🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 403 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1f9d8bbe-205f-44b6-a0c6-89b9135e6363
< 17.0.5
HIGH 7.2 The Contest Gallery – Files Upload and Contest Plugin for WordPress plugin for WordPress is vulnerable to SQL Injectio… wordfence
1f7e2323-42e9-4cc7-b3f4-d133e0073b7b
< 2.8.6
HIGH 7.2 The CM Download Manager plugin for WordPress is vulnerable to arbitrary file uploads because it allows administrators to… wordfence
1f533dbd-4dd0-48ec-b083-e6284acab067
< 4.9.3
HIGH 7.2 The Slimstat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in versions up … wordfence
1f37ed0e-3e03-4f00-9967-16047beab1cf HIGH 7.2 The MSync plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insufficien… wordfence
1f34302c-b08c-4542-9aa9-c66fe1f0288d
< 3.1.0
HIGH 7.2 The WP-CopyProtect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘CopyProtect_nrc_text’ … wordfence
1ed98565-3f86-46c0-a696-13d678f2d523
< 1.0.27
HIGH 7.2 The Rank Math SEO is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including 1.0.26. wordfence
1ed6c1c2-8fbd-4bcb-854a-492d1060364b
< 2.8.15
HIGH 7.2 The System Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includ… wordfence
1ec907bc-bd10-4dc5-be35-4f2aaf5ef444
< 20260110
HIGH 7.2 The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Store… wordfence
1ec45848-33b1-4088-ba06-9a12d291120e
< 3.5.4
HIGH 7.2 The Better WP Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inc/secure.php' file i… wordfence
1ec3cc3e-c11b-43b6-9dd0-caa5ccfb90c8
< 1.17.0
HIGH 7.2 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Re… wordfence
1e84fbbf-05b0-497b-81d8-1b029d24cddd
< 5.11.1
HIGH 7.2 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.1 did not properly… wordfence
1e72d5c7-c601-4775-a825-4786bbd1b5f0
< 2.04
HIGH 7.2 The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. Thi… wordfence
1e518d40-deda-438a-9787-b3cf7faad7a4
< 2.4.6
HIGH 7.2 The Import WP – Import and Export WordPress data to XML or CSV files plugin for WordPress is vulnerable to arbitrary f… wordfence
1e35eb83-716e-4177-99ba-24a884725265
< 2.169
HIGH 7.2 The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
1e273170-9c37-4f34-ab46-097d3eac47df
< 1.4.5
HIGH 7.2 The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.4.5 due to insuff… wordfence
1e223e0e-959f-498e-8c0e-daae36bd28cb
< 2.7.1
HIGH 7.2 The WP Easy Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 'galleryId' or 'select_gallery' … wordfence
1e0cf512-f676-4f47-abaa-5198998376b7
< 1.5.18
HIGH 7.2 The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome… wordfence
1e0c77a6-08fd-4d54-8ecd-6e5fe0e03e14
< 1.12.4
HIGH 7.2 The WP ERP plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in versions up to 1.12.4 due to … wordfence
1e0426e9-f6d8-40aa-9ceb-a3e5515ac316 HIGH 7.2 An id GET parameter of the Easy Testimonial Manager WordPress plugin through 1.2.0 is not sanitised, escaped or validate… wordfence
1e030085-a323-4275-848a-3c6cbc587748
< 1.0.59
HIGH 7.2 The Timetics – Appointment Booking Calendar & Scheduling System plugin for WordPress is vulnerable to Stored Cross-Sit… wordfence
1defa728-9f9d-4e8f-8f6c-432c615da7f5
< 2.2.0
HIGH 7.2 The Custom Payment Gateways for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a… wordfence
1de41980-93bb-4831-bb31-50675499f648
< 2.2.13.1
HIGH 7.2 The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before us… wordfence
1d8c5b14-6a4c-4d66-85cc-b6ab3b886ff7
< 1.6.10
HIGH 7.2 The Zippy plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ZippyC… wordfence
1d46033d-27aa-4d92-aa41-3547a3d17aff
< 1.6.1
HIGH 7.2 The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
1d4469e4-5d99-4a56-bde8-9a0aaca7794f HIGH 7.2 The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i… wordfence
← Prev 400 401 402 403 404 405 406 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top