πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 162 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7e3a1e3c-eba0-4ef4-bcb8-929799bb56a8
< 7.6.3
HIGH 8.8 The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy… wordfence
7e24383b-5b0f-4114-908b-4c2778632f73
< 12.1
HIGH 8.8 The wp image slideshow plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to,… wordfence
7e199cd3-e2ce-4969-a517-4a9c2a84bf44
< 1.0.17
HIGH 8.8 The Travelpayouts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
7e0fd44d-e152-4883-a734-031f68e3ba97
< 3.3.4
HIGH 8.8 The LinkWorth plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.3. … wordfence
7df0ea8a-5e2c-4f5e-a326-b92df37ffa3c
< 2.0.7
HIGH 8.8 The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,… wordfence
7dea9b4a-d7a5-4ea7-b55f-b42f8f5c4a91
< 8.6.8
HIGH 8.8 The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via th… wordfence
7de51bf2-f3dc-40d7-8d63-c85c267c4e98
< 2.1.10
HIGH 8.8 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to blind SQL Injection via the several… wordfence
7dd45dc7-b37c-42f3-a4b5-c4564174148c HIGH 8.8 The amtyThumb WordPress plugin through 4.2.0 does not sanitise and escape a parameter before using it in a SQL statement… wordfence
7d977636-a509-4f32-9ad3-762720fdb433 HIGH 8.8 The MF Gig Calendar plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, … wordfence
7d66694a-c99f-44f8-8004-1a47ad9f9250
< 2.2.5
HIGH 8.8 The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering o… wordfence
7d623512-ee99-4a73-a752-ecbb6ad96b63
< 2.2.0
HIGH 8.8 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via many parameters in versions up to, and including, … wordfence
7d5dd7cd-f96a-48df-a553-be5e59d8290f
< 0.7.2
HIGH 8.8 The Link Whisper Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0… wordfence
7d525c50-5911-4be6-a860-b48db619adba
< 3.1
HIGH 8.8 The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
7d379721-d629-433d-ba89-a74c9dec537e
< 4.1.4
HIGH 8.8 The Advanced Dynamic Pricing for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in version… wordfence
7d057ac6-a341-4ec3-956c-2a2a5636155c
< 5.4.22
HIGH 8.8 The Woffice Core plugin for WordPress, used by the Woffice Theme, is vulnerable to arbitrary file uploads due to missing… wordfence
7cbe39ae-d10b-432f-afab-682948de2521 HIGH 8.8 The Video Merchant plugin for WordPress is vulnerable to Cross-Site Request Forgery in version <= 5.0.4. This is due to … wordfence
7cbb1e71-baf1-4d1d-96c8-93fd2686297d
< 11.8
HIGH 8.8 The WP Google Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid parameter in versions up to… wordfence
7cb08fc1-fb8b-4478-8569-eb9b28aff50b
< 1.8.1
HIGH 8.8 The Style Kits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.0.… wordfence
7c734aa9-ee9e-4605-a4b8-5075ce4b941f
< 3.11.2
HIGH 8.8 The Fusion Builder plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and i… wordfence
7c22bf07-753b-4874-893a-952105dc8107
< 1.1.37
HIGH 8.8 The Popup Builder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.35. T… wordfence
7bfd4e4c-63c2-4442-b91a-ca940a31c3be
< 1.2.11
HIGH 8.8 SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to… wordfence
7be28b54-def9-46b7-bb59-58b0ae5ea674
< 4.2999
HIGH 8.8 The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions o… wordfence
7b971ae0-624d-416e-b2f2-92ce44e96418 HIGH 8.8 The Randomize plugin for WordPress is vulnerable toSQL Injection in versions up to, and including, 1.4.3 due to insuffic… wordfence
7b941db0-9d6d-4b89-8e04-8770499b6a9a
< 2.9.14
HIGH 8.8 The Sunshine Photo Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
7b834a3c-6af0-48fd-aa13-985d226b546d
< 1.5.9
HIGH 8.8 The Nextend Facebook Connect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
← Prev 159 160 161 162 163 164 165 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top