🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 406 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
16ac73ae-6a0a-4c9b-8830-e0745061e587
< 2.10.4
HIGH 7.2 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all vers… wordfence
168e7eac-21ad-43ca-93d1-73c38e12bc29
< 3.4.5
HIGH 7.2 The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions … wordfence
1664fef3-6416-4678-9ee7-bed2184d7490
< 4.0.4
HIGH 7.2 The Simple Membership plugin for WordPress is vulnerable to time-based SQL Injection via the 's' and 'status' parameters… wordfence
1653c4e0-c5e5-44c6-a84d-cdd070696ac4 HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
163fc78a-753e-4aa4-80d5-1b2a5f68e65a HIGH 7.2 The Flaming Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
1630129e-d983-4c44-92a4-357e1e471c9a
< 13.3.0
HIGH 7.2 The Free Gifts for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and … wordfence
162dff28-94ea-4a47-a6cb-a13317cf1a04
< 17.0.18
HIGH 7.2 The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, … wordfence
162a194c-a7de-44c4-a659-8188e303b6a2
< 3.6.5
HIGH 7.2 The WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads via the tax rate importer due to missing fi… wordfence
15e90f19-e4cb-4096-8192-85d4f1f5ec24 HIGH 7.2 The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Sto… wordfence
15d9817c-910d-4ce1-a5fb-67a2b6580e16
< 1.3.0
HIGH 7.2 The Injection Guard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via malicious query parameter name… wordfence
15ce2e54-ca5a-4dbc-9795-6e989e85b330
< 2.4.4
HIGH 7.2 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to miss… wordfence
15c35ed2-a614-4cac-8a2e-b1a2417919d7
< 1.1
HIGH 7.2 Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote atta… wordfence
15c2cc20-8d10-4e77-8009-df91e171183f
< 9.7.2
HIGH 7.2 The Image Hover Effects Ultimate plugin for WordPress is vulnerable to Arbitrary Options Update in versions up to, and i… wordfence
15b0cf88-cbb1-4264-af89-302822089284
< 1.1.1
HIGH 7.2 The WP Gravity Forms Constant Contact Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, … wordfence
1575f0ad-0a77-4047-844c-48db4c8b4e91
< 3.3.18
HIGH 7.2 The Multiple Page Generator Plugin for WordPress is vulnerable to time-based SQL Injection via the orderby and order par… wordfence
15679ce4-984a-4933-86c5-c8349b03abf9
< 1.2.6.5
HIGH 7.2 The Contact Form 7 Database Addon plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, … wordfence
155f765c-65ab-443a-a4b7-50d916e2903c
< 3.4.1
HIGH 7.2 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Remote Code Execution in all versions u… wordfence
1525e1c9-4b94-4f9f-92c5-fc69fe000771
< 2.1.3
HIGH 7.2 The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions u… wordfence
1500c72a-0621-4f97-9cab-0c9c8abeaf8f
< 2.6.0
HIGH 7.2 The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an… wordfence
14ebc642-ebe4-4493-859b-22192bc5b10d
< 1.1.8
HIGH 7.2 The GMap Targeting plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1… wordfence
14acb770-9a32-4308-993d-a3d3dec91f78
< 3.6.8
HIGH 7.2 The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to Reflected Cros… wordfence
14958861-305e-4a9b-b428-de204cd6781e
< 2.34.0
HIGH 7.2 The 404 Solution plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up … wordfence
14759eb0-455f-4b7d-abab-4e4d89b32bb1 HIGH 7.2 The DocoDoco Store Locator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
142bcbdd-7495-49be-a5b3-8ba1674cd64d HIGH 7.2 SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenti… wordfence
1419f089-7656-43a1-aeee-c33eef604c84
< 2.1.1
HIGH 7.2 The Ultimate Product Catalog plugin for WordPress is vulnerable to generic SQL Injection via the Catalogue_ID, SubCateg… wordfence
← Prev 403 404 405 406 407 408 409 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top