🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 420 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
35246286-c0df-4f82-84b8-ebefe966a4dc
< 1.4.8.1
HIGH 7.1 The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and includi… wordfence
34a6c9af-1616-4b5d-8660-4f141bdd25c9 HIGH 7.1 Cross-site scripting (XSS) vulnerability in ajax_functions.php in the GEO Redirector plugin 1.0.1 and earlier for WordPr… wordfence
33e010dd-d9b2-410c-8397-638def946fbe
< 2.0.9
HIGH 7.1 The Human Presence – Stop Form Spam Without ReCaptcha plugin for WordPress is vulnerable to Reflected Cross-Site Scrip… wordfence
334570f7-967b-4792-934c-ebe4c4f18490
< 3.3.25
HIGH 7.1 The My Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2… wordfence
32a24a9d-b902-4a66-83d5-c8e3b8dd7923 HIGH 7.1 The Delete Old Orders WordPress plugin through 0.2 does not sanitize and escape the date parameter before outputting it … wordfence
308b4cfa-3d4f-46a1-a6a8-eaa2653b4953
< 3.8.6.2
HIGH 7.1 The WP SpreadPlugin plugin for WordPress is vulnerable to Cross-Site Scripting in versions before 3.8.6.2 due to insuffi… wordfence
2f3c706f-fcce-4bcb-9773-ced011bf6407
< 1.60
HIGH 7.1 The Inactive User Deleter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
2dabb790-4f5e-447a-ad65-3f62ac7f6176
< 2.4
HIGH 7.1 The LWS Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.1. … wordfence
2c8ff4ec-9b40-4d59-b3b0-382f91042a4a
< 2.4.3
HIGH 7.1 The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data an… wordfence
2ba556d0-48f9-4953-a5aa-876284e56360
< 4.2.13
HIGH 7.1 The Gutenberg Template Library & Redux Framework plugin <= 4.2.12 for WordPress used an incorrect authorization check in… wordfence
29c47391-5d37-4f49-8806-1f378a6306d0
< 4.5.3
HIGH 7.1 The WP Meta SEO plugin for WordPress is vulnerable to unauthorized execution of tasks due to a missing capability check … wordfence
2950eb91-a232-42c5-8a28-96b770cb7c48
< 3.9
HIGH 7.1 The Real-Time Find and Replace plugin for WordPress is vulnerable to Cross-Site Scripting via the ‘REQUEST_URI’ para… wordfence
28286b89-0fcd-4616-8246-d8a19d632674
< 13.04
HIGH 7.1 Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remo… wordfence
2553a858-bbea-4ef2-8d45-e0a665123065 HIGH 7.1 Cross-site scripting (XSS) vulnerability in magpie_debug.php in the Twitter Feed plugin (wp-twitter-feed) 2.2 and below … wordfence
2482ef4b-697a-45a0-b45e-85b2af5b4735
< 1.4.3
HIGH 7.1 The Material Design Icons for Page Builders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
242ad509-32fd-4b28-b6e2-6c49b7288dde HIGH 7.1 The WP Html Page Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
22476135-8951-4012-845b-46a5dfbfc1f5
< 1.2.0
HIGH 7.1 The Gallery PhotoBlocks plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.1… wordfence
2111df14-63a3-4e3c-87b8-d0e71812d32c
< 1.5.1
HIGH 7.1 Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before … wordfence
1f9760f8-459d-4dcf-941d-f8f3f1e266ce
< 2.6
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in captcha\captcha.php in the Captcha! 2.5d and earlier plugin for W… wordfence
1e4e27e0-bbb0-498a-b425-9e9d60dfed0f
< 1.1.11
HIGH 7.1 The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' paramet… wordfence
1e4d03f0-408c-47da-bae9-38614603f02b HIGH 7.1 The SimpleDark Theme for WordPress is vulnerable to Cross-Site Scripting via the 's' parameter in versions up to, and in… wordfence
1bcc6192-b9fa-4444-b06d-2b44d53d9cfe HIGH 7.1 The WP Elegant Testimonial plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions… wordfence
1665fda6-005d-42ba-883d-2e3ad7abe0ba
< 2.1.7
HIGH 7.1 The WooCommerce Warranty Requests plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an unknown pa… wordfence
150a6dda-84de-49b1-9a8a-fcc1e0ba73d1
< 1.3.1
HIGH 7.1 The PDF & Print Button Joliprint plugin for WordPress is vulnerable to Cross-Site Scripting via multiple parameters in v… wordfence
14026e96-7e21-45db-b258-13b014ec478c
< 1.0.6
HIGH 7.1 The WP Private Message plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and inc… wordfence
← Prev 417 418 419 420 421 422 423 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top