πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1242 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
34b6475c-b5dd-42a1-98d1-9b5ae9ff4ad5
< 5.3.6
MEDIUM 5.0 The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
288853b8-7523-472e-8406-257ffb3bd5ea
< 2.0.9
MEDIUM 5.0 The WP-FormAssembly plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, … wordfence
261aad1e-43fc-4927-a97d-85a001863023
< 5.11
MEDIUM 5.0 The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Sid… wordfence
1c0572a5-6cc9-43ab-a4a3-c8d3b93c8fcf
< 5.3.6
MEDIUM 5.0 The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th… wordfence
1173e2ad-c53d-4d37-9c77-4b63f04ff335
< 2.5.3
MEDIUM 5.0 The Pz-LinkCard plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, … wordfence
0c2925c1-f5c6-45b9-bc61-96f325c0372f
< 1.7.60
MEDIUM 5.0 The Unite Gallery Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.… wordfence
ffcf8071-89be-484c-9b6a-8b08e12cf100
< 7.3.2
MEDIUM 4.9 The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versio… wordfence
ffc2fe31-9bc2-497a-a8f4-1bc4f93de5a2
< 5.7.10
MEDIUM 4.9 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQ… wordfence
fd7b0eef-3b8e-4272-bbd7-ad52088d0835
< 1.1.43
MEDIUM 4.9 The RSFirewall! plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.1.42 via th… wordfence
fd75e795-54b8-4b9a-9417-9f707215ebfa
< 1.24.3
MEDIUM 4.9 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable … wordfence
fcbe5bfa-7680-452e-bb18-ea9fbbb07b8e
< 1.5.9
MEDIUM 4.9 The Product Labels For Woocommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… wordfence
fcbd718b-4d7d-48a4-9db2-dd938de7c7eb
< 0.8.5.8
MEDIUM 4.9 The WP Fastest Cache plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… wordfence
fc1f36b1-cf28-472c-8a7a-f091ecb48c2d MEDIUM 4.9 The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' para… wordfence
fbe12337-52ca-41ca-a7bf-5dfca52a8018
< 6.0.2
MEDIUM 4.9 The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to SQL Injecti… wordfence
fad8ad54-56eb-40fa-a357-77b7d656d378 MEDIUM 4.9 The Code Explorer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.6 via t… wordfence
faa6ecad-1430-4300-b314-53619d69837b
< 2.9.10
MEDIUM 4.9 The Post SMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9 due to insuffi… wordfence
fa795a7e-9a7a-4686-9f42-df87f49f6e0d
< 1.14.0
MEDIUM 4.9 The WPMasterToolKit (WPMTK) – All in one plugin plugin for WordPress is vulnerable to Directory Traversal in all versi… wordfence
f9ff3058-a08c-40ed-b756-81e703b2277a
< 2.8.3
MEDIUM 4.9 The Loco Translate plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.8.2 via … wordfence
f96d3773-29a1-44bd-904a-905aff2b345e
< 1.5.0
MEDIUM 4.9 The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜orde… wordfence
f928d3e0-b9ac-43bb-9e54-5a6bae2a3cb4
< 1.9.1
MEDIUM 4.9 The SMTP for Amazon SES plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to… wordfence
f790114b-d000-4dd3-828d-3d00ee9ab52b MEDIUM 4.9 The Adicon Server plugin for WordPress is vulnerable to SQL Injection via the adStatus parameter in all versions up to, … wordfence
f7007230-f27e-447a-adc4-d835a0a3039b
< 1.13.10
MEDIUM 4.9 The InfiniteWP Client plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.13.9. … wordfence
f6c71e38-5ac3-46f1-8292-a49c6e44f1d8
< 4.5.12
MEDIUM 4.9 The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allow… wordfence
f62f756d-70f2-42fe-89d7-f9f50ddf466e
< 9.1.0
MEDIUM 4.9 The Newsletter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0.9 due to insuff… wordfence
f6023483-3fa5-4b85-9422-7d395abcfbd8
< 1.0.5
MEDIUM 4.9 The Thumbnail carousel slider plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions… wordfence
← Prev 1239 1240 1241 1242 1243 1244 1245 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top