🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 421 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
13f6bf06-2c24-43ac-9412-08b3d4914a21
< 1.5.3
HIGH 7.1 Cross-site scripting (XSS) vulnerability in wp-tmkm-amazon-search.php in the wp-tmkm-amazon plugin 1.5b and earlier for … wordfence
13b0f306-cfd1-4c36-b694-de7968f0ae1c
< 1.0.19
HIGH 7.1 The Optinly plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJA… wordfence
12acf651-6476-491b-84b3-afbc6c655b17
< 1.10.19
HIGH 7.1 The plugin Popup by Supsystic for WordPress is vulnerable to prototype pollution, which could make injecting malicious w… wordfence
1161f41b-1594-4b1b-8a89-44a5a5a9dca6
< 1.0.126
HIGH 7.1 The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in u… wordfence
10a54a3b-db6d-45c5-9280-7042ccc17ccd
< 8.1
HIGH 7.1 The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Multiple Cross-Site Scrip… wordfence
1080810b-ec9a-44fb-b4da-49b28646a441
< 1.19.21
HIGH 7.1 The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp… wordfence
106b31ed-d509-4551-a134-02193ab22fe1 HIGH 7.1 The DASHBOARD BUILDER – WordPress plugin for Charts and Graphs plugin for WordPress is vulnerable to Cross-Site Reques… wordfence
0f9d18a4-262b-4011-91e9-b29a27a76470
< 2.1.5
HIGH 7.1 The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. Th… wordfence
0f87d37a-879f-4506-a651-8c965a558e28
< 1.0.1
HIGH 7.1 The Thumbnail carousel slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting and Cross-Site Request F… wordfence
0f20c7d3-8987-4dc0-9d97-98a29adbab85 HIGH 7.1 The WP Shopping Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
0e46ac8d-89ee-4480-bb96-83f2044a4323
< 3.0.3
HIGH 7.1 The wpForo Forum plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 3.0.2. Th… wordfence
0e43d6fc-28f1-4208-a529-f264304fe8aa
< 10.38
HIGH 7.1 The Subscribe2 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 10.37.… wordfence
0d4420bf-1095-44ca-8fa6-dd5ea11c7489
< 1.3.32
HIGH 7.1 The Findgo theme for WordPress is vulnerable to Cross-Site Scripting in versions before 1.3.32 due to insufficient input… wordfence
0b6e9430-bb78-47c3-9958-4f40028c3d93
< 5.0.5
HIGH 7.1 Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows… wordfence
0b540fed-e358-485f-8c12-f2241078459a
< 2.0.0
HIGH 7.1 Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin be… wordfence
0903521d-3b07-4539-97c9-15e6bbe2cc2e
< 9.1.05.009
HIGH 7.1 The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ par… wordfence
0593311a-54d7-42b2-ad5e-185938b42452 HIGH 7.1 The Portfolio Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on se… wordfence
0406b7a0-517d-4462-9b65-d4f708cf364d
< 2.0.11
HIGH 7.1 Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress al… wordfence
02ac8b9e-bc59-4c46-9f9c-23e3b6ae615c HIGH 7.1 The Picture Factory plugin for WordPress is vulnerable to Cross-Site Scripting due to insufficient input sanitization an… wordfence
026f8d9b-a66b-4a59-8375-fba587a4eef7
< 1.6.5
HIGH 7.1 The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable … wordfence
01105d96-e181-4228-b785-074a4b49ce18
< 3.0.0
HIGH 7.1 The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting via several p… wordfence
00a1b66d-d81c-4539-846b-ff66301a94ca
< 4.2.6
HIGH 7.1 The SearchWP Premium plugin for WordPress is vulnerable to authorization bypass due to leaking a nonce protecting a func… wordfence
0089498d-c4b3-4167-8bf4-8d9f68a4cbd0
< 1.6
HIGH 7.1 Multiple cross-site scripting (XSS) vulnerabilities in the All-in-One Event Calendar plugin 1.4 and 1.5 for WordPress al… wordfence
8f617090-f2cf-4ac4-8d09-c1d5c21e120d
< 1.3.8
MEDIUM 6.9 Authenticated Stored Cross-Site Scripting (XSS) vulnerability in YITH Maintenance Mode (WordPress plugin) versions <= 1.… wordfence
3589fd35-df91-48fb-b3be-4954f1e05656
< 1.4.0
MEDIUM 6.9 Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities in YITH Maintenance Mode (WordPress plugin) ver… wordfence
← Prev 418 419 420 421 422 423 424 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top