πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 410 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
09773141-883b-40e3-bd20-d3115c02e023
< 2.07
HIGH 7.2 The Login Lockdown – Protect Login Form plugin for WordPress is vulnerable to SQL Injection via the β€˜sort order and … wordfence
09597618-8695-4631-8c3b-4e7580d58c86
< 2.2.11
HIGH 7.2 The License Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the orderby parameter in ver… wordfence
0955a596-d4bb-48fa-a515-a1aafe34048b HIGH 7.2 The SMM API plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.0.… wordfence
093af92e-bbc2-463a-8547-0e48fb356655
< 224
HIGH 7.2 The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scrip… wordfence
091d306d-cce4-426e-a18f-38bdaa802264
< 2.0.2
HIGH 7.2 The Responsive Image and video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜$_GE… wordfence
09152aa7-5c10-416a-aa77-a0cde1b6442e
< 2.7.7
HIGH 7.2 The ao_ccss_import AJAX call in Autoptimize Wordpress Plugin 2.7.6 does not ensure that the file provided is a legitimat… wordfence
09127277-9e71-484d-b674-52af693c995b
< 9.1.3
HIGH 7.2 The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable … wordfence
0903bd2b-240f-4791-bfa6-f727d193af4a
< 7.1.0
HIGH 7.2 The Booster for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing ca… wordfence
08df7ef5-fff0-4808-a79e-4d85cc9e2fa7
< 4.7.1
HIGH 7.2 The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-S… wordfence
08d15c46-d15f-4803-80be-90bf33335c18
< 5.7.0
HIGH 7.2 The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5… wordfence
08bbde25-bb9a-469c-83de-b680bb501ad6
< 4.1.11
HIGH 7.2 The Magic Post Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
08b75a3b-fb12-4b71-b207-468558e40fec
< 8.141
HIGH 7.2 The Kintpv Wooconnect plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu… wordfence
08ad76c6-8e63-4015-b0d9-5699f24f36ca
< 4.1.36
HIGH 7.2 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Privil… wordfence
08906577-162c-4875-b16c-18d4912c2611
< 6.1.4
HIGH 7.2 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Se… wordfence
0880ad7a-8886-44dd-9860-37b79d8e9a18
< 1.5.3
HIGH 7.2 The Store Locator WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida… wordfence
084e3f78-275b-4692-9cce-e17074f55cfb
< 5.6.7
HIGH 7.2 The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/… wordfence
08264ef7-940f-46b6-9880-34d730adad3c HIGH 7.2 The SurveyJS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5… wordfence
08077781-a9e5-421b-8768-777f9f7ab4aa
< 5.2.3.4
HIGH 7.2 The Survey Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includi… wordfence
080683bb-713f-4aa8-b635-90c96f358bec
< 2.13.3
HIGH 7.2 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val… wordfence
07fda92e-a085-42c7-a16d-1eace1dee195 HIGH 7.2 The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al… wordfence
07e110b3-ef10-482d-a564-c9f23631e5f3
< 3.14
HIGH 7.2 The CopySafe Web Protection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in versio… wordfence
07ab0bb5-841a-46ea-a726-bee17428a5df
< 9.1.3
HIGH 7.2 The Product Filter for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and… wordfence
07847ba1-cbce-4d81-bd24-46887ac31a5d
< 2.13.10
HIGH 7.2 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
0714273b-014e-4bed-b394-138f46a77eaa
< 1.8.14
HIGH 7.2 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbf… wordfence
070a5d26-9126-4d0e-9421-739090bea421
< 1.2.0
HIGH 7.2 The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header. wordfence
← Prev 407 408 409 410 411 412 413 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top