πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 413 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
01e8e53c-8d23-4bd3-9291-29f97df7c984
< 1.6.0
HIGH 7.2 The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported … wordfence
01cfe0da-0ffc-4046-b58a-a31f5d10d1bd
< 1.7.7
HIGH 7.2 The WPForms Pro plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.7.6. This allows… wordfence
01ba4259-e76a-4876-b910-fd2688680739 HIGH 7.2 The IP Blacklist Cloud plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.00 due to… wordfence
01acb93b-89ae-4024-9f43-5fd14a7bd5f6
< 30.0.7
HIGH 7.2 The Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, … wordfence
017f5894-be0d-4b0f-82bd-13bf7e2ff53f
< 1.0.25
HIGH 7.2 The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ… wordfence
015db31a-eadf-4159-9be4-a455de791e35 HIGH 7.2 The DukaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.4 … wordfence
01370a71-2611-4826-b08b-485839ca606a
< 1.1.9
HIGH 7.2 The Booking Ultra Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in ve… wordfence
011fad07-0235-41e1-83b5-09588dd63d50
< 1.2
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject … wordfence
00fa12c7-5814-45f3-a35e-363cd0920e43
< 2.7.1.1
HIGH 7.2 The Arigato Autoresponder and Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u… wordfence
00df02cd-b4d3-477a-86ee-aa2f9b5216e8
< 1.8.9
HIGH 7.2 The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
00ab5d7e-be38-42ea-befc-e1d91de13d1b HIGH 7.2 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in ve… wordfence
0099a8d7-827d-4215-9a2b-b3c268fb5e97
< 4.9.8
HIGH 7.2 The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4… wordfence
0082e46d-fdbe-4ab7-bba3-0681a25d4495
< 0.9.113
HIGH 7.2 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary file uploa… wordfence
007ec879-7241-4dd2-9b81-93e44786bbcb
< 1.8
HIGH 7.2 The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found… wordfence
00687370-8374-44cc-8fd1-53b462acd061
< 1.8.0
HIGH 7.2 The iPanorama 360 plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and… wordfence
00500322-0984-49f5-8a6f-8cf72d125e6a
< 2.80.8
HIGH 7.2 The WP-DBManager plugin for WordPress is vulnerable to remote code execution due to an incorrect capability check in the… wordfence
00323c12-151d-42e4-a85c-76400bce1ec8
< 1.1.14
HIGH 7.2 The Header Footer Code Manager WordPress plugin before 1.1.14 does not validate and escape the "orderby" and "order" req… wordfence
002c6fea-4b76-47a6-9a39-1195f18aa6f6
< 1.9.1
HIGH 7.2 The Live Scores for SportsPress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
00162c25-bf56-42cf-b9bd-f6435e788d3d HIGH 7.2 The amr cron manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including,… wordfence
00138875-d892-460c-b0ce-7a01335d26dc
< 3.3.8
HIGH 7.2 The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action … wordfence
ff22c969-e580-4290-ab08-7c02b6eac938
< 1.3.8
HIGH 7.1 The Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 1.3.8 due to insuff… wordfence
fc91cae0-6d54-43f3-8c0e-d1f972573d13
< 3.5.16
HIGH 7.1 The WP No External Links plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β€˜page’ paramet… wordfence
fbbd3209-7ed6-4409-a24e-9f6225cf10f5
< 4.4
HIGH 7.1 The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to unauthorized data modification due t… wordfence
f7d80a23-f55d-4ab8-b139-daf5bc436d4f
< 2.7.6
HIGH 7.1 Cross-site scripting (XSS) vulnerability in captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin 2.7.4 … wordfence
f7926afb-b441-49bf-9af2-5bfc434319e3
< 1.0.11
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) … wordfence
← Prev 410 411 412 413 414 415 416 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top