🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 274 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ff506c6a-6a8b-47ca-a2bd-e9502a60271d
< 2.15.2
HIGH 7.5 The Paid Member Subscriptions plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.15… wordfence
ff346465-62c2-4a2b-8a4a-c88558d7cabd
< 1.7
HIGH 7.5 The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is… wordfence
ff319625-bc2c-454a-8194-f9fe11baad2f
< 1.3.8
HIGH 7.5 The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in version… wordfence
ff21241d-e488-4460-b8c2-d5a070c8c107
< 3.2.8
HIGH 7.5 The Simple File List WordPress plugin is vulnerable to Arbitrary File Download via the eeFile parameter found in the ~… wordfence
feee3268-b384-400c-a76d-e5d7972c05b7
< 2.2.69
HIGH 7.5 The Post Grid Combo – 36+ Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
fed758e0-7fea-4b6a-9157-47f5603be2c9 HIGH 7.5 The Instant Appointment plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to… wordfence
fec590e7-c15e-4063-892a-a945333d848e HIGH 7.5 The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the … wordfence
febd1ff3-3a1a-49c2-b210-9e72051e3172
< 3.1.7
HIGH 7.5 The Travel Booking WordPress Theme theme for WordPress is vulnerable to blind time-based SQL Injection via the ‘order_… wordfence
feb056b0-5ea0-4257-8d58-0e29b3c304bd
< 3.2.39
HIGH 7.5 The Download Manager WordPress plugin before 3.2.39 uses the uniqid php function to generate the master key for a downlo… wordfence
fea7c3f1-1fb4-4a0f-8bbe-c4a0e346993f
< 5.9.2
HIGH 7.5 The Basel - Responsive WooCommerce Theme theme for WordPress is vulnerable to unauthorized access due to a missing capab… wordfence
fe93f443-7941-4463-a068-c292c172f071 HIGH 7.5 The S3 Bubble Amazon S3 HTML5 Video with Adverts plugin for WordPress is vulnerable to Arbitrary File Download in versio… wordfence
fe926435-ef91-4717-8612-31c053771491 HIGH 7.5 The AdminOnline plugin for WordPress is vulnerable to Directly Traversal/Arbitrary File Read via the 'file' parameter in… wordfence
fe573d64-036e-4f6f-bcc1-5183bb9ad2b9
< 2.0.3
HIGH 7.5 The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including… wordfence
fe43b168-5b40-4d64-8fbd-c394970e832e HIGH 7.5 The North plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.2. This makes… wordfence
fdf33f1c-7e07-425a-aed7-43511f358362 HIGH 7.5 The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 92.0.0 due t… wordfence
fd839b20-69d1-4cad-80fc-3e7b9940fd30
< 3.8.10.2
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The list… wordfence
fd739eb1-4d63-42a2-85ba-a4cfc034628f HIGH 7.5 The Handmade Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.… wordfence
fd64b351-fbce-4c75-bdd7-3b38a1b5d049
< 3.2.2
HIGH 7.5 The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to,… wordfence
fd5fb3fb-425a-458b-b3cb-92cd23f50726
< 3.8.10
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.9.1 due to insuf… wordfence
fd1704ef-e259-40a3-974b-128145bc8a4a
< 2.4.13
HIGH 7.5 The wpForo Forum plugin for WordPress is vulnerable to generic SQL Injection via the `post_args` and `topic_args` parame… wordfence
fc0a1bfe-0ead-4333-bb77-0f2f4356626d
< 1.0.0
HIGH 7.5 The Peter's Math Anti-Spam Spinoff plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to 1.0.0. This is… wordfence
fbea84f2-2077-4ea9-b5dc-e527423810fc HIGH 7.5 The Sports Rankings and Lists plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… wordfence
fbcb33c1-d8f4-4ff9-8148-7bce494b2f0f HIGH 7.5 The WP Backup+ (aka WPbackupplus) plugin through 2018-11-22 for WordPress allows remote attackers to obtain sensitive in… wordfence
fb5c7875-e531-4ee8-bd19-360cbcfef8ed
< 4.0.8
HIGH 7.5 The Turbo Manager plugin for WordPress is vulnerable to Local File Inclusion in versions up to 4.0.8. This makes it poss… wordfence
fb26ea7b-fc54-4cef-aaa8-3a41e8d0c371
< 2.0
HIGH 7.5 The wp-private-content-plus plugin before 2.0 for WordPress has no protection against option changes via save_settings_p… wordfence
← Prev 271 272 273 274 275 276 277 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top