🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 402 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
22ff4b09-063b-425e-9d59-be2e5d283186
< 2.33.1
HIGH 7.2 The Give - Donation Plugin plugin for WordPress is vulnerable to privilege escalation due to an insufficient capability … wordfence
22cb2bc4-ddf1-4e23-af1c-4f59ff88e9e1
< 1.1.3
HIGH 7.2 The Spider Calendar plugin for WordPress is vulnerable to generic SQL Injection, Cross-Site Scripting, and Parameter Pol… wordfence
22bcfd36-ecf9-4d2c-ac94-94ffa0340c4c
< 5.2.6
HIGH 7.2 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross… wordfence
22a5020a-ab81-43be-b160-082347a2a2d9
< 2.5.8
HIGH 7.2 The Custom Field Template plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2… wordfence
225900ea-ab59-4864-a65b-583730d2703f
< 1.4.8
HIGH 7.2 The Testimonial WordPress Plugin WordPress plugin before 1.4.7 does not validate and escape the id parameter before usin… wordfence
222079a2-20f1-4d53-8420-46ccc50988a8
< 6.83
HIGH 7.2 The Spam protection, AntiSpam, FireWall by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting i… wordfence
220b0e71-8e80-4a29-982e-259a475835fe
< 1.15.7
HIGH 7.2 The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via th… wordfence
21e06220-c8f0-4754-ba19-8df519be4038
< 5.185.1
HIGH 7.2 The AntiSpam plugin for WordPress is vulnerable to SQL Injection via the ‘ids’ parameter in versions up to, and incl… wordfence
21c87602-bbe7-4fde-8ba2-031120212a8b
< 15.8
HIGH 7.2 The WP Symposium plugin for WordPress is vulnerable to blind SQL Injection in versions before 15.8 due to insufficient e… wordfence
21c31df6-7515-48f5-ad74-fe116e836da8 HIGH 7.2 The MagicForm plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.1 due to in… wordfence
213b6dec-a64d-4597-a079-8fb82df9c8b4
< 1.3.3
HIGH 7.2 The Five Minute Webshop WordPress plugin through 1.3.2 does not properly validate and sanitise the orderby parameter bef… wordfence
2131e418-bd95-4bd1-868f-0bd3b4abdf78
< 0.18.10
HIGH 7.2 The plugin Tainacan for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 0.18.9 due to … wordfence
211634f6-afc4-4841-8851-6c56a248af95 HIGH 7.2 SQL injection vulnerability in the GD Star Rating plugin 1.9.22 for WordPress allows remote administrators to execute ar… wordfence
2105a26a-0813-4f63-a28d-6b3bd68ea9a1
< 3.3.66
HIGH 7.2 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.3.66 due to i… wordfence
20eff8fc-0572-40b9-ab28-758c7ab8ed73
< 5.3.2
HIGH 7.2 Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin… wordfence
20d989d9-6bf0-4f9f-acf4-b4c3452855cc
< 3.7.1
HIGH 7.2 The Custom 404 Pro plugin for WordPress is vulnerable to blind SQL Injection via the ‘path’ parameter in versions up… wordfence
20d30931-bfaf-47bb-9265-b326c959b871
< 1.7.29
HIGH 7.2 The Contact Form by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and inc… wordfence
209019bd-b214-4389-a972-42e38d501203
< 2.6.4
HIGH 7.2 The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPr… wordfence
2085c9a3-1cc7-4750-875e-d20c7f94bb78
< 7.3.5
HIGH 7.2 The Quiz And Survey Master plugin for WordPress is vulnerable to SQL Injection via several parameters in versions up to,… wordfence
20720912-6bfd-4df1-97c7-7025c16d7a0f
< 4.0.2
HIGH 7.2 The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' paramet… wordfence
206eee58-af07-426d-8c11-7a5e5ec52ddc
< 3.1
HIGH 7.2 The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up t… wordfence
2046c6cf-32fa-4fac-a4bc-00f11f739d14
< 1.8.3
HIGH 7.2 The Website File Changes Monitor plugin for WordPress is vulnerable to SQL Injection via the ‘path' parameter in versi… wordfence
2013b9ac-7853-40b9-8bef-7207ccd58eb1
< 5.5.2
HIGH 7.2 The miniorange otp verification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
1fe257e6-4bdf-49ef-adbb-f82ce378e3e7
< 2.4.12
HIGH 7.2 The Five Star Restaurant Reservations plugin for WordPress is vulnerable to authorization bypass due to a missing capabi… wordfence
1fb05281-205f-4d9c-aac9-2b37e069a6fb
< 3.2.16
HIGH 7.2 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via S… wordfence
← Prev 399 400 401 402 403 404 405 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top