πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1019 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4eeae6dd-a41f-4878-aa92-064ec78367d7
< 6.7.0.57
MEDIUM 5.9 The Quiz Maker plugin for WordPress is vulnerable to SQL Injection via spoofed IP headers in all versions up to, and inc… wordfence
3cb73d5d-ca4a-4103-866d-f7bb369a8ce4
< 3.7.2
MEDIUM 5.9 The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Seco… wordfence
33e8a48e-0ddb-4278-a023-818aebe92dab
< 2.6.1
MEDIUM 5.9 The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before … wordfence
30147e39-af94-4620-870b-71a0a46b7509
< 1.6.2
MEDIUM 5.9 The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Sensitive Information Exposu… wordfence
2fdc32a4-adf8-4174-924b-5d0b763d010c
< 1.12.3.1
MEDIUM 5.9 The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
2745a40c-b011-4fe5-b2f7-d97ee6972568 MEDIUM 5.9 The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in a… wordfence
254b5dd2-c3d9-45d9-8328-6cc8ef29c9db
< 5.5
MEDIUM 5.9 WordPress up to version 5.5 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier fo… wordfence
20caab24-4af7-4592-9b18-f2f5acb423c9
< 1.3.0
MEDIUM 5.9 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Reads in all versions u… wordfence
1dbdc673-b0ee-4d1d-8cd9-603056f41cda
< 1.51.0
MEDIUM 5.9 The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl… wordfence
18d6dffd-8df3-4611-ad94-6d806aa7328a
< 3.25
MEDIUM 5.9 The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
12ab3e54-a0b9-4420-ac90-f16e23688cca
< 5.5.0
MEDIUM 5.9 The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure … wordfence
02066dcd-1f2f-4ed3-b1f4-7ea8711918e8
< 5.2.0
MEDIUM 5.9 The All In One WP Security plugin for WordPress is vulnerable to sensitive information disclosure in version 5.1.9. This… wordfence
01def852-367b-4f64-9c5a-58dcc3478b2e MEDIUM 5.9 The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an at… wordfence
fa995fa9-5fb1-434a-bf88-c60e986c45eb
< 6.7.1.30
MEDIUM 5.8 The Quiz Maker by AYS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rate_reason' parameter … wordfence
dcbd6f84-06b5-4430-94b0-68471ca47fc0
< 1.4.1
MEDIUM 5.8 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Unauthenticated Arbitrary Email Sending in… wordfence
dc7ba538-a7ee-48c8-996c-b8db1934fdeb
< 8.2.7
MEDIUM 5.8 The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6… wordfence
d9f1719c-ef66-4c68-b25c-175c99938e7a MEDIUM 5.8 The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file … wordfence
d89918e1-b525-4d32-9b11-5e014eb02c16
< 6.4.2.8
MEDIUM 5.8 The Auto Affiliate Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
d6ae7c9f-852d-428f-a469-6bfeead53db5
< 2.8.65
MEDIUM 5.8 In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of al… wordfence
d31d0553-9378-4c7e-a258-12562aa6b388
< 6.9.4
MEDIUM 5.8 The Super Store Finder plugin for WordPress is vulnerable to unauthenticated arbitrary email creation and relay in versi… wordfence
cddbb0f8-fc73-46d7-80af-edb69227084f
< 4.7.34
MEDIUM 5.8 WordPress Core is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 7.0.2 due to ins… wordfence
c96175ef-03a5-43cb-adec-1b3c9fb8b1eb
< 2.0.1
MEDIUM 5.8 The Give – Divi Donation Modules plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
c77b0d79-5738-4ce2-b219-cb557216890f
< 4.2.3
MEDIUM 5.8 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa… wordfence
c434e6b8-0dd5-4ffe-93b1-1af614c08f85
< 18.3
MEDIUM 5.8 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and… wordfence
c17b03b4-d503-4bee-a1cd-4d66d27f6f9e
< 8.6.7
MEDIUM 5.8 The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to… wordfence
← Prev 1016 1017 1018 1019 1020 1021 1022 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top