πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1592 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a38a58de-5f7d-4033-9a65-41b590b7d510
< 6.1.1
LOW 2.7 The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check … wordfence
a1ee5b10-1694-4991-b3fb-4b3b365fbca6
< 2025.03.30
LOW 2.7 The Administrator Z plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2025… wordfence
9f58a5eb-53cb-4a25-b693-bcd2b7a1cd00
< 1.0.27
LOW 2.7 The Image Optimizer by 10web plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including,… wordfence
94f0041d-eed6-4980-a7b8-f7410ca68e67
< 1.5.2
LOW 2.7 The Easy WP SMTP plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.5.1 possi… wordfence
941aef7f-435b-4e59-8d55-f95800233c80 LOW 2.7 The Health Check & Troubleshooting plugin for WordPress is vulnerable to Path Traversal in all versions up to, and inclu… wordfence
8c21de03-4d62-4ecf-a2f1-57e0e416792b
< 4.0.3
LOW 2.7 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic… wordfence
890dadec-b60c-4f4c-8644-1a0d1eecc74d
< 2.0.9
LOW 2.7 The Search with Typesense plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0… wordfence
84683caa-8bc7-4adf-ad64-249f988047bf
< 1.4.8
LOW 2.7 The Mobile Events Manager plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.7. T… wordfence
7bdadc84-0cfb-4bec-aeb9-f59f205d269b
< 4.8.5
LOW 2.7 The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerabl… wordfence
7a20b65a-6d3a-41fc-80c5-94cce0459a6b
< 7.3.16
LOW 2.7 The Product Feed Manager – WooCommerce to Google Shopping, Social Catalogs, and 170+ Popular Marketplaces plugin for W… wordfence
7303c2d0-f3b0-41b2-9786-acbe181ccb2e
< 5.1.6
LOW 2.7 The Bold Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.1.5. … wordfence
7115756e-69fa-42fe-bde3-a36e34d4bae3
< 1.2.64
LOW 2.7 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordP… wordfence
6a8d0f86-73fe-43a6-a03a-38bf815dd30b
< 2.5.3
LOW 2.7 The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… wordfence
662aa8dd-69b7-49e3-811c-04329544e106
< 0.9.121
LOW 2.7 The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory … wordfence
640dafa4-c4b8-4f22-ab3b-441667c03428
< 1.9.9
LOW 2.7 The Klarna Order Management for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all … wordfence
607d85a5-afad-49ac-9982-d3da0becc052
< 3.6.4
LOW 2.7 The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.6… wordfence
5d4c92dd-a605-42b5-af10-0a0e25461dde
< 3.17.1
LOW 2.7 The Smush Image Optimization – Optimize Images | Compress & Lazy Load Images | Convert WebP & AVIF | Image CDN plugin … wordfence
5c3862db-d04b-40e2-8b5e-99cd3153d654
< 1.0.277
LOW 2.7 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized access in… wordfence
5a62e8b2-7606-4842-8be5-dff8634539d0
< 1.2.6
LOW 2.7 The Orders Tracking for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in versions up to, and inc… wordfence
4eb8f85f-656a-4e5a-a57d-7289da2cd951
< 2.6.1
LOW 2.7 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins… wordfence
4b78e38b-d16a-4891-96ae-6f6f7138dcc5 LOW 2.7 The Site Info plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
4b389604-a999-45a1-a32f-7f8c951cb94c
< 3.7.4
LOW 2.7 The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, per… wordfence
4613f4d5-8c13-4007-8be0-40568d94fffe
< 1.5.1
LOW 2.7 The Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue plugin for WordPress is vulnerable to unauthoriz… wordfence
3c1a773f-6908-48fc-99d9-a718ee120855
< 2.0.98
LOW 2.7 The Blocksy theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax_bl… wordfence
359c573f-7031-4f56-b66f-c37339667aca
< 7.6.4
LOW 2.7 The wpDiscuz plugin for WordPress is vulnerable to unauthorized modification of data due to a missing authorization chec… wordfence
← Prev 1589 1590 1591 1592 1593 1594 1595 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top