πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1244 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e424d27b-f719-4fbf-b4eb-83b42130666c MEDIUM 4.9 The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up… wordfence
e3d231e1-a63e-4b41-a6b7-91e6dfc33600
< 4.2.7
MEDIUM 4.9 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection via th… wordfence
e289988c-8bc1-4b2a-87a2-c94758d10e88 MEDIUM 4.9 The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜path’ parameter in all ve… wordfence
e1531898-c6f6-4841-a03b-bbcd841b76cc
< 4.29.1
MEDIUM 4.9 The YITH WooCommerce Product Add-Ons plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
e1089e3e-9d81-4e4b-9703-403029f5265c
< 2.5.7
MEDIUM 4.9 The WC Vendors Marketplace plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.6 d… wordfence
e049e3d4-5168-4e1b-8128-8d42df1db2fd
< 1.0.17
MEDIUM 4.9 The Cart tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
dfd969b8-b88e-4d75-9d69-5f290b111fc7
< 3.8.9
MEDIUM 4.9 The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-ba… wordfence
dfb59bca-0653-4e75-8da1-e78e5d659422
< 1.19.3
MEDIUM 4.9 The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates'… wordfence
df790bbc-7427-4f7e-9aa2-e137c9fceffd
< 2.7.1
MEDIUM 4.9 The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable … wordfence
df67e870-d600-46d3-88cc-058d8b9d30c9
< 2.10.23
MEDIUM 4.9 The Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin for WordPress is vulnerable to SQL … wordfence
df5fc86f-e4ba-424b-bece-79abd763cf74
< 2.1.3
MEDIUM 4.9 The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor… wordfence
deb912f0-bfba-470f-9a18-47c3d65905dc
< 1.0.9.2
MEDIUM 4.9 The Transposh WordPress Translation plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' pa… wordfence
ddd2c5d9-6489-4154-a494-20392f435bc6
< 0.9.5
MEDIUM 4.9 The W3 Total Cache plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 0.9.4… wordfence
ddbd4940-fe1c-46f0-9148-53c5a4095785 MEDIUM 4.9 The ResAds plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.5 due to insufficie… wordfence
dbfb3895-6826-4c2d-9959-b3a9d3f175f5 MEDIUM 4.9 The WP Profitshare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.9 due to in… wordfence
dba84eb3-f48a-4175-a652-7c11b12c9afc
< 2.6.1
MEDIUM 4.9 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version… wordfence
db14e2b8-3217-4f81-a44e-e50734ef304c
< 9.2.04.003
MEDIUM 4.9 The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver… wordfence
d9938c7d-ef0d-45a2-900f-ac8bda9ce75a
< 2.4.1
MEDIUM 4.9 The Booking Calendar | Appointment Booking | BookIt plugin for WordPress is vulnerable to Price Bypass in versions up to… wordfence
d8ecb2c6-c2d0-44b0-b9c2-4fcbc0f97632
< 6.2.0
MEDIUM 4.9 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traver… wordfence
d8c11ebc-5c83-46a2-a8dd-b838cd50ddc6
< 1.6.4
MEDIUM 4.9 The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via pat… wordfence
d81b2927-f855-48f2-b7ae-f1411bee0040
< 2.6
MEDIUM 4.9 The Theme Editor WordPress plugin before 2.6 did not validate the GET file parameter before passing it to the download_f… wordfence
d7dc74e2-fa6d-4d4c-b27c-d77c3688ed15
< 3.0.13
MEDIUM 4.9 The License Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… wordfence
d7d08144-82b8-4f2e-8410-41bae20da00f MEDIUM 4.9 The Nearby Locations plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to … wordfence
d774bd22-4d4e-42d4-b4ae-c833dd36aa79
< 4.44.4
MEDIUM 4.9 The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa… wordfence
d6eba6da-ac14-4914-a807-6e234b80ee71
< 2.5.1
MEDIUM 4.9 The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress … wordfence
← Prev 1241 1242 1243 1244 1245 1246 1247 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top