🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1255 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4bf43620-34ee-4e4f-b6ee-d24fbdbc894e
< 1.2.23
MEDIUM 4.9 The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 vi… wordfence
4b34ad23-246e-42ba-89de-5985043848be
< 1.1.4
MEDIUM 4.9 The Recurio – Ultimate Subscription for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via th… wordfence
4ada476b-6978-4c38-a5d3-67266a709a3e MEDIUM 4.9 The Flat Shipping Rate by City for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the 'c… wordfence
4ad02efa-4edb-485c-8fc4-79a030597d70
< 1.1.5.7
MEDIUM 4.9 The Hostel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.5.6 due to insuffic… wordfence
4aa0fa80-05dd-4fe1-b7b5-7ed0cf13053c
< 3.1.20.3
MEDIUM 4.9 The JetBackup – Backup, Restore & Migrate plugin for WordPress is vulnerable to Path Traversal leading to Arbitrary Di… wordfence
49afcc74-2d30-4023-a98a-e7c7c5be228d MEDIUM 4.9 The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v… wordfence
4938206e-2ea4-47ed-a307-87cf67dd74a4
< 2.7.10
MEDIUM 4.9 The Groundhogg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gh_form' shortcode in versions… wordfence
48bf876f-b817-454d-a802-db52f3900e18 MEDIUM 4.9 The Track Logins plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0 due to in… wordfence
484dded3-dbe7-4a11-877a-a19504d30206
< 3.18.0
MEDIUM 4.9 The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' … wordfence
47fe3de6-6c7b-4af3-8604-06f4522a36f2
< 3.45.0
MEDIUM 4.9 The TaxoPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.44.0 due to insuff… wordfence
4731eb39-8c01-4a2b-80f7-15d8c13a19b5
< 1.24.4
MEDIUM 4.9 The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug… wordfence
46cc1643-fc65-483c-923d-a458786f8e23
< 1.6.0.523
MEDIUM 4.9 The Surfer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.0.502 due to insuff… wordfence
4671d360-407d-49ed-8e49-c317f1693ec6
< 1.5.2
MEDIUM 4.9 The Store Locator WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.1 … wordfence
4618c1f4-c0aa-47f5-8c0b-2cb4a021f2e0
< 1.2.9.2
MEDIUM 4.9 The WP Editor plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.9.1. T… wordfence
456e4cda-a797-469e-9b48-62345e9876e6
< 1.18.7
MEDIUM 4.9 The Mail Mint plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.18.6 due to insuff… wordfence
4552786b-3362-45bf-9012-cd52f69f0462
< 2.1.8
MEDIUM 4.9 The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions u… wordfence
44f7c455-7d1f-44c0-b2dc-828b1b740a46 MEDIUM 4.9 The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to SQL Injection i… wordfence
43ec4320-3b2b-49b8-acd2-833ea999efa0 MEDIUM 4.9 The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to SQL Injection in versions up to, and… wordfence
4399c3b5-9bd6-4334-82fd-6afa735f89e0
< 2.4.8
MEDIUM 4.9 The Broken Link Checker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.7 due … wordfence
42ecc4e5-d660-472f-823d-a29b84cdf041
< 1.4.6
MEDIUM 4.9 The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and inclu… wordfence
42a19238-3af8-4b4f-9e78-96ef79f63c0f MEDIUM 4.9 The Easy Query – WP Query Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… wordfence
41b4a0c4-84f6-4c7a-926a-5f436c710759
< 1.10.0
MEDIUM 4.9 The Lana Downloads Manager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.… wordfence
415469cc-516d-41c4-a2c9-dc5dee061ada MEDIUM 4.9 The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.9 due to insuffic… wordfence
4075bf0f-d2fe-4f37-b2b3-2fbaad08ea15
< 4.0
MEDIUM 4.9 The WP Airbnb Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9 du… wordfence
40186505-3031-44e7-90ae-f013750c7ea1
< 1.11.0
MEDIUM 4.9 The User Feedback plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.10.1 due to in… wordfence
← Prev 1252 1253 1254 1255 1256 1257 1258 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top