πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 273 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
68420c5a-4add-4597-bd2a-20dc831e81bd
< 2.4.27
HIGH 7.7 The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versio… wordfence
442551ba-409d-4b46-bdba-111a8df00a47
< 1.3.7
HIGH 7.7 The WP CSV Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.6. This al… wordfence
31f6032a-19f8-463b-9642-cba205069a22
< 2.9.4
HIGH 7.7 Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2… wordfence
2e27cfff-6763-4e54-af5d-0f4cf23e72f7
< 3.7.5
HIGH 7.7 wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remo… wordfence
103a7e7b-74bb-4691-8670-c66ed2144596
< 2.9.12
HIGH 7.7 The Paid Memberships Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'membership' shortcode in v… wordfence
0f02b258-d911-401e-8b32-57166d75bde7 HIGH 7.7 The ARforms plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 6.4.1. This … wordfence
eabde2e7-5cd4-4c3e-959a-69e04f6350d3
< 4.9.4
HIGH 7.6 The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu… wordfence
dfd6c2b8-b00c-49d1-930f-50397e742ac5
< 2.0.7
HIGH 7.6 The Gallery Images Ape plugin for WordPress is vulnerable to Arbitrary Plugin Deactivation in versions up to, and includ… wordfence
d9d6e168-a768-4062-9ef1-0be9d6c65c51
< 6.2.0
HIGH 7.6 The RumbleTalk Live Group Chat plugin for WordPress is vulnerable to unauthorized access of data, modification of data, … wordfence
cf4f3f5e-28f7-492c-9d54-4826826bd904
< 2.7.1
HIGH 7.6 On sites that also had the Elementor plugin for WordPress installed, it was possible for users with the edit_posts capab… wordfence
cd7553e8-e43d-4740-b2ee-e3d8dc351e53
< 4.1.6
HIGH 7.6 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to LDAP Injection in versions up … wordfence
ba4aabcc-9db8-4385-90c2-58ed93df8f9d
< 5.8
HIGH 7.6 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database… wordfence
b801e7d9-0ca0-471e-a524-af19ea0d85be
< 5.4.7
HIGH 7.6 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database… wordfence
af063570-43f7-4bf4-850c-21c3bff40ac1 HIGH 7.6 The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to unauthorized modification of data due… wordfence
7be75b0a-737d-4f0d-b024-e207af4573cd
< 2.3.42
HIGH 7.6 The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorize… wordfence
5a4d7d40-8e0e-4251-8e25-3fd4ebd3a93e
< 2.6.3
HIGH 7.6 The Export and Import Users and Customers plugin for WordPress is vulnerable to Server-Side Request Forgery in all versi… wordfence
52daa230-1600-4ace-9adf-3f4e9be51e9f
< 2.1.0
HIGH 7.6 The JupiterX Core plugin for WordPress suffers from several access control issues in versions up to, and including, 2.0.… wordfence
406b52dc-3d36-4b03-a932-34f456395979
< 2.5.1
HIGH 7.6 The Product Import Export for WooCommerce – Import Export Product CSV Suite plugin for WordPress is vulnerable to Serv… wordfence
3283b3ff-1787-466b-9517-84bd715e4165
< 2.6.1
HIGH 7.6 The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all… wordfence
0652b19c-52c8-4d77-973f-1e93a5ba811c
< 5.0.5
HIGH 7.6 Cross-site request forgery (CSRF) vulnerability in the Facebook Members plugin before 5.0.5 for WordPress allows remote … wordfence
ffffedb4-633a-4490-98f1-9bc827c8ba1c
< 3.9.001
HIGH 7.5 The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to o… wordfence
ffdd5446-5835-4976-b764-9b5c75251438 HIGH 7.5 The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all vers… wordfence
ffd1cd48-96dc-4b35-8310-a5eb0a82dc19
< 1.18
HIGH 7.5 The RokNewsPager plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.17 via t… wordfence
ffb72c2a-f0b5-4a82-a187-121636a1d324
< 1.3.6.5
HIGH 7.5 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in… wordfence
ff904d2a-5be1-4a17-ac95-b0099eb616f6
< 3.1.5
HIGH 7.5 The Pendulum theme for WordPress is vulnerable to PHP Object Injection in versions up to 3.1.5 via deserialization of un… wordfence
← Prev 270 271 272 273 274 275 276 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top