🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,590
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 14, 2026
Last Updated

39,590 vulnerabilities found (page 219 of 1584)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e8a704b5-6db3-4197-bf03-c64f0508bcf1
< 1.9.9.5
HIGH 8.2 The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary directo… wordfence
e2c11005-dcb3-40b3-863a-0612132acb08
< 3.9.6
HIGH 8.2 The Slimstat Analytics plugin for WordPress is vulnerable to blind SQL Injection via the ‘_data’ parameter in versio… wordfence
e2876c97-a612-4c0f-b094-3233768703b1 HIGH 8.2 The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shor… wordfence
d96743ea-08b1-4b4c-9d62-558b97a6e297
< 4.1.3
HIGH 8.2 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due… wordfence
d7389e17-a357-481a-8716-3a93cb6afa7c
< 5.2.0
HIGH 8.2 The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with… wordfence
d5fa3282-b3be-4ea1-9865-011dea828a25
< 4.0.2
HIGH 8.2 The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information di… wordfence
cc468bfd-b9a2-4fe6-b896-d738c767146a
< 7.1
HIGH 8.2 The Super Store Finder plugin for WordPress is vulnerable to SQL Injection via the ‘ssf_wp_user_name’ parameter in a… wordfence
c31828dc-ef94-4895-8395-a5d52a0a82bd
< 1.2.6
HIGH 8.2 The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure token check that is susc… wordfence
b85b44ed-94cd-4d85-bcc5-60b50cdb94f1
< 0.5.10
HIGH 8.2 The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. wordfence
b105fe2a-b1fd-42d4-ab16-b80115e22531
< 1.4.4
HIGH 8.2 The Site Offline Or Coming Soon Or Maintenance Mode plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
ae13dc61-c4bf-4b17-8055-98c80a853a2a
< 1.3.7
HIGH 8.2 The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici… wordfence
a881ca02-cef9-4f4b-8a62-e241c4c80004
< 8.0.0
HIGH 8.2 The PeproDev Ultimate Profile Solutions plugin for WordPress is vulnerable to unauthorized modification of data due to a… wordfence
a41d78b9-9bdb-48dd-b3ec-2559e79fa251
< 3.11
HIGH 8.2 The WP Email Capture plugin for WordPress is vulnerable to unauthorized Email Capture list download due to a missing cap… wordfence
9db1dfde-0cba-41b2-ab7a-a1640e5fd96b
< 2.2.1
HIGH 8.2 The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr… wordfence
9cd12b8a-2033-4236-abcd-2a8d08e7f099
< 6.2.1
HIGH 8.2 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
9239d691-c431-402e-83ce-01896c9433fc HIGH 8.2 The Grand Restaurant WordPress theme for WordPress is vulnerable to unauthorized modification of data that can lead to a… wordfence
8fecc015-518f-4aab-a17e-17cf4b8cf123
< 5.1.3
HIGH 8.2 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions … wordfence
81aad41e-0330-4dff-a5f8-08a108d724f5
< 6.2.0
HIGH 8.2 The Fluent Forms plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions … wordfence
7e639aed-ec67-4212-9051-1f7465bbfde2
< 2.0.3
HIGH 8.2 The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions … wordfence
7a04705d-cd17-4b4b-b04d-de55d6479dab
< 1.3.95
HIGH 8.2 The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file … wordfence
78d7920b-3e20-43c7-a522-72bac824c2cb
< 6.15.22
HIGH 8.2 The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for W… wordfence
78af7acb-bcaf-4ad9-807e-4a95a522f8c5
< 4.3.0
HIGH 8.2 The jobify theme for WordPress is vulnerable to arbitrary file read in all versions up to, and excluding, 4.3.0. This ma… wordfence
77eb40c2-735a-49f2-9d07-5cf7535bd722
< 2.6.5
HIGH 8.2 The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due… wordfence
65a02152-be62-4e27-8a31-e88f23e0236f
< 2.7.1
HIGH 8.2 The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files. wordfence
656300ce-6e94-4382-b0ed-9cecca5b917c
< 1.4.0
HIGH 8.2 The Watermark RELOADED plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
← Prev 216 217 218 219 220 221 222 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top