🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 153 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
947626b4-c640-4b45-8186-2ed4ff7c2c18
< 19.6.2
HIGH 8.8 The REHub Framework plugin for WordPress is vulnerable to SQL Injection in versions prior to 19.6.2 due to insufficient … wordfence
94356695-d2b1-4144-a0ca-b638d4e70d8f
< 1.8.8
HIGH 8.8 The WpTravelly plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.8.7 via de… wordfence
942ae035-91b3-4330-800c-2dbe94a4b4b5
< 2.2.5
HIGH 8.8 admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica… wordfence
93ff1634-d520-4895-8822-2dbfa7b5e030
< 1.13.3
HIGH 8.8 In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_… wordfence
93ef0a2c-2197-4c23-b5c4-5a94bd44130d
< 2.2.6
HIGH 8.8 The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard … wordfence
93a4d653-a852-41c1-8942-8f059420aeb1
< 8.4.4
HIGH 8.8 SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary … wordfence
9391474f-8cf8-4e8b-b3e6-39b397b7b6b6
< 2.5.2
HIGH 8.8 The Master Slider - Responsive Touch Slider plugin for WordPress is vulnerable to blind SQL Injection via the ‘orderby… wordfence
938be2d0-1e56-42d5-874e-574e78a44932
< 2013.0.1.41
HIGH 8.8 The Developer Formatter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 2013.0.1.41. … wordfence
938b8a4f-96cf-488d-8fd9-116caa929ccf
< 14.1.8
HIGH 8.8 The AI ChatBot for WooCommerce with ChatGPT, Retargeting, Exit Intent plugin for WordPress is vulnerable to arbitrary fi… wordfence
9382d94c-3767-4d05-ada7-2857713b9e3a
< 3.0.0
HIGH 8.8 The Sahifa theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4.0. This… wordfence
93495395-42cc-4787-be95-4691ff77d01b
< 1.2.3
HIGH 8.8 The GeekyBot — AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content plugin for WordPress is vulnerable to a… wordfence
931e83b6-b05a-4f48-a159-e15cc99e0fe4
< 2.0.4
HIGH 8.8 The export_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or n… wordfence
93164941-effe-4363-811e-3161cff10c88
< 2.0.7
HIGH 8.8 The WP Simple Booking Calendar WordPress plugin before 2.0.7 did not escape, validate or sanitise the orderby parameter … wordfence
93027dd1-f36a-4954-a8d2-b77bbbaef6fb
< 1.1.19
HIGH 8.8 The Hydra Booking plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the tf… wordfence
92f6f3f7-c49b-4290-806f-6add333159b9
< 4.6.2
HIGH 8.8 The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data paramet… wordfence
92f02a92-9364-492e-a896-2f7e6f8b3b13
< 1.6.0
HIGH 8.8 The WP Shopify plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.9. This … wordfence
92d048a2-3ecb-466d-9e0c-f1b654d2a944
< 4.2.2
HIGH 8.8 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg plugin for WordPress is vuln… wordfence
92c88e7f-9393-4e44-8a1d-314f6560bf63 HIGH 8.8 The GoCodes plugin for WordPress is vulnerable to blind SQL Injection via the ‘gcid’ parameter in versions up to, an… wordfence
9269d18d-8d83-43ff-b777-ba8f58321e9e HIGH 8.8 The Offsprout Page Builder plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization plac… wordfence
92652339-ec86-4069-aeee-91c314ed2540
< 5.39
HIGH 8.8 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor… wordfence
925ca72b-3761-42e5-aace-b31d42bc9a73
< 5.5.0
HIGH 8.8 The Content Egg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.0… wordfence
925af22b-a728-496e-a63a-5966347ebe6c
< 7.29
HIGH 8.8 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Remote Code Execution in… wordfence
921795f5-0477-474b-a9c2-3f5955c6f131
< 2.17
HIGH 8.8 The WC Affiliate plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.16 via d… wordfence
921489e9-a083-47b3-a20d-e2566b51d8d4
< 1.5
HIGH 8.8 SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra… wordfence
91f67907-9b42-4fa3-a333-2ac0d3afaaad
< 4.1.0
HIGH 8.8 The Post Snippets – Custom WordPress Code Snippets Customizer plugin for WordPress is vulnerable to Remote Code Execut… wordfence
← Prev 150 151 152 153 154 155 156 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top