πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1591 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
112ece28-27ac-4d3c-b302-7acab43390fb LOW 3.1 The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the mo… wordfence
0d3010a9-10fa-40ec-9791-3ac993123f93
< 3.9.0
LOW 3.1 Cross-site request forgery (CSRF) vulnerability in the All In One WP Security & Firewall plugin before 3.9.0 for WordPre… wordfence
0ac6603f-7eed-424e-a56b-f45d4a7f7b2a
< 1.1.31
LOW 3.1 Multiple cross-site scripting (XSS) vulnerabilities in the Web-Dorado Photo Gallery plugin 1.1.30 and earlier for WordPr… wordfence
07904ed6-ff3c-41b6-a0ee-87fdbfd14bea
< 0.3.6
LOW 3.1 The FV Thoughtful Comments plugin for WordPress is vulnerable to unauthorized access due to a missing capability check o… wordfence
4f9bd960-01ef-41dd-ab05-0a5f734484a2
< 2.2
LOW 3.0 The EventON plugin for WordPress is vulnerable to HTML Injection via admin settings in all versions up to, and including… wordfence
ee8436c2-3dda-481c-92b3-cc2ba8fc1993
< 9.0.0
LOW 2.7 The WooCommerce plugin for WordPress is vulnerable to content injection in all versions up to, and including, 8.9.2. Thi… wordfence
eb3a26c7-8693-4a1d-a2b9-c548ef3c0ee0
< 1.10.5
LOW 2.7 The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPr… wordfence
e05d9aec-5b17-4af8-8985-d4bb003f2d6f
< 5.2.10
LOW 2.7 The B2BKing β€” Ultimate WooCommerce B2B and Wholesale Plugin β€” Wholesale Prices, Bulk Order Form & More plugin for Wo… wordfence
db25e8f7-07f2-470e-850e-b8cd3388baea
< 4.16
LOW 2.7 The Car Dealer (Dealership) and Vehicle sales plugin for WordPress is vulnerable to unauthorized content injection due t… wordfence
d222ef6d-cdec-482e-92ba-65eeabbcdeae
< 2.5.1
LOW 2.7 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to arbi… wordfence
CVE-2026-2419 LOW 2.7 The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… nvd
CVE-2026-1831 LOW 2.7 The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac… nvd
CVE-2025-14270 LOW 2.7 The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, … nvd
c97a341c-23f5-49a9-ad05-1fb387047e3b
< 2.5
LOW 2.7 The Rankology SEO and Analytics Tool plugin for WordPress is vulnerable to unauthorized modification of data due to an i… wordfence
c6ae2f0d-a0c2-4f4a-bb1b-f6419aa2e155 LOW 2.7 The Foxit eSign for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
c2805cb0-8913-4487-8445-031b7d920e2d
< 3.14
LOW 2.7 The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13… wordfence
c0c293db-5526-4600-838a-6e88586926c4
< 2.7.2
LOW 2.7 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Path Traversal in all versi… wordfence
bbd5e24f-2934-422e-a3bd-452e916c2ffb
< 2.2.12
LOW 2.7 The GPX Viewer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.11. This m… wordfence
b9002f6e-4345-4908-9cb8-9841a2458eb7
< 1.11.12
LOW 2.7 The CartFlows plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1… wordfence
b871883c-509b-4776-b550-349b3f5aa365 LOW 2.7 The WordPress Gallery Exporter – Export your NextGen, Envira and FooGallery galleries to your computer plugin for Word… wordfence
b4b5cc5e-af82-49e0-a0b5-d27c3631a102
< 1.1.0
LOW 2.7 The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, … wordfence
b043197c-4477-4663-abb8-5840173c574d
< 2.3.1
LOW 2.7 The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information … wordfence
ad382ec2-55c8-4d6c-b318-db199f812493
< 1.176.0
LOW 2.7 The Site Kit by Google – Analytics, Search Console, AdSense, Speed plugin for WordPress is vulnerable to unauthorized … wordfence
a821d61c-e3c8-4a1b-8a52-a63adcb6c127
< 1.0.8.6
LOW 2.7 The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to Path Traversal i… wordfence
a568162a-5a2d-47ab-9dfe-2f2f5f324f0d
< 4.3.3
LOW 2.7 The YayMail - WooCommerce Email Customizer plugin for WordPress is vulnerable to unauthorized plugin installation and ac… wordfence
← Prev 1588 1589 1590 1591 1592 1593 1594 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top