πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1257 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2d4a463b-e447-4fd0-a8df-284ecd6cd975 MEDIUM 4.9 The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and i… wordfence
2c11f469-b136-4429-87a1-083d7d5e6695
< 1.9.0
MEDIUM 4.9 The MC Woocommerce Wishlist plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.9 … wordfence
2be23829-cbee-4e44-945d-14835dbba104
< 2.11.32
MEDIUM 4.9 The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.11.31 due… wordfence
2b4b0640-d61a-4969-a5c0-d2d709fb56d0
< 3.3.204
MEDIUM 4.9 The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin… wordfence
2a59db6d-82a6-4570-bfa5-674ae4054ea7
< 8.2.6
MEDIUM 4.9 The WP Full Stripe Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.2.5 due … wordfence
28eb6998-be54-4cf9-8bb1-454c07151748
< 1.5
MEDIUM 4.9 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to SQL Injection via the 'params' param… wordfence
2760587c-78f5-40b1-affd-dfdfb2bc2a68
< 0.9.71
MEDIUM 4.9 Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= … wordfence
25940775-2ff9-49cf-ab24-3e87f1ca8e42
< 1.8.0
MEDIUM 4.9 The Behance Portfolio Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.… wordfence
259010bd-ccb4-4907-bea8-f49e6464eaa1
< 6.10
MEDIUM 4.9 The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versio… wordfence
23f8e757-a4ed-4929-9647-dfe5a21689aa
< 4.9.13
MEDIUM 4.9 The Spiffy Calendar plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.9.12 due… wordfence
23e0f61b-f122-46f7-83c8-7fcb022c45e9
< 1.5.75
MEDIUM 4.9 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.75 did not ensure that uploaded… wordfence
2328efaf-4174-48f0-b575-1939d6af9216
< 1.09
MEDIUM 4.9 The Falling things plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.08 due to ins… wordfence
2242c86e-c769-4104-b266-0cdcd90ccf63 MEDIUM 4.9 The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio… wordfence
21da92d2-c38d-4a12-b850-bd0b580aaa54
< 1.16.9
MEDIUM 4.9 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Se… wordfence
205efe4d-45c3-4180-b839-ab2ba94ec94a
< 1.0.8
MEDIUM 4.9 The ShortLinks Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.7 due to in… wordfence
2000b23f-d8a2-4b83-9bf7-b90cb16718f3
< 1.3.2
MEDIUM 4.9 The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, a… wordfence
1fc5f0ac-3323-4e6c-8900-10e13294ff9a
< 2.2.0
MEDIUM 4.9 The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the β€˜raw… wordfence
1f3b5d85-a8b0-43ac-b593-a61e20b9a4ca
< 2.18.4
MEDIUM 4.9 The Contact Form by Bit Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a… wordfence
1e7c1eab-78d7-48f8-810b-db6cea668d92
< 9.0.16
MEDIUM 4.9 The WP Go Maps plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.0.15 via th… wordfence
1e2dab05-97ce-4f53-8069-2577c5c25b16
< 2.4.7
MEDIUM 4.9 The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the … wordfence
1e193bb9-bb16-4a77-877b-fa0ab29a6c74
< 3.9.12
MEDIUM 4.9 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via t… wordfence
1dd094b8-440a-47ae-8edc-c23f1909d607
< 9.2.5
MEDIUM 4.9 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via th… wordfence
1d9d5afb-d38d-442c-8511-f1683739a1da
< 4.0
MEDIUM 4.9 The VR-Frases (collect & share quotes) plugin for WordPress is vulnerable to SQL Injection via several parameters in all… wordfence
1ce15d38-c5bc-441b-976a-60a3e90b5a30
< 4.5.91
MEDIUM 4.9 The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog fold… wordfence
1a38e571-a92a-4a47-9507-8a989be4b405 MEDIUM 4.9 The Plugin Inspector plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5. Thi… wordfence
← Prev 1254 1255 1256 1257 1258 1259 1260 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top