🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 417 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
91d72089-6ad9-401b-ab7b-0996e28d3be9 HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in frame-maker.php in the Walk Score plugin 0.5.5 and earlier for Wo… wordfence
9103c67c-d75f-469d-94f1-ce7877384417 HIGH 7.1 Cross-site scripting (XSS) vulnerability in main_page.php in the Game tabs plugin 0.4.0 and earlier for WordPress allows… wordfence
8ea25e80-af12-4845-b505-16654a68b009 HIGH 7.1 Cross-site scripting (XSS) vulnerability in the Easy Banners plugin 1.4 for WordPress allows remote attackers to inject … wordfence
8c529017-2fb9-4665-97a6-3ec062908299 HIGH 7.1 The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SV… wordfence
87e9d29b-9e0d-409c-97a5-7c444dff7382
< 1.1
HIGH 7.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration screen in wp-relatedposts.php in the WP … wordfence
868bbe8c-6d21-4d4b-ae23-e08dfb7a1277
< 3.0
HIGH 7.1 The Ultimate Profile Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting v… wordfence
85fd3e3c-f1cb-4384-86fd-3691f1deb963
< 2.0.6
HIGH 7.1 Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5). wordfence
84c4e3cc-1f7c-4ed9-9072-32f3e84419c9 HIGH 7.1 The Booking Calendar plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev… wordfence
822b5a6b-0be6-4511-bf5d-c32574f27865
< 3.2.6.8
HIGH 7.1 be_teacher in class-lp-admin-ajax.php in the LearnPress plugin 3.2.6.5 and earlier for WordPress allows any registered u… wordfence
7bfd8c31-4f89-4f09-8d46-11340c4eea1d HIGH 7.1 The Backup and Restore plugin – WordPress plugin for WordPress is vulnerable to arbitrary file deletion due to insuffi… wordfence
7a4ef9e6-2299-4024-a6a9-482199ca06db
< 2.3.1
HIGH 7.1 There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme befo… wordfence
78e7d0f7-b588-407b-bb3e-068589114ab0 HIGH 7.1 Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attacke… wordfence
74f8af2b-69fb-41db-b978-62709322aed3
< 20.13.7
HIGH 7.1 The Email Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘search’ parameter… wordfence
74b81d31-8ee6-47cf-a5e8-3cf0900ebea0
< 2.6.7.2
HIGH 7.1 The Events Manager Pro, versions up to 2.6.7.2, and Events Manager, versions up to 5.9.7.2, plugins for WordPress are vu… wordfence
736e51d4-da1d-4252-a10f-d89eb6a68de4
< 2.26.5
HIGH 7.1 The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2loc… wordfence
721f7c9e-34f3-4c41-992d-df35b56f95cd
< 3.2.6
HIGH 7.1 The Count per Day plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP Referer header in ve… wordfence
710574a8-a6e2-4ee6-9ea7-03a34994fec7
< 3.2.1
HIGH 7.1 The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… wordfence
7061781d-999b-47a7-b4b2-f0335c6247f8 HIGH 7.1 The Gaxx Keywords plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,… wordfence
70544986-af4a-48e4-8497-8ee78589676e HIGH 7.1 The "FLASH PLAYER PLUGIN" plugin for WordPress is vulnerable to Cross-Site Scripting via the 'plfilter' and 'search' par… wordfence
6f8945e9-51db-46aa-b198-3762b6628553
< 2.52
HIGH 7.1 Cross-site request forgery (CSRF) vulnerability in the Options in the WP-Print plugin before 2.52 for WordPress allows r… wordfence
6b78e1e8-2298-4889-955c-e9b7472ffbff
< 1.2.13
HIGH 7.1 The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘json… wordfence
6a639d27-8704-4841-b2b5-6afbf342a0ff
< 3.2.6.9
HIGH 7.1 Versions below 3.2.6.9 allow an attacker to publish or trash any existing post or page, or even set it to a nonexistent … wordfence
69725919-490c-4357-872c-d8112af5fe40
< 6.4.2
HIGH 7.1 The Import all XML, CSV & TXT into WordPress plugin for WordPress is vulnerable to authorization bypass due to a missing… wordfence
683e10af-5414-4959-9823-93e88e84bb1b
< 2.0.21
HIGH 7.1 The Crowdsignal Dashboard – Polls, Surveys & more plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
66ddb0f7-4d4c-4c4f-b766-9a07609cd0e5
< 3.8.1
HIGH 7.1 The Fruitful theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘author’ parameter in versi… wordfence
← Prev 414 415 416 417 418 419 420 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top