πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1249 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9b86a259-b102-411a-8d4c-c131737b90d8
< 3.9.2
MEDIUM 4.9 The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Sensitive Data Exposure in ve… wordfence
9b6f21ce-8601-425f-bd44-6a1af31c67de MEDIUM 4.9 The Code Clone plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜snippetId’ parameter in all v… wordfence
9b3a6e01-cb4a-4e8f-b981-cf95af541366
< 3.0.9
MEDIUM 4.9 The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to SQL Injection in al… wordfence
9adfc632-2e47-4fea-ad87-41840cdab225
< 1.8.6
MEDIUM 4.9 The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Directory Traversal in all v… wordfence
9ac50927-e3e3-41db-9dd0-3e22361b497a
< 1.4.3
MEDIUM 4.9 The BMA Lite plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.2 due to insuffic… wordfence
9aaf2188-966d-43f3-a359-44ebdccaf6d8
< 5.4.0
MEDIUM 4.9 The PDF Invoices for WooCommerce + Drag and Drop Template Builder plugin for WordPress is vulnerable to SQL Injection in… wordfence
9a825b7b-118d-4c34-905b-0cf7cfa00ad7
< 1.1.0.35
MEDIUM 4.9 The bizcalendar-web plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.0.34 due t… wordfence
9a68e2ab-fe2f-43f8-bb1b-b46a483bd06f
< 5.1.1
MEDIUM 4.9 The Invisible Anti-Spam & CAPTCHA β€” reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic … wordfence
975ddadd-12f8-4ace-9c1a-489114a2da6a
< 3.2.33
MEDIUM 4.9 The Front End Users plugin for WordPress is vulnerable to SQL Injection via the 'UserSearchField' parameter in all versi… wordfence
96e86515-5786-4652-b65e-f4c9b009c598
< 1.8.4
MEDIUM 4.9 The Split Test For Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.3… wordfence
9689a638-f7e5-4340-8a69-990fc2f6b9e5
< 8.53.0
MEDIUM 4.9 The Smart Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.52.0 due to in… wordfence
9676c768-496a-4131-93ff-481db158cceb
< 1.0.6
MEDIUM 4.9 The Database Cleaner: Clean, Optimize & Repair plugin for WordPress is vulnerable to Arbitrary File Read in all versions… wordfence
961702ff-60fb-41ff-99b0-a37ade051083
< 1.0.9
MEDIUM 4.9 The WPB Floating Menu & Categories for WordPress – Sticky Side Menu with Icons plugin for WordPress is vulnerable to S… wordfence
9534b2dc-fe56-4f97-bb6e-79d55508ed38
< 5.2.2
MEDIUM 4.9 The AutomatorWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.1.3 due to ins… wordfence
948dc4ed-7dd3-4a53-83db-82b8c39ace7a
< 2.1.0
MEDIUM 4.9 The Melapress File Monitor plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0… wordfence
9455eccb-9f32-4e4e-8fe4-f345bf6e8da7
< 1.1.7
MEDIUM 4.9 The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and… wordfence
939f0660-067f-49c9-b4eb-e174985165fd MEDIUM 4.9 The Video Player & FullScreen Video Background plugin for WordPress is vulnerable to SQL Injection in versions up to, an… wordfence
935171a3-9db0-4b01-babb-fa0b3d8985f6
< 3.8.3
MEDIUM 4.9 The WP Post Author plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.2 due to in… wordfence
92babbbf-74bd-474f-9057-c5022a7d64c7
< 4.7.34
MEDIUM 4.9 WordPress Core is vulnerable to Stored Cross-Site Scripting via Quick Edit in all versions up to, and including, 7.0.2 d… wordfence
924903f8-3b25-4d56-ae37-d3afd58ad4ed
< 1.0.9
MEDIUM 4.9 The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to SQL Injection in… wordfence
920708d9-44e8-45c4-85d4-c19bb507cca7 MEDIUM 4.9 The Product Feed Manager for WooCommerce – CTXFeed – Support 220+ Shopping & Social Channels plugin for WordPress is… wordfence
91ca027c-0483-44de-b19e-243ccb2c7b31
< 3.8.0
MEDIUM 4.9 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to insuffi… wordfence
91173862-4f2d-4ca5-a58e-6fdaaeb71fc7 MEDIUM 4.9 The WP Music Player plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 due to ins… wordfence
90c3f8bc-fc41-4ba7-b9f2-8873203d5794
< 0.9.36
MEDIUM 4.9 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to sensitive information disclosure of a W… wordfence
8e4cf9eb-8f89-4cc7-9cdf-6d2e76f31388
< 8.5.2
MEDIUM 4.9 The WPBot AI ChatBot plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.5.1 due to … wordfence
← Prev 1246 1247 1248 1249 1250 1251 1252 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top