πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1256 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3fe1bb24-1f60-40f6-9b5e-58e0158bdfd3
< 2.21.0
MEDIUM 4.9 Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.… wordfence
3f9c3503-9c31-4620-9d82-a7cbb1c3fa33
< 4.0.2
MEDIUM 4.9 The Payment Forms for Paystack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0… wordfence
3ef59cb5-4d6d-4859-bd4c-3fc7dc97c51b MEDIUM 4.9 The Appointify plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.8 due to insuff… wordfence
3e765e05-9be1-40fa-97f2-a6e57728cb85
< 2.0.6
MEDIUM 4.9 The Woosa – Marktplaats for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal i… wordfence
3d7b73f4-e52f-40bd-9865-de994cd8d610
< 2.4.0
MEDIUM 4.9 The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the … wordfence
3d3336f7-ee20-4f1c-92b4-f1c77aac91f9
< 3.43
MEDIUM 4.9 The IP Blacklist Cloud plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 3.42 via t… wordfence
3cf26716-70b6-4e5e-9ac1-764060be2215
< 2.1.3.7
MEDIUM 4.9 The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'material_text' parameter in all versions u… wordfence
3c49fa36-f572-4e04-8f92-742af0e93f00 MEDIUM 4.9 The Ultimate Learning Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9 due … wordfence
3c1ad419-0767-4e2d-908a-83b57cfa8ed5 MEDIUM 4.9 The FireStorm Professional Real Estate plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
39d325d4-073c-47b6-8ea4-30637417f0d7
< 1.4.3
MEDIUM 4.9 The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in … wordfence
3930614d-1b3a-4ca2-9d17-b2e905330fe9
< 18.5
MEDIUM 4.9 The Google Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 18.4 due … wordfence
389bee79-b59f-484a-86df-f041d6b00051
< 3.1.1
MEDIUM 4.9 The 404 Solution plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3.1.0 due to … wordfence
37ce28de-f41d-42f8-8467-0af5e643a739 MEDIUM 4.9 The Catalyst Connect Zoho CRM Client Portal plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜ui… wordfence
37b085f9-3b15-44aa-9ba0-de5321dfbce4
< 4.1.0
MEDIUM 4.9 The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up … wordfence
376741ee-9b6b-4822-8bad-548e212cd563
< 4.3.7
MEDIUM 4.9 The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to generic SQL Injection vi… wordfence
36742d6b-3cd5-4e12-86b5-0d3f361372ea
< 1.0
MEDIUM 4.9 The Libro de Reclamaciones y Quejas plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… wordfence
3607420e-3f02-425d-a708-f785ce66f2db
< 5.6.4
MEDIUM 4.9 The ShortPixel Image Optimizer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.6… wordfence
35a690c5-dc7e-4bb7-be5b-c70bd0ea7d10
< 1.2.2
MEDIUM 4.9 The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerab… wordfence
35219b1e-f716-4be8-926c-62a7c462d2eb
< 5.2.4
MEDIUM 4.9 The Ninja Tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.2.3 due to insu… wordfence
340980de-d746-4191-9e7b-24630975c535
< 7.1.0
MEDIUM 4.9 The Persian Woocommerce SMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0.10… wordfence
3288536d-e0c9-4c9f-8d28-444dfe79d770
< 4.6.9
MEDIUM 4.9 The Advanced Coupons for WooCommerce Coupons plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
315fbc93-5af3-4fe9-b97a-a09957e54c97 MEDIUM 4.9 The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ativ… wordfence
2fda47d8-8e8c-4103-aabb-c70935e13450
< 3.14.10
MEDIUM 4.9 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injec… wordfence
2f2d8b21-1c25-4cfc-bf62-2e71d6a90d91
< 9.1.13
MEDIUM 4.9 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injecti… wordfence
2d97ca8e-e735-4312-bfb2-5c434cb5b190
< 5.1.1
MEDIUM 4.9 The Invisible Anti-Spam & CAPTCHA β€” reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic … wordfence
← Prev 1253 1254 1255 1256 1257 1258 1259 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top