🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1252 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6d490bfb-6560-428e-ad91-0f8d8bc9b1f2
< 5.5.1
MEDIUM 4.9 The ProfileGrid plugin for WordPress is vulnerable to unauthorized decryption of private information in versions up to, … wordfence
6cd166bc-774e-4083-b5f7-bffba1f7c293
< 1.68.11
MEDIUM 4.9 The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1… wordfence
6c3194de-5330-48d2-9d5f-c5772b756ee2
< 1.5.0
MEDIUM 4.9 The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio… wordfence
6ad21e49-6a18-40f1-9c5f-3f1cbe97cb1d
< 5.7.44
MEDIUM 4.9 The Email Subscribers by Icegram Express – Affordable, Powerful Email Marketing for WordPress & WooCommerce plugin for… wordfence
69f29a7a-5671-4de1-a010-413f20b41495
< 2.13.12
MEDIUM 4.9 The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
69dc9236-8079-434f-b2b5-060a0c5eba46
< 5.1.20
MEDIUM 4.9 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
69aa2287-3d26-43e2-a2d0-4985ed17d096
< 2.8.15
MEDIUM 4.9 The System Dashboard plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8… wordfence
699fc7f8-ed1f-465c-be37-f27a9dd74076 MEDIUM 4.9 The Connexion Logs plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.0.2 due t… wordfence
699e5c80-8a11-4f67-8b17-41170d9c6411
< 2024.2
MEDIUM 4.9 The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe s… wordfence
6959abd8-5c79-4be1-975d-905632b0f922
< 8.2
MEDIUM 4.9 The WP Yelp Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.1 due … wordfence
68f7caa7-e97a-41d9-b9e3-eb37f53fb0f9
< 4.8
MEDIUM 4.9 The Just Writing Statistics plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7 du… wordfence
68846ab2-684c-40ad-8a91-0b7d9de1ecde
< 3.2.9
MEDIUM 4.9 The Ni WooCommerce Cost Of Goods plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3… wordfence
670c1c3e-200c-4303-ac34-3bca5605fcde MEDIUM 4.9 The دکمه، شبکه اجتماعی خرید plugin for WordPress is vulnerable to SQL Injection in versions up to, a… wordfence
66dc2ca2-c61c-4c73-aa2a-0017299cbca5
< 2.6.4
MEDIUM 4.9 The 简数采集器 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.6.… wordfence
6623f130-152e-47ec-9545-3a6128ab1c82 MEDIUM 4.9 The Absolute Links plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to in… wordfence
65f70c77-ea67-49a3-8626-7b66a8827f11
< 4.2.1
MEDIUM 4.9 The Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery plugin for WordPress is vulnerable to SQL Injection … wordfence
65aa20e2-efc1-481a-8ed4-423d2420c3db MEDIUM 4.9 The WP-ClanWars plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, a… wordfence
659bbf79-f4f2-49fa-8ba5-60e821c798fc
< 1.3.2
MEDIUM 4.9 The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… wordfence
63d93203-e8fb-4a88-9546-580944f03d9a
< 4.1.0
MEDIUM 4.9 The 0 Day Analytics plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.0 due to i… wordfence
63ba2d29-26dc-4c5f-9d9d-9a13e25c44b9
< 3.1.0
MEDIUM 4.9 The Double the Donation – A workplace giving tool to help your fundraising efforts plugin for WordPress is vulnerable … wordfence
63902f5b-98e2-4586-9e20-4b900b6f861a
< 3.0
MEDIUM 4.9 The plugin WPide for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.6. This makes it… wordfence
638eeffd-ed57-42dd-982e-3b20d852d009
< 5.6.6
MEDIUM 4.9 The Poll Maker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6.5 due to insuff… wordfence
62faa5c1-d6ac-4b76-ac08-05fffbf71391
< 1.0.18
MEDIUM 4.9 The Cart tracking for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
62c28db1-094c-46b7-992f-428d36cdd6ba
< 5.9.7
MEDIUM 4.9 The Premium Packages plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.6 due to … wordfence
6288e6a8-d65f-48e0-bd71-fa3bab46f4a8
< 7.4.6
MEDIUM 4.9 The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4.5 due to insuffi… wordfence
← Prev 1249 1250 1251 1252 1253 1254 1255 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top