πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 412 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
042d9bc7-50ea-4585-9789-b10ed40b0d14
< 3.3.5
HIGH 7.2 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scriptin… wordfence
03fd0c97-7b50-4930-99ca-c9b37d7e4ade
< 1.32
HIGH 7.2 The Map Block for Google Maps plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
03faec37-2cce-4e14-92f2-d941ab1b4ce9
< 1.20.26
HIGH 7.2 The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the '… wordfence
03d8b8e7-5702-42d4-8cd9-ae3ff1a74a7e
< 5.4.5
HIGH 7.2 The Zero Spam for WordPress plugin is vulnerable to generic SQL Injection via the 'type', 'country', and 's' parameters … wordfence
03c8a13e-7484-40f1-907f-f3a5ace9f7e9
< 1.3.48
HIGH 7.2 The Falang multilanguage plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.47 du… wordfence
03c51b09-c304-488d-9405-0304597a7b97 HIGH 7.2 The Blog Floating Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and includ… wordfence
03986638-6fdb-4fa9-876c-fb6e90da38ea
< 2.9.5
HIGH 7.2 The WPFunnels Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.… wordfence
036467de-95bb-4bfd-9522-df8dc17f3102
< 5.11.2
HIGH 7.2 The Meta Box plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t… wordfence
03623f00-2c3c-4590-92fe-a5eaac15b944
< 2.9.2
HIGH 7.2 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜alt’ parameter in all v… wordfence
03542812-b6e5-421d-9ba6-43f1c779940f
< 1.22.4
HIGH 7.2 The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
035097dd-8ebd-49b8-93ea-0f957594f130
< 1.6.6
HIGH 7.2 The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the uuid parameter in … wordfence
034c38e3-98b7-4c31-8d43-981b1ba2ad22
< 1.0.3
HIGH 7.2 The Exit Intent Popup plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
03329efa-6ffd-42e1-ab7e-cc21cb48866f
< 8.9.6
HIGH 7.2 The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable befor… wordfence
033069d2-8e0f-4c67-b18c-fdd471d85f87
< 3.4.9.3
HIGH 7.2 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the X-Forwarded-F… wordfence
03123f2f-1241-445c-8d28-cb02e85795e3
< 1.3.2
HIGH 7.2 The TOCHAT.BE plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.… wordfence
02fe87e4-4275-4652-aec1-b25547071796 HIGH 7.2 The iONE360 configurator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Form Paramet… wordfence
02c6ec97-50cc-4c61-9bb7-b94250d5dda3
< 1.1.4
HIGH 7.2 The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on … wordfence
02b03c4a-1b2a-4fd0-887d-930229dc384f HIGH 7.2 The myLinksDump plugin for WordPress is vulnerable to SQL Injection via the 'sort_by' and 'sort_order' parameters in all… wordfence
02af50bf-d0f3-4dd7-89bd-dd60c33b5097
< 1.3.6.2
HIGH 7.2 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized modificati… wordfence
029ab433-baf5-47e3-92bb-dad14e268779 HIGH 7.2 The Car Repair Services theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and incl… wordfence
026ff6f4-077e-4fee-8fbe-8176f8ca5af3
< 7.6.12
HIGH 7.2 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the filename of an image… wordfence
0256b4ad-6094-4062-bdf7-c3fc0410557b
< 4.1.2
HIGH 7.2 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner β€” Groundhogg plugin for WordPress is vuln… wordfence
02480559-be5c-4d23-9e62-bb76fafb4f42
< 5.0.19
HIGH 7.2 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all ve… wordfence
0242c1e3-0828-426a-a514-907204d009d0
< 1.10.2
HIGH 7.2 The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and i… wordfence
022dcd52-0e6f-4979-9088-d257b6a5fc11
< 3.2.1
HIGH 7.2 The get_poll_categories(), get_polls() and get_reports() functions in the Poll Maker WordPress plugin before 3.2.1 did n… wordfence
← Prev 409 410 411 412 413 414 415 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top