🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1245 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d524b859-b61c-4c52-b4b3-76f2983c085a
< 4.2.0
MEDIUM 4.9 The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPre… wordfence
d4ec4480-ed4a-4a8b-b19a-2b60e7fba0c7
< 2.2.2
MEDIUM 4.9 The EKC Tournament Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin… wordfence
d4e04650-624a-4440-b166-8de0f24bb1dd
< 1.13.1
MEDIUM 4.9 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
d39a85fe-8cae-4ba1-b100-fbfa5a08df67
< 6.18.13
MEDIUM 4.9 The SeedProd Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.18.12 due to in… wordfence
d230b781-e208-4e66-b8ed-aba72db8d8dc
< 11.1.3
MEDIUM 4.9 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based blind S… wordfence
d156f277-88cb-43aa-895c-63684aa1466e
< 1.1.21
MEDIUM 4.9 The OttoKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.20 due to insuffic… wordfence
d0fbf502-2dfb-49e5-94a6-1525aabc08c1
< 1.4.7
MEDIUM 4.9 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t… wordfence
d0d58775-13c1-4926-9015-554106a1d0f5
< 2.6.5
MEDIUM 4.9 The AI Engine plugin for WordPress is vulnerable to SQL Injection via the 'value' parameter in all versions up to, and i… wordfence
d0d4bbcc-4a91-404d-8d07-de0d552f46cd
< 2.1.1
MEDIUM 4.9 The Melapress File Monitor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.1… wordfence
CVE-2026-3523 MEDIUM 4.9 The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, … nvd
CVE-2026-2831 MEDIUM 4.9 The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the ‘logid’ parameter in all versions up to… nvd
cfefcc38-764d-4dd9-b098-cdcad475d634
< 1.3.9
MEDIUM 4.9 The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and … wordfence
cec0d64e-7b31-4484-8237-2ab4d730ab86
< 3.8.9
MEDIUM 4.9 The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a… wordfence
ce47c956-5b19-43e4-8e04-9e7f68aeb924 MEDIUM 4.9 The Upunzipper plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 1.0.0… wordfence
ce1e944b-1ee9-4400-a182-d505381cb007
< 3.3.0
MEDIUM 4.9 The Captivate Sync plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.2 due to in… wordfence
cde440a2-55f8-406a-b81b-919028f0e887 MEDIUM 4.9 The AHAthat Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions… wordfence
cc90d500-b338-43ff-aac7-14a42d3d16b8
< 10.14.16
MEDIUM 4.9 The Booking Calendar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.14.15 due … wordfence
cc7c7e21-fbd7-4451-bc7d-3d11db01a443 MEDIUM 4.9 The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' paramet… wordfence
cc116b88-6610-4383-a6a7-5528e1a16ba9
< 2.1.3
MEDIUM 4.9 The Hover Effects plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.2 due to ins… wordfence
cad821ec-04f5-4cff-8846-628d183502fd
< 1.3.1
MEDIUM 4.9 The YaySMTP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 due to insufficien… wordfence
c6372bcd-ae01-4fe4-ac9e-4f3c34c34416
< 16.26.12
MEDIUM 4.9 The WP-Recall plugin for WordPress is vulnerable to SQL Injection via the 'product[fields]' parameter in all versions up… wordfence
c5cff14e-e891-4569-afd8-2885ebb26401
< 1.9.3
MEDIUM 4.9 The Hot Random Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a… wordfence
c55404f8-f928-4ed8-af60-a8dec103ce78
< 1.5.9
MEDIUM 4.9 The Product Labels For Woocommerce (Sale Badges) plugin for WordPress is vulnerable to SQL Injection in all versions up … wordfence
c536ae81-cf30-4af4-8b79-ee5dd03a4751
< 2.4.8
MEDIUM 4.9 The AI Engine plugin for WordPress is vulnerable to SQL Injection via the sort[accessor] parameter in all versions up to… wordfence
c532fc06-1ddd-4472-a5aa-10d7c8688d36
< 1.5.1
MEDIUM 4.9 The CSS JS Files plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.0 via th… wordfence
← Prev 1242 1243 1244 1245 1246 1247 1248 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top