ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1586 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
003686a7-929b-4c17-bb4b-2a330506819c
< 4.1.19
MEDIUM 4.3 The Event SOlution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including… wordfence
00274313-9079-4877-b72e-310e312aa814
< 1.3.0
MEDIUM 4.3 The Backup Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
0007d830-2e68-4c2f-8fac-f4363bc2d73d
< 4.3.6
MEDIUM 4.3 The Gift Cards (Gift Vouchers and Packages) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions… wordfence
e3048c4c-77b1-4778-a5d0-b532df777d06 MEDIUM 4.2 The Buddypress Force Password Change plugin for WordPress is vulnerable to authenticated account takeover due to the plu… wordfence
dcbfcaeb-2635-4b11-b426-ee04345d5f36
< 1.8.8
MEDIUM 4.2 The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
c2081e4a-c6b7-4730-be59-bc728b90ecaa
< 1.67
MEDIUM 4.2 The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a m… wordfence
8242e0f0-b9c5-46fe-b691-3275cd0f9a43
< 5.1.19
MEDIUM 4.2 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
63374c5c-0b0a-4091-9aee-2e6c1d17a1b2 MEDIUM 4.2 The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5… wordfence
f5b8d39c-d307-42c9-a972-29b5521a82a4
< 6.9.12
MEDIUM 4.1 The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions… wordfence
ee11d9e5-64d5-49b4-b5f5-b76605250028
< 2.2.20
MEDIUM 4.1 The GeoDirectory plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.2.19. This allo… wordfence
e9c9214d-45d4-4477-8244-7802a4901114
< 7.0.6
MEDIUM 4.1 The Media Cleaner: Clean your WordPress! plugin for WordPress is vulnerable to Server-Side Request Forgery in all versio… wordfence
dc24d2de-352c-4215-a4db-2966aa6467c7
< 2.9
MEDIUM 4.1 The Real3D Flipbook plugin for WordPress is vulnerable to Directory Traversal via uploads in versions up to, and includi… wordfence
d2e040bd-df5f-4b40-bc7b-9521f224c297
< 1.3.43
MEDIUM 4.1 The Photo Gallery by 10Web plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.3.42… wordfence
cd96beee-afcb-4439-ad9b-f24e8afeac3c
< 1.3.1
MEDIUM 4.1 The Broken Link Notifier plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.3.0… wordfence
bda0d24c-b1c9-4ae4-93b3-46568982d718
< 1.5.5
MEDIUM 4.1 Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <=… wordfence
a3a5c4f2-22f6-45df-bf76-9dfa1d2f5f41
< 3.2.4
MEDIUM 4.1 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to unauthorized access due to a miss… wordfence
8436ba39-b236-4d76-95b6-d2bed3728d8a
< 2.0.0
MEDIUM 4.1 The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to Arbitrary Log File Download in versions below… wordfence
7d65a987-e8a6-4615-b681-9f48b7caed4f
< 4.3.3
MEDIUM 4.1 The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. wordfence
66bd5065-aa4c-4b5b-a312-2f7bd1643d35 MEDIUM 4.1 Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booki… wordfence
5177bde6-4922-48ee-9155-577c392809a0
< 3.3.1
MEDIUM 4.1 The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and… wordfence
4fd929e7-8f28-43de-92ce-4f52ece24f7c
< 2.9.2
MEDIUM 4.1 The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Remote Code Execution in a… wordfence
4a748589-51e5-4e3c-930c-d073d5cc94bf
< 1.1.83
MEDIUM 4.1 The WP Time Slots Booking Form plugin for WordPress is vulnerable to authorization bypass due to improper capability che… wordfence
3b1bfe88-2513-4acc-91e2-50a3bc9d7183
< 3.5.8.4
MEDIUM 4.1 wordfence
2677cea6-d60d-4e10-afd7-e088a5592b19
< 2.9.7
MEDIUM 4.1 The Welcart e-Commerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2… wordfence
258177c4-d3d4-4465-8b73-0af1b02485b0
< 6.5.3
MEDIUM 4.1 The Import Export All WordPress Images, Users & Post Types WordPress plugin before 6.5.3 does not fully validate the fil… wordfence
← Prev 1583 1584 1585 1586 1587 1588 1589 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top