πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 411 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
06e0f191-27e7-478d-a6ad-351b22311fbf
< 2.5.49
HIGH 7.2 The Houzez Property Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
06c63f82-fe0f-435c-9cf8-5db6a7ce0677
< 3.4.8.3
HIGH 7.2 The Tickera WordPress plugin before 3.4.8.3 does not properly sanitise and escape the Name fields of booked Events befor… wordfence
06bc7a24-eafc-4b06-852e-9b596f107805
< 1.6.0.2
HIGH 7.2 The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper i… wordfence
06b31f3a-8516-427c-b819-7bcf2717705b
< 0.3.4
HIGH 7.2 The Custom Icons for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
066e9f46-83a5-4a2f-ae09-6d06c5c66817
< 1.4.6
HIGH 7.2 The Form Vibes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insuff… wordfence
0659aca3-6b72-460f-8bf4-e7ad17b74773
< 3.1
HIGH 7.2 The Product Enquiry for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to,… wordfence
06156cb7-baa0-4e66-a146-505b09698a4a
< 12.8.4
HIGH 7.2 The Real Estate Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inc… wordfence
06063978-6c61-42e0-bf03-092aaa20d850
< 2.5.3
HIGH 7.2 The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up t… wordfence
05fc4b17-7922-45a4-aac8-a47b3f50ce69
< 1.0.12
HIGH 7.2 The LTL Freight Quotes – Freightview Edition, LTL Freight Quotes – Daylight Edition and LTL Freight Quotes – Day &… wordfence
05f7d9fe-e95f-4ddf-9bce-2aeac3c2e946
< 3.2.0
HIGH 7.2 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text ar… wordfence
05de038f-eff4-4b00-930c-3d2335345869 HIGH 7.2 The URL Preview plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
05b434f7-6bce-4ad0-bd12-db5b01f14953
< 1.15.19
HIGH 7.2 The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type_textarea' field … wordfence
05a5b6be-0253-479c-a80f-19de7d8af1a5 HIGH 7.2 The Kids Zone - Children WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a… wordfence
057216e2-3fad-49fc-ac31-06dbd7b110f9 HIGH 7.2 The Flaming Password Reset plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and incl… wordfence
055d50de-8a7f-40fa-88e9-f57046c0c450 HIGH 7.2 The Custom Login And Signup Widget plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, an… wordfence
055979ad-84d9-4f72-872d-ee86b9b062af
< 2.6.1
HIGH 7.2 The GDPR Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP headers in all versions… wordfence
0506f360-17c3-4cc8-9ac7-988c056c3caf
< 1.15.6
HIGH 7.2 The Form Maker plugin for WordPress is vulnerable to SQL Injection via the β€˜id’ parameter in versions up to, and inc… wordfence
05042006-aff6-4ba6-ae67-249dc0dcbb93 HIGH 7.2 The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter befor… wordfence
04a937d0-9844-49d1-bcb5-0ee6026c3947
< 3.0.3
HIGH 7.2 The Chaty plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficien… wordfence
04a64a52-f0a0-4559-834d-88d3edd1bb6a
< 6.5.8
HIGH 7.2 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.5.7… wordfence
049ec264-3ed1-4741-937d-8a633ef0a627
< 1.0.88
HIGH 7.2 The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in… wordfence
04689f95-30ea-4b68-b50c-c00ed6ab835b
< 1.13.20
HIGH 7.2 The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.13.… wordfence
045fdfd8-7c4a-4fa8-81fd-f749777fb9ed
< 1.6.2
HIGH 7.2 The Educare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.6.1 du… wordfence
045f52f2-b77d-4ddb-a674-0fccf3e6dc7d
< 3.135.1
HIGH 7.2 The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 3.135… wordfence
0448eb1c-1a4a-465e-aa30-e4af10d27560 HIGH 7.2 The Mini Cart plugin for WordPress is vulnerable to SQL Injection via the β€˜item’ parameter in versions up to, and in… wordfence
← Prev 408 409 410 411 412 413 414 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top