🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1248 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ab807beb-0e20-47e4-be3e-9e8f50b84c7b
< 8.7.16
MEDIUM 4.9 The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Inject… wordfence
aa6874e5-d99d-4d20-aaf7-897fe8f05292
< 2.21.11
MEDIUM 4.9 The Bit Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.21.10 due to insuff… wordfence
aa5b6311-d9ca-4736-a6e3-56c6746b2470
< 1.4.6
MEDIUM 4.9 The FOX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insufficient … wordfence
aa46842f-ed07-4f72-aedb-aa27baecd79c
< 2.15.3
MEDIUM 4.9 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
a9bffba4-5bcd-4ef7-a8d8-84ba452827ab
< 3.1.2
MEDIUM 4.9 Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administ… wordfence
a919c252-c468-48be-a4e4-f5524419d8f9
< 1.5.6
MEDIUM 4.9 The YayExtra plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.5 due to insuffic… wordfence
a7ef66cf-ddf1-42be-82b1-cb6edcbf253c MEDIUM 4.9 The WP Online Users Stats plugin for WordPress is vulnerable to time-based SQL Injection via the ‘table_name’ parame… wordfence
a7aa2246-aee9-4992-b030-97e78e3b7d22
< 2.4.6
MEDIUM 4.9 The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to time-based blind SQL Injection v… wordfence
a6e513cc-5008-4f59-87c1-2a1b42d98850
< 1.9.2
MEDIUM 4.9 The TrackShip for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.… wordfence
a55af7fd-5f45-4978-b2b9-636b33297deb
< 6.0.6
MEDIUM 4.9 The Premium Packages plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.0.5 due to … wordfence
a43dd1a8-4710-4cbc-920b-582e29d7ce98 MEDIUM 4.9 The SC filechecker plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 0… wordfence
a3bb387c-3f4c-450e-bc3f-4524378bac93
< 1.1.15
MEDIUM 4.9 The Kargo Entegratör plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.14 due t… wordfence
a3779501-4ac7-4b76-8b2b-9852c6467f16
< 3.7.19
MEDIUM 4.9 In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin del… wordfence
a2399535-c293-4b06-8ef4-1706bbe12bf7
< 3.6.21
MEDIUM 4.9 The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordP… wordfence
a1af9757-23e9-41d2-bbcd-15b0610b6538
< 23.0.0
MEDIUM 4.9 The Apocalypse Meow plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, … wordfence
a0f55f3e-9a9a-42a7-91b5-0d515519d545
< 1.8.15
MEDIUM 4.9 The Photo Gallery plugin by 10Web for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1… wordfence
a0e9e803-8f52-4210-9c28-fe0438487a4b MEDIUM 4.9 The Directory Listings WordPress plugin – uListing plugin for WordPress is vulnerable to Directory Traversal in all ve… wordfence
a0d38788-5f90-4ab1-8df1-1c67c1052e6d
< 14.7
MEDIUM 4.9 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' para… wordfence
a0289458-7ffb-4e9c-a685-7d38664fe701 MEDIUM 4.9 The iCafe Library plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.3 due to ins… wordfence
9ef89bd0-e1f6-4818-a5e6-857fae7cf231
< 1.5.7
MEDIUM 4.9 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in all versions up to 1.5.7. This is due to ins… wordfence
9e4cff1c-6a01-4725-9e37-f48b5de16d9b
< 1.0.13
MEDIUM 4.9 The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and… wordfence
9e21d279-aa83-42ff-9906-bc61dc4aba52
< 2.10
MEDIUM 4.9 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to arbitrary… wordfence
9d637d7b-7a47-40db-a931-ec7ca723dfab
< 4.0.2
MEDIUM 4.9 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via t… wordfence
9c7aeef5-b87e-4cd0-9374-93b7f67a9187
< 3.0.5
MEDIUM 4.9 The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to SQL Injection via t… wordfence
9bdfa6e8-0bf6-4ca5-b145-af66d99dbf6c
< 14.4
MEDIUM 4.9 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete… wordfence
← Prev 1245 1246 1247 1248 1249 1250 1251 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top