πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1246 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c42139fc-34a2-47ae-b172-d2cd4f1cf098
< 1.1.4
MEDIUM 4.9 The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields'… wordfence
c2c58f4a-1436-4796-bf61-895177639dbe
< 0.9.7
MEDIUM 4.9 The Link Whisper Free plugin for WordPress is vulnerable to SQL Injection in all versions up to 0.9.7. This is due to in… wordfence
c2ba5136-cd30-4b65-af3e-f1161ae6eeee
< 4.5.9
MEDIUM 4.9 The Dynamic Pricing With Discount Rules for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions … wordfence
c2b36621-3322-4631-b693-629c5084708b
< 9.1.8
MEDIUM 4.9 The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7… wordfence
c26e5109-aaf8-4bba-9331-b8baaf109a55
< 3.9.26
MEDIUM 4.9 The Simple Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.25… wordfence
c2353d9d-d5ae-4470-9c0f-119acecd6686
< 1.3.1
MEDIUM 4.9 The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions … wordfence
c1d532f8-c8aa-4d1b-9a6b-cb12402bf1eb
< 1.1.8
MEDIUM 4.9 The BEAR plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.7.1 due to insufficie… wordfence
c0c4028d-24b5-4293-8969-66e199556d73
< 1.10.1
MEDIUM 4.9 The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.0 due to in… wordfence
bf7c500e-311f-4db5-8a54-de7b02fb11dd
< 1.24.2
MEDIUM 4.9 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable … wordfence
bed2ada9-af3d-479e-8ae4-11eaad0b3842
< 3.4.6
MEDIUM 4.9 The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-b… wordfence
beb489d3-2c1b-4af5-b73e-126d2526e0a3
< 2.3
MEDIUM 4.9 The Design Import/Export plugin for WordPress is vulnerable to SQL Injection via XML File Import in all versions up to, … wordfence
be3bd1f2-092c-47c4-a4e4-3365e107c57f
< 1.2.8
MEDIUM 4.9 The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all ver… wordfence
bdd03b29-daeb-43bb-b54d-6d7a053a051c MEDIUM 4.9 The Altra Side Menu plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0 due to… wordfence
bd3e30ea-8f58-4895-b78c-fb18c94d5253
< 1.0.5
MEDIUM 4.9 The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in… wordfence
bd184c80-e785-4e9b-961d-9c3378688f91
< 1.5.9
MEDIUM 4.9 The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'ce_venue_name' CSV field in the `on_sa… wordfence
bced99cc-89db-4e42-9336-b83721826680
< 1.1.1
MEDIUM 4.9 The Slider by BestWebSoft plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.0 du… wordfence
bcae549f-6a10-4b0d-a8d1-5dcc83e1f2e5
< 3.9.8
MEDIUM 4.9 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulne… wordfence
bc176920-04c4-42c7-ab9c-683788e998dd
< 2.8.1
MEDIUM 4.9 The Zoho Flow for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.8.0… wordfence
bbe9eed9-9a96-47da-95fa-b942817a9d4f
< 3.7.22
MEDIUM 4.9 Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme fil… wordfence
bb9aedc6-42ef-4fd9-a9d5-2a79214be472
< 7.4.5
MEDIUM 4.9 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all vers… wordfence
bb8f7748-8268-4a38-b794-495c5f6eb5ca
< 4.0.1
MEDIUM 4.9 The Advanced Shipment Tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, an… wordfence
bb3859eb-5a1f-408c-84aa-acfc68bd0bb5
< 2.5.0
MEDIUM 4.9 The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowi… wordfence
bb23bc2e-4484-46d5-b46e-5e43e5a1bf12 MEDIUM 4.9 The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' para… wordfence
ba60fb73-9056-4163-9874-f0f4af35f5b3
< 1.5.25
MEDIUM 4.9 The 10Web Photo Gallery plugin before 1.5.25 for WordPress has Authenticated Local File Inclusion via directory traversa… wordfence
ba326241-46a3-4891-a180-d7977f4e83ed
< 4.4.0
MEDIUM 4.9 The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version … wordfence
← Prev 1243 1244 1245 1246 1247 1248 1249 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top