🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 408 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
103db583-9399-4a45-a316-808b55fc6a6c
< 2.9.4
HIGH 7.2 The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for… wordfence
101f8390-7fd1-427d-a62e-83c527adedec HIGH 7.2 The DZS Video Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'initer' parameter in… wordfence
10101e3f-8c8a-4a62-bf41-809983a3b610
< 1.1.33
HIGH 7.2 The Heateor Social Login WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up … wordfence
0ffd60d2-ae8d-4738-a4f4-6df6e0ffa8c6
< 14.0
HIGH 7.2 The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the $days_time_list value in versions up to, a… wordfence
0ff05b7a-874a-4262-98a8-963f5fa1e48b
< 1.5.1.1
HIGH 7.2 The Assistant plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.1 via des… wordfence
0fe57abe-4354-46de-a742-d86722c381d8
< 2.3.6
HIGH 7.2 The AffiliateX – Amazon Affiliate Plugin, Product Boxes, Comparison Tables & Affiliate Link Tracking plugin for WordPr… wordfence
0faa8f07-88c1-4638-9de5-e202807866e1
< 3.28.32
HIGH 7.2 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to PHP Object Injection via deserialization of the '… wordfence
0fa6a112-ee69-43eb-bded-daba2c2c4dc5
< 12.4.0.3
HIGH 7.2 The PixelYourSite PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pysTrafficSource' param… wordfence
0fa49df8-6989-4099-be06-8b232c4f90ef
< 1.2.11
HIGH 7.2 The WP Time Slots Booking Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, … wordfence
0f8aa38b-85c5-45a7-b5cd-9ecd43a3c340 HIGH 7.2 The Customily Product Personalizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via user cookies in… wordfence
0f76c9f8-c57a-4875-b581-f67c9c60021c
< 1.3.1
HIGH 7.2 The Broken Link Notifier plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in… wordfence
0f6bc166-8489-44bc-862e-dd4dcc1dcff8
< 1.7.2
HIGH 7.2 The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due … wordfence
0ee7b30f-9d06-421c-af30-f20b774d389e
< 1.5.7
HIGH 7.2 The ARForms Form Builder plugin for WordPress is vulnerable to Cross-Site Scripting via an unspecified parameter in vers… wordfence
0e63ca03-f0dc-484d-8e2d-f77527595872
< 1.11.6
HIGH 7.2 The Z-Downloads plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, … wordfence
0e604d56-572f-4d60-b5ad-14c02ba9cc94
< 1.2.1
HIGH 7.2 The DSubscribers plugin for WordPress is vulnerable to SQL Injection via the ‘dsubscribers’ parameter in versions be… wordfence
0e27a9cb-0df8-4570-b7b5-7aa6c15d2e43 HIGH 7.2 A proid GET parameter of the WordPress支付宝Alipay|财付通Tenpay|贝宝PayPal集成插件 WordPress plugin through … wordfence
0e2734d5-b985-4153-ada1-06cc2992dcbd
< 3.6.0
HIGH 7.2 The Linet ERP-Woocommerce Integration Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insuff… wordfence
0de639a9-37a6-4a72-8afb-ff43de81a83c HIGH 7.2 The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in al… wordfence
0dd1ded1-8966-4247-ab75-17980f00f9b9
< 1.0.7
HIGH 7.2 The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead… wordfence
0d8ea1c2-7c6e-43b3-97ca-a06438d51d11
< 3.3.4.2
HIGH 7.2 The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.… wordfence
0d5a0c05-736f-4fb9-9358-894977664bf4
< 1.1.45
HIGH 7.2 The Event Calendar WD plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1.4… wordfence
0d012f97-9ccb-4ff6-a24a-df3c10bacc63
< 3.107.0
HIGH 7.2 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Rem… wordfence
0cf60aad-1c74-4da2-b62a-42582a74e0e9
< 9.2.3
HIGH 7.2 The NEX-Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2.2 … wordfence
0cd96a4b-8985-430d-b1b6-4176b6dd0bc1
< 2.7.2
HIGH 7.2 The Image Slider by Ays- Responsive Slider and Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
0cac7f96-eb64-427d-9a95-b8bf1c675af0
< 8.7
HIGH 7.2 The Salon booking system plugin for WordPress is vulnerable to privilege escalation in all versions up to, but excluding… wordfence
← Prev 405 406 407 408 409 410 411 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top