πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,369
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 25, 2026
Last Updated

40,369 vulnerabilities found (page 1020 of 1615)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
be5be40f-89da-4b97-9a85-527602d84c4d
< 2.0.6
MEDIUM 5.8 The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versi… wordfence
b6b6fb24-f70b-44b0-a1e8-12ebc0e0c105
< 3.7.33
MEDIUM 5.8 In affected versions of WordPress, some private posts, which were previously public, can result in unauthenticated discl… wordfence
b3a77b7a-65ad-4334-99c9-92cc79e60bee
< 1.3.73
MEDIUM 5.8 The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.7… wordfence
adf3fb57-b080-4cda-b78b-14d94bad21a9
< 3.7.33
MEDIUM 5.8 In affected versions of WordPress, a cross-site scripting (XSS) vulnerability in the navigation section of Customizer al… wordfence
aa290a4b-06b6-4057-ae56-1c0b74b2ee5a
< 2.18.1
MEDIUM 5.8 The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to Cross-Site Re… wordfence
9960bae9-6f19-49eb-8f24-fdde4933671e
< 2.25.2
MEDIUM 5.8 The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and includ… wordfence
88001f3c-f5cc-4051-a713-788014e2241a
< 1.3.7
MEDIUM 5.8 The Insert PHP Code Snippet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
868b7492-c550-4c06-adb0-3478eb7d9b55
< 8.4.2
MEDIUM 5.8 The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and includ… wordfence
81bb4b60-a674-4276-b7e5-5626f9eb3ff8
< 2.1.3
MEDIUM 5.8 The Himer theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. T… wordfence
7f734db8-216e-43f3-8082-ebdcc28d3606
< 2.3.1
MEDIUM 5.8 The Wholesale For WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit… wordfence
7cfc1f42-c9dd-4dcb-8be5-c440a568a02e
< 3.7.33
MEDIUM 5.8 In affected versions of WordPress, a vulnerability in the stats() method of class-wp-object-cache.php can be exploited t… wordfence
78b98f21-ac0c-496b-8cb9-8d2f3bd751b1
< 3.7.32
MEDIUM 5.8 WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specifi… wordfence
694005fc-7703-4343-a7b4-d36906869df3
< 1.5
MEDIUM 5.8 The CampTix Event Ticketing plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2.… wordfence
5fd000dd-f75a-4ff0-bc71-20db878caca7 MEDIUM 5.8 The OneTone Companion plugin for WordPress suffers from an Open Mailer vulnerability in versions up to, and including, 1… wordfence
5e54dbf9-a5d1-413d-96ac-93dd499c21a4
< 1.3.4
MEDIUM 5.8 The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
5778ba3d-6670-47ad-ae65-50b6fb8e5db0
< 3.3.5
MEDIUM 5.8 The Real Estate 7 Theme for WordPress suffers from an Open Mailer vulnerability in versions up to, and including, 3.3.4.… wordfence
5754dce7-6b47-4490-a04a-7eabfded0720
< 5.1.2
MEDIUM 5.8 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
5539aa79-66ad-43fa-967c-2bec877061e0
< 18.3
MEDIUM 5.8 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and … wordfence
534a5d1d-cc34-4d84-b3a3-bf2282718656
< 4.2.8
MEDIUM 5.8 The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due … wordfence
52dc69e7-d4c0-492e-a334-54464fc963fd
< 4.0
MEDIUM 5.8 The Email Before Download plugin for WordPress is vulnerable to SMTP Header Injection in versions up to, and including, … wordfence
4d4301ca-081b-4fa3-ac4f-aa8f0b37d32c
< 6.8.4
MEDIUM 5.8 WordPress core is vulnerable to Blind Server-Side Request Forgery in all versions up to and including 6.9.1. This is due… wordfence
4b098711-ed01-4a71-b0df-30ff4fffa930
< 2.7.7
MEDIUM 5.8 The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Fo… wordfence
408cd4a7-d850-40fb-9b46-9381815c1222
< 1.6.5
MEDIUM 5.8 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Open Proxy attacks in versions up to, and including, 1.6.… wordfence
366ff716-e325-48e2-8fbd-ad4edbdaf9eb MEDIUM 5.8 The Search & Replace Everything – Quick and Easy Way to Find and Replace Text, Links plugin for WordPress is vulnerabl… wordfence
289a4076-974f-4b0c-bfaa-83c1b2cb62ef
< 4.9.61
MEDIUM 5.8 The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnera… wordfence
← Prev 1017 1018 1019 1020 1021 1022 1023 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top