πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 404 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1d14779f-3ee5-4a55-b49d-e9162db2f4a2
< 8.3.1
HIGH 7.2 The WP Statistics plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions… wordfence
1cbb309c-015b-4bdb-917a-a67e028484e6 HIGH 7.2 The Email Artillery (MASS EMAIL) WordPress plugin through 4.1 does not properly check the uploaded files from the Import… wordfence
1cae9918-be0b-416f-a81b-d08c826d8612
< 3.0.4
HIGH 7.2 The Internal Links Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
1ca3fe43-c579-4a8d-8747-6573f3ec7901
< 1.5.8
HIGH 7.2 The Gutenify plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.7 d… wordfence
1c94028c-a774-45ac-817d-ad9b966a3b51
< 2.7.26
HIGH 7.2 The Ad Inserter plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.7.25 via … wordfence
1c93b564-5428-4b0e-bbe8-f1e1e68940ac
< 2.32
HIGH 7.2 The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is … wordfence
1c63eaea-0a0f-412b-9f1a-3091de3a653a
< 2.0.5
HIGH 7.2 The Social Slider Feed plugin for WordPress is vulnerable to authenticated arbitrary API key update via the YouTube API … wordfence
1c19520b-531a-48d8-acfd-fc35bf860bc2
< 27.8
HIGH 7.2 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site … wordfence
1c09743a-cf0a-4eaa-8508-ecde32de4fce
< 3.7.6
HIGH 7.2 The WP Product Review Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
1c025fc0-5dac-4a18-8338-fefb2a1fca5a HIGH 7.2 The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to un… wordfence
1bd007fd-eee9-4c3c-b509-63e180e3fd28
< 1.5.2
HIGH 7.2 The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before … wordfence
1baa699e-b071-490c-b932-2dea603165e1
< 7.8.4
HIGH 7.2 The Ajax Load More – Infinite Scroll, Load More, & Lazy Load plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
1ba68898-da5d-40ef-87b8-51fd256788cc HIGH 7.2 The Logo Changer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.2… wordfence
1b5cf360-0163-4a7c-8979-ec89ec80ad62
< 26.0.1
HIGH 7.2 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or S… wordfence
1b162ef2-7428-47cc-91c6-c8f66512c5dc
< 4.2.3
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Slider Revolution (revslider) plugin 4.2.2 for WordPress allows remote a… wordfence
1ad2b168-5874-4b0f-8710-d9ed9afc54bf HIGH 7.2 The FAQs Manager plugin for WordPress is vulnerable to blind SQL Injection via the β€˜order’ and 'orderby' parameters … wordfence
1ad0d6eb-aafa-4f0b-bf1c-73d94e361087
< 1.8.6
HIGH 7.2 The Custom Product Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to… wordfence
1a7298ae-e1e6-4d3f-b4fb-9f9db9f3832d
< 1.3.3
HIGH 7.2 The Five Minute Webshop WordPress plugin through 1.3.2 does not sanitise and escape the id parameter before using it in … wordfence
19e48549-8a28-4626-b0b5-b781cd01fa5b HIGH 7.2 The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all version… wordfence
19e46bdd-3dd2-4199-8efa-fb1c0d25957b HIGH 7.2 The SOHO - Photography WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and… wordfence
19c2d455-ae47-49bd-9bb8-1f87b0c76c32
< 3.0
HIGH 7.2 The Image Hover Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
19b69d1e-84fd-446e-8de3-dad73bede5bb
< 6.18.14
HIGH 7.2 The SeedProd Pro plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 6.18.… wordfence
199c5480-f1ca-4607-a236-41ef177d8b42
< 1.1.0
HIGH 7.2 The WooCommerce Pricing – Product Pricing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver… wordfence
199a280f-a629-44f5-8ebe-399d86b5e0f1
< 2.2
HIGH 7.2 The Social Media Widget by Acurax plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜acx_si_th… wordfence
197760d1-395d-4dfb-aaa7-5fc5fc0a1ecb
< 1.2.2
HIGH 7.2 The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting… wordfence
← Prev 401 402 403 404 405 406 407 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top