πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1253 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6222d255-47cc-469a-850d-fc11d7860d75
< 3.11.0
MEDIUM 4.9 The Funnel Builder by FunnelKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.… wordfence
61bac919-90be-4fb5-859a-d135e87fe0bb
< 4.10.19
MEDIUM 4.9 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's onCl… wordfence
61b28b8c-4588-4b4e-85e8-d3d37b791f3d
< 4.5.1
MEDIUM 4.9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & News… wordfence
6186fe48-fc5c-44e3-b998-7d84acb1869e MEDIUM 4.9 The WP Employee Attendance System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
60d7a5c1-7006-412d-897f-16c3105c20c4 MEDIUM 4.9 The MindValley Super PageMash plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 … wordfence
604e81a2-62ba-49c6-81f4-bab2ad8419c2
< 4.7.4
MEDIUM 4.9 The PublishPress Authors plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.7.3 due… wordfence
602bf9b1-17a9-441a-b12d-15412df2deb4
< 2.33
MEDIUM 4.9 The WordPress Report Brute Force Attacks and Login Protection ReportAttacks Plugins plugin for WordPress is vulnerable t… wordfence
5f7b15ba-5d7b-448d-ae95-b7d3ae7ff1c0
< 2.11.2
MEDIUM 4.9 The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.11.1 … wordfence
5f5a1eb3-3fda-49de-aefb-2205c9ca3520
< 1.45.1
MEDIUM 4.9 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-bas… wordfence
5f4e6daf-9f89-4f34-ad07-82f63fd730da
< 2.1.8
MEDIUM 4.9 The BetterLinks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.7 due to insuf… wordfence
5f0406ad-8f4e-49a2-87dd-a6e319904652
< 8.7.9
MEDIUM 4.9 The NEX-Forms – Ultimate Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… wordfence
5edd7fba-77d1-4a13-ad31-0135ec83c2a1 MEDIUM 4.9 The Link to URL / Post plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.3 due… wordfence
5e4ab6c3-fa9a-4643-aaf5-eabbdf909f9f
< 1.2.24
MEDIUM 4.9 The Email Subscription Popup plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.2… wordfence
5e383b8a-27e5-4b35-8d11-6e4102255d44
< 1.15.41
MEDIUM 4.9 The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection via the 'ip_search', 'startdate', 'enddate',… wordfence
5e16a3e2-79db-4647-9712-03ae666feac4 MEDIUM 4.9 The WP Post Corrector plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due to… wordfence
5cb80db2-753c-40fa-aee4-7d8c1749d037
< 3.3.20
MEDIUM 4.9 The LWS Optimize – All-in-One Speed Booster & Cache Tools plugin for WordPress is vulnerable to Arbitrary File Read in… wordfence
5bd95df9-4355-4d57-ba44-59280463e284
< 1.0.8
MEDIUM 4.9 The BFG Tools – Extension Zipper plugin for WordPress is vulnerable to Path Traversal in all versions up to, and inclu… wordfence
5bc8da1b-8095-46b5-8268-63bdddb4e629
< 4.5.1
MEDIUM 4.9 The MailArchiver plugin for WordPress is vulnerable to SQL Injection via the β€˜logid’ parameter in all versions up to… wordfence
5a7e8284-d70f-4448-8f0d-99c23b8eda79
< 5.4.7
MEDIUM 4.9 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to time-based SQL Injec… wordfence
5a6cda1f-8af9-44b1-98e2-619d29c28a88
< 4.1.9
MEDIUM 4.9 The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, al… wordfence
59f622ee-eccf-4b5b-8fa0-93a4405eb1e9
< 7.3.2
MEDIUM 4.9 The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versio… wordfence
590720a3-1881-4a5d-b004-ad92d386afe6
< 13.7.4
MEDIUM 4.9 The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all … wordfence
58e1a5a1-800f-45e8-a356-759ba568d7c5
< 1.7.2
MEDIUM 4.9 The SEUR Oficial WordPress plugin before 1.7.2 creates a PHP file with a random name when installed, even though it is u… wordfence
575870b0-269e-4651-9e0f-0a178266a02e
< 1.9.1
MEDIUM 4.9 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… wordfence
572bfa82-92f5-4801-8710-0626ca563a6c
< 4.3.6
MEDIUM 4.9 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection vi… wordfence
← Prev 1250 1251 1252 1253 1254 1255 1256 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top