ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,402
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 28, 2026
Last Updated

40,402 vulnerabilities found (page 1258 of 1617)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
19cff824-7fb7-4b60-bfc4-2157c9ecb0bf
< 2.2.5
MEDIUM 4.9 The UpsellWP – WooCommerce Upsell and Related Products Offers plugin for WordPress is vulnerable to SQL Injection in v… wordfence
188baddc-134c-4a82-898b-9b038e795893
< 3.5.1.29
MEDIUM 4.9 The Smart Slider 3 plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sliderid’ parameter in al… wordfence
17fd14e7-503a-49e4-9344-5f8d51801eb3
< 1.5.3
MEDIUM 4.9 Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down… wordfence
176a2200-db90-4a16-b8bc-da85471ff8d1
< 3.1.0
MEDIUM 4.9 The Verowa Connect plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.5 due to in… wordfence
174bcee9-cb2d-4181-8168-df5d28de8484 MEDIUM 4.9 The WP Inquiries plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.1 due to insu… wordfence
16c212d8-21e2-407f-b2ea-0ca519da26dd MEDIUM 4.9 The donation plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and inclu… wordfence
16820eda-e5ff-48d1-81bc-355ee916119b
< 3.1.3
MEDIUM 4.9 The ELEX Product Feed for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
156945e1-80dc-4fb4-958f-bb87722e96fb
< 2.1.3.7
MEDIUM 4.9 The 3DPrint Lite plugin for WordPress is vulnerable to SQL Injection via the 'infill_text' parameter in all versions up … wordfence
156209c0-27d0-4c87-883a-bf9376f8858c
< 1.18.6
MEDIUM 4.9 The Mail Mint plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.18.5 due to insuff… wordfence
153647b8-c5eb-47f5-b375-0baec367287f
< 3.4.7
MEDIUM 4.9 The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to SQL Inject… wordfence
13fcbff8-8560-48ca-82df-8b620961d9c6
< 3.16.1
MEDIUM 4.9 The WatchTowerHQ plugin for WordPress is vulnerable to arbitrary file read via the 'wht_download_big_object_origin' para… wordfence
13b7a2e4-59f4-4d61-a165-a830ccfb696a
< 2.6.3
MEDIUM 4.9 The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… wordfence
13929b51-b32e-401c-a642-49f7cd2d07bf
< 3.30.3
MEDIUM 4.9 The Elementor plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.30.2 via… wordfence
12349179-e61c-42b8-b0ff-5b49fc4906c1
< 1.4.1
MEDIUM 4.9 The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a… wordfence
120f15aa-ccef-49be-8743-e77d699601e2
< 2.7.15
MEDIUM 4.9 The RSVP and Event Management Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
1197a66e-4557-458f-b8fd-b7a8e7586817
< 2.53
MEDIUM 4.9 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to Sensitive… wordfence
115a63bd-65ca-4ccb-affd-c14119d6b9a3
< 6.5.1
MEDIUM 4.9 The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.5 d… wordfence
10c5ed1e-1288-4b57-a26c-874c15dcef08 MEDIUM 4.9 The WP Triggers Lite plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.5.3 due… wordfence
109427de-3b8a-46cc-a888-6fea4f72a31a
< 2.7.2
MEDIUM 4.9 The plugin Mailchimp for WooCommerce for WordPress is vulnerable to Server-Side Request Forgery via one of its AJAX acti… wordfence
10543a3b-e1ac-4c6b-b511-4cbd45924f6f
< 7.4.0
MEDIUM 4.9 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… wordfence
0f6d0ba7-f9e8-493b-9e6d-62f1c662e21e
< 4.1.5
MEDIUM 4.9 The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to Arbitrary File Read via Directory Trave… wordfence
0d1c85c3-2aa7-4b65-a771-a4571746bfc9
< 4.5.5
MEDIUM 4.9 The Slim SEO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.4 due to insuffic… wordfence
0cd62935-f865-43ff-b727-f17b6fc5976d MEDIUM 4.9 The WordPress Auction Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7 d… wordfence
0b395777-2e2a-4dc3-9b0c-ce4c9d22d7e9
< 4.1.0
MEDIUM 4.9 The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_dire… wordfence
0afe37bb-fa8a-4e7b-93c6-c44b3fbeb904
< 1.4.4
MEDIUM 4.9 The ELEX WooCommerce Google Shopping (Google Product Feed) plugin for WordPress is vulnerable to SQL Injection via the '… wordfence
← Prev 1255 1256 1257 1258 1259 1260 1261 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top