🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1243 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f53cf99e-3136-4a1d-bbbd-ff484f1df5c3
< 1.5.0
MEDIUM 4.9 The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versio… wordfence
f44483df-e50d-4dcf-8a6f-499e2bd05b89
< 1.0.3
MEDIUM 4.9 The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all v… wordfence
f4050403-6b8c-4023-b170-39f3cb68583e
< 5.1.10
MEDIUM 4.9 The Fluent Forms plugin for WordPress by Fluent Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting … wordfence
f2c17222-5de5-4ecd-a7c6-beabe7624c5b MEDIUM 4.9 The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injec… wordfence
f28a95b0-0f7d-43c4-acf9-13c561245f4b
< 1.2.1
MEDIUM 4.9 The OptinCraft – Drag & Drop Optins & Popup Builder for WordPress plugin for WordPress is vulnerable to generic SQL In… wordfence
f1efcff5-3af6-4c44-9654-b917523419aa
< 7.0.1
MEDIUM 4.9 The WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7… wordfence
f1be8cdd-d394-4627-90a3-0a4781b9902e
< 3.6.0
MEDIUM 4.9 The Vitepos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.0 due to insuffici… wordfence
f18617cd-b2e9-480d-9ec0-9438a416721e
< 3.2.29
MEDIUM 4.9 The Cost Calculator Builder plugin for WordPress is vulnerable to SQL Injection via the discount[direction] parameter in… wordfence
f10636ea-06aa-4186-a891-ed4bb0800c41
< 2.14.17
MEDIUM 4.9 The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Arbitrary File … wordfence
f04c481b-98ef-4a15-9a73-198bd1c29028 MEDIUM 4.9 The WP Text Expander plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.1 due to … wordfence
edc197c6-dd0e-4a61-9421-5ae2595ff42b
< 2.1.1
MEDIUM 4.9 The Keep Backup Daily plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.… wordfence
ed54fe33-6467-4af2-ba28-dd17287d8f92
< 5.2.8
MEDIUM 4.9 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function i… wordfence
ecc7ac81-46cd-49ff-a01d-8679ccbc18a1
< 4.2.1
MEDIUM 4.9 The SureCart – Ecommerce Made Easy For Selling Physical Products, Digital Downloads, Subscriptions, Donations, & Payme… wordfence
ec4be524-a763-4f2b-8a1d-6189014b4d86
< 5.3.16
MEDIUM 4.9 The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for… wordfence
ec065da7-b8aa-414d-9673-5caf87ad45b5
< 3.3.3
MEDIUM 4.9 The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Dire… wordfence
ebffe466-0fd7-4110-bd2f-730978711087
< 3.2.2
MEDIUM 4.9 The CardGate Payments for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
eac8e81c-2f6f-4a4a-9678-f5d75f4954ae MEDIUM 4.9 The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘reference… wordfence
eaac2a61-7be6-4936-82a0-21c3665fa436
< 2.1.3.7
MEDIUM 4.9 The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'coating_text' parameter in all versions up… wordfence
e9e89383-a9c6-4300-970c-0b36e4d97e3d
< 3.1.5
MEDIUM 4.9 The Ultimate Gift Cards for WooCommerce plugin for WordPress is vulnerable to boolean-based SQL Injection via the 'defau… wordfence
e9ccd2cc-ee5e-40e3-905d-21884ec01f72
< 3.9.1
MEDIUM 4.9 The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ pa… wordfence
e8150619-9710-4dc0-ab62-ffd3e9fa8cd6 MEDIUM 4.9 Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce … wordfence
e7dd19f1-9b19-4c69-aa05-6bd414378bc5 MEDIUM 4.9 The WP Social Stream Designer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 … wordfence
e78c1280-10ce-4a92-b173-cd08a36c97dc MEDIUM 4.9 The Complete Google Seo Scan plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.1… wordfence
e74503d5-7498-43d3-995c-20ec4ee975fa MEDIUM 4.9 The Super Simple Subscriptions plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1… wordfence
e68d47e7-9a42-4a77-aefa-fe130500cbd3
< 9.1.7
MEDIUM 4.9 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orde… wordfence
← Prev 1240 1241 1242 1243 1244 1245 1246 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top