πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1018 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a3ecc238-1f84-47fd-96b9-753d4b528c47
< 2.4
MEDIUM 6.0 The WooCommerce - Store Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2… wordfence
8f1e6f04-04d4-4484-86bd-28df6388a953
< 3.4.0
MEDIUM 6.0 The Simple History plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 3.3.1. This all… wordfence
62ac66d8-fc10-4ec2-a567-7b95eb6f2c76
< 2.73.13
MEDIUM 6.0 The MapPress Maps for WordPress plugin before 2.73.13 allows a high privileged user to bypass the DISALLOW_FILE_EDIT and… wordfence
5dde4850-347f-40e6-9cea-87284aa655e7
< 0.9.76
MEDIUM 6.0 The WPvivid plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 0.9.75. This all… wordfence
084a209f-c67b-4df9-9f4b-c537ea065a50 MEDIUM 6.0 The Emails & Newsletters with Jackmail plugin for WordPress is vulnerable to CSV Injection in versions up to, and includ… wordfence
fa452a9a-9e26-41a1-8dea-4bafaf735bee MEDIUM 5.9 The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
f8bbab6e-ed2f-4b90-a658-aae85906d06e
< 3.2.1
MEDIUM 5.9 The Filter & Grids plugin for WordPress is vulnerable to SQL Injection via the 'phrase' parameter in all versions up to,… wordfence
f373a1d5-3d7e-4a0a-af03-28ca6ce6a170
< 7.15
MEDIUM 5.9 The All-in-One WP Migration plugin for WordPress is vulnerable to unauthenticated arbitrary back-up downloads due to ins… wordfence
e9f31ec5-c376-45b1-9ffe-35c80b89b60d
< 2.6.1
MEDIUM 5.9 The Feeds for YouTube Pro plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including… wordfence
d360de79-8490-4e70-b2d9-4f01a1ed3305
< 2.7.3
MEDIUM 5.9 The EUCookieLaw plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.7.2 vi… wordfence
d33199ea-7c96-4c60-a7b8-5c7e9835e231
< 2.3
MEDIUM 5.9 The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive … wordfence
c70bb3d6-6acd-46b2-8e47-30be031f73e4 MEDIUM 5.9 The asMember plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.5.4 d… wordfence
ab40146d-9b49-4214-af73-41c5b5512542
< 1.19.2
MEDIUM 5.9 The WP Crontrol plugin for WordPress is vulnerable to blind Server-Side Request Forgery in versions 1.17.0 to 1.19.1 via… wordfence
a1fadba1-674f-4f3d-997f-d29d3a887414
< 4.4.1.2
MEDIUM 5.9 The MainWP Child plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
97cef309-da2f-461a-b5a3-3a85c540c7aa
< 3.25.2
MEDIUM 5.9 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all … wordfence
8c052622-ac99-4069-b7df-41aea303ed9d
< 3.2.18
MEDIUM 5.9 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to time-based SQL Injection via the … wordfence
869d7cab-cf21-4168-b45d-1681c76d896c
< 2.3.6
MEDIUM 5.9 The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to… wordfence
7fc9bf38-0214-4f0d-9f3d-5ba0da9b76d9
< 1.5.5
MEDIUM 5.9 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.5.4 due… wordfence
7e98b1ef-70dd-408d-8644-08933bca1cdd MEDIUM 5.9 The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… wordfence
703ba736-5834-40f2-9cf6-a6a70a73e4d6
< 6.4.0
MEDIUM 5.9 The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_aj… wordfence
6ee6dedb-72bc-43b0-a7cb-9069533df705
< 1.5.6
MEDIUM 5.9 The User Blocker plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.5.5. This allow… wordfence
68f41e88-ed36-4361-bddd-41495a540cd9
< 2.01
MEDIUM 5.9 The WP Reset – Most Advanced WordPress Reset Tool plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
5f88a21d-28a9-4c91-9bf9-6b69f6a420e8
< 4.4.6
MEDIUM 5.9 The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Featu… wordfence
5652f9c3-3cc9-4541-8209-40117b4d25d9
< 1.15.23
MEDIUM 5.9 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Sensi… wordfence
4fd6df9d-2963-44b1-bc4e-e53eda97a2a9
< 6.5.0
MEDIUM 5.9 The Fancy Product Designer plugin for WordPress is vulnerable to Information Disclosure and PHAR Deserialization in all … wordfence
← Prev 1015 1016 1017 1018 1019 1020 1021 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top