πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 405 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
197449f5-9304-49df-9261-a354145fc00e
< 1.15.41
HIGH 7.2 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box… wordfence
194a4dd0-9cd2-477b-8926-360f8a8a0a0f HIGH 7.2 The File Manager Plugin For WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t… wordfence
1941f1e7-c65f-4894-8de7-1aeacf35fc69 HIGH 7.2 The EONSR AEO Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
18ff2556-9e20-42f6-a8fb-b81473c42576
< 3.9.16
HIGH 7.2 The Auto Featured Image (Auto Post Thumbnail) plugin for WordPress is vulnerable to Arbitrary File Upload due to insuffi… wordfence
18f16148-b4a8-4f89-af0d-c0baba8f9ccf
< 3.8.1
HIGH 7.2 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in ve… wordfence
18d1ba80-ddf6-4076-bc78-78647b964bcf HIGH 7.2 The CataBlog plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.7.0. T… wordfence
18a37063-31aa-4b1f-b1a5-1ea921a20686
< 4.4.18
HIGH 7.2 The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization… wordfence
188c4417-962a-4b28-b215-1c567b39ba7a
< 2.0.4
HIGH 7.2 The Nexter Extension plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.3… wordfence
188b6da2-1d4f-44af-82e1-a642170bcb36 HIGH 7.2 The Edit domain functionality in the WP Domain Redirect WordPress plugin through 1.0 has an `editid` parameter which is … wordfence
186180ed-321f-4618-8828-65b93fa054a4 HIGH 7.2 The Theme Demo Import plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.1… wordfence
184b9ae4-945a-4602-99da-679ff9db3029
< 6.0.1.1
HIGH 7.2 The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to … wordfence
183282c6-2069-4fb5-acbd-539aea265d74
< 2.0.13
HIGH 7.2 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to… wordfence
18003103-3a14-4cbc-8bed-87a8ab050308
< 26.1.1
HIGH 7.2 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or S… wordfence
17dd97b6-a186-4351-b08b-1eff696e25b1
< 4.7.5
HIGH 7.2 The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameteriza… wordfence
17d295d6-c594-4342-8be7-37f472a6310c
< 5.10.5.2
HIGH 7.2 The TheGem (Elementor) theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
1774b9b6-b98b-410c-98eb-326eda53adca
< 3.3.6.2
HIGH 7.2 Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress … wordfence
175eba7e-454b-4ba3-bbb5-22bd56734f5c HIGH 7.2 The Skitter Slideshow plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
172e740c-f69d-4b35-87fd-167530c5f8a0
< 1.1.3
HIGH 7.2 The NHR Options Table Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… wordfence
172b2191-6595-47dd-bf2d-97dc3d17e5ca HIGH 7.2 The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in vers… wordfence
17150263-261d-422f-8b36-a2981d4aaad3
< 1.5
HIGH 7.2 The tagDiv Opt-In Builder plugin is vulnerable to Blind SQL Injection via the 'couponId' parameter of the 'recreate_stri… wordfence
1714c26f-775a-4ccc-8b55-e85ca1fb3a84
< 4.0.7
HIGH 7.2 The Popup Builder WordPress plugin before 4.0.7 does not validate and properly escape the orderby and order parameters b… wordfence
170cd2e3-e31b-452e-8c15-d44a8be7757b
< 1.2.23
HIGH 7.2 The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on… wordfence
170bb0cc-85c0-41e2-a7e0-a082aee1e6c0
< 1.2.7
HIGH 7.2 The Affiliate Program Suite β€” SliceWP Affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
16ded5aa-c8e8-4d98-b07f-e689ad0e03c7 HIGH 7.2 The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' sh… wordfence
16d1eb4a-c68a-43b9-a514-d8751687709a
< 2.3.2
HIGH 7.2 The Debug Log Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
← Prev 402 403 404 405 406 407 408 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top