ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 407 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
13dbda83-d309-4723-9876-1b19f5ab4620
< 1.2.10
HIGH 7.2 The Spam Protect for Contact Form 7 plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 1.… wordfence
13c9a71f-ec0a-4d4a-be08-787aa22a0fae
< 1.2.25
HIGH 7.2 The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameter… wordfence
13be8a88-bcd3-4ce9-9538-e93c78323456
< 4.9.0
HIGH 7.2 The EAN for WooCommerce plugin for WordPress is vulnerable to arbitrary options updates n all versions up to, and includ… wordfence
13a96e78-c83c-4ff1-a751-3dbaeb683d9d
< 1.8.9
HIGH 7.2 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe… wordfence
13101551-d62e-4b27-9156-5b3d022f0e55
< 9.9.4
HIGH 7.2 The RSVPMaker plugin for WordPress is vulnerable to SQL Injection via the 'delete' parameter in versions up to, and incl… wordfence
12fe64ad-2998-4f41-b8d7-aa5921b0d0d9
< 1.69.234
HIGH 7.2 The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
12f3dc64-322d-4015-8c57-eaa41c9a1829
< 2.2.16
HIGH 7.2 The EventON plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
12b1b1b4-a62f-451e-a78d-c1d85202a4cf
< 5.3.4
HIGH 7.2 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via room… wordfence
12a9fbe8-445a-478a-b6ce-cd669ccb6a2d
< 1.1.3
HIGH 7.2 The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
12817b77-17d0-418c-a9a1-87d0057da90e
< 1.6.12.4
HIGH 7.2 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
1268bdb9-7f80-4fdc-a95a-d51b0ab83e17
< 4.2
HIGH 7.2 The The School Management – Education & Learning Management plugin for WordPress is vulnerable to SQL Injection via an… wordfence
125e7ea3-574a-4760-b10b-7a98d94c87a5
< 1.6.0
HIGH 7.2 The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the id para… wordfence
124f2b72-d8da-46ba-844f-e9cc01441702
< 8.5.0
HIGH 7.2 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cro… wordfence
120514af-41d8-49ca-be87-28c7d4777fee HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in cryptographp/admin.php in the Cryptographp 1.2 and earlier plugin… wordfence
120313be-9f98-4448-9f5d-a77186a6ff08
< 1.3.3
HIGH 7.2 The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio… wordfence
11f883d2-c183-4cc9-a330-6c50610a5c39
< 1.0.8
HIGH 7.2 The Shariff Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shariff_image' paramete… wordfence
11a469e8-d6af-4ad7-98aa-9f74d0318947
< 16.9
HIGH 7.2 The User Extra Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including… wordfence
1148b18d-7af1-41c6-bd7f-1b2d53cb44e6 HIGH 7.2 The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check… wordfence
11305d35-07d6-4c61-a0c7-035671229f07 HIGH 7.2 The bbPress Toolkit plugin for WordPress is vulnerable to Unspecified Cross-Site Scripting in versions up to, and includ… wordfence
112456a9-8bb6-4007-87da-6d0fba912498
< 1.2.26
HIGH 7.2 The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Stor… wordfence
1106e7b2-eac7-459d-8eb3-fe84c76f3b67
< 3.10.1
HIGH 7.2 The Custom 404 Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several logged parameters in al… wordfence
11043029-1b77-4e18-bdd8-fca2eadc6901 HIGH 7.2 Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.11 and earlier for W… wordfence
109a99ca-1173-4367-b8a7-c3d8cffcfcaf
< 2.4.5
HIGH 7.2 The Chatbot with ChatGPT WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
106fd83b-2ab0-4fcf-8c73-ba18ba9dbe56
< 2.4.19
HIGH 7.2 The Kali Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.4.1… wordfence
105ae6be-2cb7-4ab2-8e4c-5d3ff84c5b9f
< 4.9.5
HIGH 7.2 The Download Monitor plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter in all versions up to… wordfence
← Prev 404 405 406 407 408 409 410 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top