πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 409 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0c58c1c6-cdda-463c-9a76-4ace96138dcb
< 0.92
HIGH 7.2 The Google Forms plugin for WordPress is vulnerable to Server Side Request Forgery in versions before 0.92. This allowed… wordfence
0c19d041-c26b-453e-b0fd-4304205469e4
< 4.3000000026
HIGH 7.2 The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads due t… wordfence
0bbdbd0f-19cc-4a1e-9167-fbdb6d45ffbe
< 1.4.2
HIGH 7.2 The GNUCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up… wordfence
0b8af407-b49d-4d3f-a7a5-c3ad3d56fcba
< 8.5
HIGH 7.2 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referer link in versions up … wordfence
0b82f5da-42ef-40b4-bfa4-26b88a3328db
< 2.1.0
HIGH 7.2 classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete ac… wordfence
0b75cad9-9f76-4839-8eb2-40d84662846d
< 3.20.4
HIGH 7.2 The Query Monitor – The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site… wordfence
0b668f45-c7fb-481b-bc8e-115e5b7248c9
< 4.0
HIGH 7.2 The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to… wordfence
0b658052-f283-4a47-a440-dbd7acded186
< 5.5.0
HIGH 7.2 The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Stored Cros… wordfence
0b4e6dae-f38c-4f5b-ae1d-cf998946c675
< 1.2.4
HIGH 7.2 The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to SQL Injection via the 'orde… wordfence
0b3acc5f-b2a5-4e7b-a596-9a934fe6ff87
< 6.2.0.9
HIGH 7.2 The Quiz Maker WordPress plugin before 6.2.0.9 did not properly sanitise and escape the order and orderby parameters bef… wordfence
0b0ff994-0348-48e4-86d4-eb723744f2b0
< 4.5.5
HIGH 7.2 The BetterDocs plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.5.4… wordfence
0ae8f5a1-680d-47c4-b009-16601eac13d9 HIGH 7.2 The All push notification for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
0add23c7-fef1-48c1-8395-5ddd2f4f8e8d
< 3.6.1
HIGH 7.2 The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in … wordfence
0aca6ac7-2002-4099-a17e-91f47b56b660
< 11.72
HIGH 7.2 The WPMobile.App plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 11.… wordfence
0a97a217-b00b-4268-a472-8d62ae1d18e3
< 7.12
HIGH 7.2 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS C… wordfence
0a8fc12b-4ca1-42ea-9362-8c39de27c98d HIGH 7.2 The Oyster - Photography WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
0a397025-ada7-4a59-80b9-5a778ea27776 HIGH 7.2 The Easy Pixels plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up… wordfence
0a309bf8-7fe3-4033-993c-3c8dba0f216d
< 5.4.12
HIGH 7.2 The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'User-Agent' header in … wordfence
09ec4633-7639-4d46-8070-9fc6909bc610
< 3.4.18
HIGH 7.2 The Types plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknown… wordfence
09e2d2d2-c79e-467d-a1a0-602d0d2d2709
< 8.5.1
HIGH 7.2 The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress … wordfence
09d9785a-db71-4735-b86b-7fa10cf36a0b
< 2.2.2
HIGH 7.2 The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl… wordfence
09c67364-a1cb-45cd-8573-1fd1b2325824
< 2.5.2
HIGH 7.2 The Gutenverse Companion plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and includ… wordfence
099cc754-6a56-498f-848a-a242733e7fb0
< 1.1.3
HIGH 7.2 The WP Mail Log plugin for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in all versions up to, an… wordfence
09935fd1-5a95-411a-a820-60888be7b059
< 3.8.2
HIGH 7.2 WordPress Core, in versions less than 3.8.2, is vulnerable to SQL Injection via the 'links_recently_updated_time' parame… wordfence
097fdc88-9424-4de9-9a03-d4ea724da13f
< 15.0.7
HIGH 7.2 The cformsII plugin for WordPress is vulnerable to stored Cross-Site Scripting via an unknown parameter in versions up t… wordfence
← Prev 406 407 408 409 410 411 412 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top