πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1254 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
56ef374e-db03-4f46-8902-243943131629
< 3.13.2
MEDIUM 4.9 The FlexStock plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.13.1 due to insuff… wordfence
56e0efba-4913-4772-8a5b-5cb5c84b5d48
< 6.0.8
MEDIUM 4.9 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to generic SQL Injectio… wordfence
55e5b3e2-0a8c-4628-835e-249c9362a238
< 4.1.0
MEDIUM 4.9 The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to SQL I… wordfence
558b27a3-548b-4df3-84aa-24331394f2fe
< 8.2.5
MEDIUM 4.9 The Nelio AB Testing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.2.4 due to … wordfence
54c1b0e9-6fab-4452-b232-953e671f4d8d
< 5.2.8
MEDIUM 4.9 The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_f… wordfence
5443aa7f-e290-4b7f-9be0-23daf1624935 MEDIUM 4.9 The Coupon API plugin for WordPress is vulnerable to SQL Injection via the β€˜log_duration’ parameter in all versions … wordfence
5300f1dc-d110-45d0-9e08-6339b12c2bdd
< 3.15.0.6
MEDIUM 4.9 The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to SQL Injection in version… wordfence
52f820c5-d4ce-4925-a055-a7c75a320971
< 1.0.8
MEDIUM 4.9 The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing user i… wordfence
51ee45f8-9978-48ec-8f87-229dc82938a8
< 5.243
MEDIUM 4.9 The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in… wordfence
51d79701-8580-4130-8f84-e739aa2f7f5f
< 3.28.29
MEDIUM 4.9 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter i… wordfence
513f407d-e90f-4fd1-82dd-c28bab9f76d0
< 1.15.44
MEDIUM 4.9 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to gener… wordfence
505858dc-c420-484c-a067-6962836eea6a
< 2.2.3
MEDIUM 4.9 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
500ce6fe-0528-4b15-89a7-0e1f92e97364
< 4.9.9.8
MEDIUM 4.9 The Newsletters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.9.7 due to ins… wordfence
4fc81a70-f43d-4a92-b376-7ed85481e00f
< 6.2
MEDIUM 4.9 The Mailchimp for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to 6.2 due to insuffici… wordfence
4f7fa5a4-07d7-4815-b393-871568777b0f
< 4.7.3
MEDIUM 4.9 The Download Monitor plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.7.2 v… wordfence
4f1cf0f3-faf2-43f7-a641-95bfa5d73ca8
< 5.5.4.1
MEDIUM 4.9 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to arbitrary file download via direc… wordfence
4ed4dfee-5f14-47ce-abed-cd226c110665
< 5.1.20
MEDIUM 4.9 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
4e2527d4-750d-4e36-ae27-920105958c21
< 3.2.55
MEDIUM 4.9 The Download Manager plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.2.54 via … wordfence
4e1a40cc-0b20-4713-b713-5766619d38cb
< 7.1.8
MEDIUM 4.9 The Total processing card payments for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all vers… wordfence
4df72b72-1188-4a02-9a53-7c69f7e31ddd MEDIUM 4.9 The Advance Post Prefix plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to… wordfence
4df60fbe-4475-4cbf-b497-a9c5251bc91f
< 2.5.1
MEDIUM 4.9 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Dire… wordfence
4d67675a-b77b-41c6-a94f-d9385e609b37
< 2.2.3
MEDIUM 4.9 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
4d265120-992b-4138-b77a-1cf529e4d742 MEDIUM 4.9 The Haxcan plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.0.0 via improper lim… wordfence
4ccd1314-b9b9-4f63-820c-2817a4932ee8
< 6.1.0
MEDIUM 4.9 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (… wordfence
4c9e5fff-c204-41bf-a675-13f39e34e0c5
< 1.1.38
MEDIUM 4.9 The BookingPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.28 due to ins… wordfence
← Prev 1251 1252 1253 1254 1255 1256 1257 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top