πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,549
Total CVEs
66
CISA KEV (Actively Exploited)
Sep 2, 2026
Last Updated

40,549 vulnerabilities found (page 1593 of 1622)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
33356b50-9c9c-4719-8321-b391fda69867
< 1.9.13
LOW 2.7 The Pricing Table by Supsystic plugin for WordPress is vulnerable to content injection in all versions up to, and includ… wordfence
30beb916-764e-48fd-bcd4-f772b9d92133
< 1.6.1
LOW 2.7 The Squeeze – Image Optimization & Compression, WebP Conversion plugin for WordPress is vulnerable to Full Path Disclo… wordfence
2d8b816f-815a-4109-b34b-06e806c765e8
< 4.8.4
LOW 2.7 The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerabl… wordfence
2d4e9daf-d414-4ace-9efd-4c3e16deeb8f
< 4.1.0
LOW 2.7 The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1.… wordfence
2d443c70-6537-4c6d-a282-12d392f0f558
< 2.6.3
LOW 2.7 The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… wordfence
181403fe-42be-4136-8ff5-5ef40904124b
< 1.3.7
LOW 2.7 The WP Directory Kit plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 1.3.6. T… wordfence
1405d8e3-3aa8-4a32-ac55-a260eda3d68c
< 2.0.5
LOW 2.7 The Academy LMS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… wordfence
11c9124d-80e0-435d-9eb4-901c4f481a6f
< 1.0.4
LOW 2.7 The FileOrganizer plugin for WordPress is vulnerable to unauthorized access of data due to missing controls throughout t… wordfence
0bb96da1-9c17-4264-ac29-b5ff8dec745d
< 1.69.1
LOW 2.7 The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… wordfence
06f4b68c-eb17-470a-a119-5143eff7117e LOW 2.7 The Traveler Option Tree plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and… wordfence
045e3aba-16b6-46f1-8c57-dd54e1e0e950
< 1.0.8.4
LOW 2.7 The WOLF – WordPress Posts Bulk Editor and Manager Professional plugin for WordPress is vulnerable to PathTraversal in… wordfence
027fa70f-8777-4a0b-b2aa-18bcdcd99cbf
< 8.7.4
LOW 2.7 The Import feature of the RSVPMaker WordPress plugin before 8.7.4 (/wp-admin/tools.php?page=rsvpmaker_export_screen) tak… wordfence
01984754-e332-4500-99a2-10a7b79967f5
< 2.1.3
LOW 2.7 The Keep Backup Daily plugin for WordPress is vulnerable to Limited Path Traversal in all versions up to, and including,… wordfence
d5c48de7-20f6-408e-b4fb-f3d5d7ab272f
< 1.3.24
LOW 2.4 The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less … wordfence
92895f8e-59c9-4988-9d7a-2601880d71a2
< 3.7.34
LOW 2.4 In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that coul… wordfence
f029bd86-d979-45d1-97fe-75c43fb71148
< 2.7.5
LOW 2.2 The Modula plugin for WordPress is vulnerable to unauthorized modification of data due to an incomplete capability check… wordfence
77227fc5-7c38-476d-af4c-4b2ad3dd8420
< 5.0.29
LOW 2.2 The Church Admin plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,… wordfence
73980a90-bb17-46e4-a0ea-691f80500fe3
< 4.5.1.3
LOW 2.2 The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS … wordfence
640b1800-3b59-4b06-a803-08cb76d62d99
< 6.3
LOW 2.2 The File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager plugin for WordPress i… wordfence
4bce4f04-e622-468a-ac7e-5903ad50cc13
< 4.0.3
LOW 2.2 The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up t… wordfence
1ea40b96-4693-4f98-8e6e-2ed8186cedd8
< 1.3
LOW 2.2 The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in vers… wordfence
0585969d-dd08-4058-9d72-138a55a2cdf1
< 4.2
LOW 2.2 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Passback in versions up t… wordfence
CVE-2026-8832
< 2.3.6
LOW N/A WPCode < 2.3.6 - Author+ Remote Code Execution via XML-RPC wp.newPost wpscan
CVE-2026-8825
< 4.1.4
LOW N/A Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API wpscan
CVE-2026-8438
< 5.4.8
LOW N/A All-In-One Security (AIOS) < 5.4.8 - Unauthenticated Stored Cross-Site Scripting via REST API Request Path wpscan
← Prev 1590 1591 1592 1593 1594 1595 1596 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top