4671-9a75-377237ac1ea1 HIGH 7.2 The Steveas WP Live Chat Shoutbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shoutboxes in ve… wordfence
25f277f3-8b94-4ea2-ba84-885257690b18
< 2.7.6
HIGH 7.2 The NextGEN Gallery Voting plugin for WordPress is vulnerable to SQL Injection via the 'nggv[limit]' parameter in versio… wordfence
25e145b5-719b-4b7c-aee2-343e8418bf08
< 4.7.3
HIGH 7.2 The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
25bdc101-ba13-40fa-97af-75777a2f4bf8
< 2.15
HIGH 7.2 The Share This Image plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includ… wordfence
25bdb89f-3478-4a1a-8bf0-46e88207eb21
< 1.1.22
HIGH 7.2 The Cart All In One For WooCommerce plugin for WordPress is vulnerable to Code Injection in all versions up to, and incl… wordfence
25a8b9c9-da25-48b9-ada1-ca8a5941b2c2
< 11.6
HIGH 7.2 The plugin Very Simple Contact Form in versions up to and including 11.4 uses a captcha that can be bypassed by bots. Ve… wordfence
2596f703-7495-4769-8400-d813f63af9c6
< 5.5.6
HIGH 7.2 The CDI – Collect and Deliver Interface for Woocommerce plugin for WordPress is vulnerable to arbitrary file uploads d… wordfence
2584097a-8955-41c7-b009-c6502fe8b99b
< 1.8.0
HIGH 7.2 The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'feed_data' … wordfence
25543955-15b0-4dda-9636-c116db7f2838
< 2.3
HIGH 7.2 Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administra… wordfence
2535c00f-7725-48f2-a4a7-ea351b6f463b
< 2.3.12
HIGH 7.2 The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for … wordfence
25205cb9-6d8b-456a-82b8-7257668f2972 HIGH 7.2 The WP Logs Book plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including,… wordfence
24e7c30e-dac9-418a-ae0b-499f192139a4
< 3.5.8
HIGH 7.2 The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
24d0229c-0f1b-42df-b89a-ce0b8a3fda7e
< 1.0.1
HIGH 7.2 The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions… wordfence
24c9ff14-1d24-4c8c-b3d5-c2e0b5eb25fb
< 3.8.10.1
HIGH 7.2 The JetEngine plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.10… wordfence
24458c37-ebcc-471b-9044-78f24667f7a6
< 6.0
HIGH 7.2 The Bit File Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.2.7 … wordfence
24118410-e5a5-46fa-ac33-ce58cb2f75a3
< 5.0.26
HIGH 7.2 The YML for Yandex Market plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 5.0.26 (excl… wordfence
23feb72c-7e6f-436b-b56e-dc6185302d31
< 1.29.1
HIGH 7.2 The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. 3gpp file) i… wordfence
239f6fdc-d0d8-48e1-9ede-79087c1ee251 HIGH 7.2 The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Server-Side Request Forge… wordfence
234789db-1440-40ac-83e7-b8afb0ba4b5f
< 7.2.5
HIGH 7.2 The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typi… wordfence
2330005e-c3ab-4556-aba9-f194a1ace329 HIGH 7.2 The WP Events plugin for WordPress is vulnerable to generic SQL Injection via the "$_GET[β€˜edit_event']" parameter in v… wordfence
← Prev 398 399 400 401 402 403 404 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top