πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 275 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fb1f3774-7d5a-44f3-9488-9eb76013e37d
< 0.92.0
HIGH 7.5 The List category posts plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.9… wordfence
fb1a977f-e5ce-425b-8817-c03b2a660265
< 7.8.0
HIGH 7.5 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to SQL Inject… wordfence
fb19f920-0fd0-491e-9e87-62c828cad9b9
< 3.13.1.6
HIGH 7.5 The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injec… wordfence
fad510b7-85f4-4cae-aaf0-eb68a32cf1b4
< 5.0.6
HIGH 7.5 The CF7 Google Sheets Connector plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up … wordfence
facb10e9-23f3-4152-bc9a-cecaafebea94
< 1.9.1
HIGH 7.5 The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Sensitive Data Exposure in vers… wordfence
faaade72-35d9-4597-812b-758fa2641472
< 5.0
HIGH 7.5 Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote at… wordfence
fa980215-3e8f-40e5-9855-12e9fd9258aa
< 15.1
HIGH 7.5 The Responsive Posts Carousel WordPress Plugin plugin for WordPress is vulnerable to Local File Inclusion in versions up… wordfence
fa098a19-6984-4eeb-b8cd-178d0e41e005
< 4.1.4
HIGH 7.5 The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deser… wordfence
f9ae9aba-fa0e-4a3d-a970-e45216685cc0
< 3.8.7.1
HIGH 7.5 The Duplicator (Free & Pro) plugin for WordPress is vulnerable to Directory Traversal in versions up to 1.3.28 (and Dup… wordfence
f9aae623-abff-4216-981f-dcd13f367a8d
< 1.4
HIGH 7.5 Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker… wordfence
f980e902-820b-43e0-8334-fc70c711a126 HIGH 7.5 The estrutura-basica theme for WordPress is vulnerable to Directory Traversal in all known versions via the arquivo para… wordfence
f90d50e4-7c71-4381-89af-92cdf20d7b39
< 1.2.15
HIGH 7.5 The Nika theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.14. This makes … wordfence
f8424fbf-4fa3-45da-b6dc-a71be6e60e3d
< 1.6.2
HIGH 7.5 The Modal Popup Box plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.1 v… wordfence
f7e70efa-a165-4251-ae54-621ea432c94c HIGH 7.5 The Bitcoin / AltCoin Payment Gateway for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up… wordfence
f7a2f989-7735-4bed-9cd9-1590093b0cd9
< 9.0
HIGH 7.5 The Bulk Product Sync plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.6 due to i… wordfence
f79164c2-be3b-496d-b747-3e4b60b7fc2b
< 1.1.0
HIGH 7.5 The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads du… wordfence
f783e626-37c0-4ad9-9074-c5332583a0cb
< 3.4.12
HIGH 7.5 The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions … wordfence
f767d94b-fe92-4b69-9d81-96de51e12983
< 4.6.9
HIGH 7.5 The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.… wordfence
f70dabb4-3ae6-43cf-86e2-62ac1454b697
< 3.3.4
HIGH 7.5 The Wise Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
f6507318-92c0-457c-8c87-2d023428a77f
< 2.1.0
HIGH 7.5 The AnalyticsWP plugin for WordPress is vulnerable to SQL Injection via the 'custom_sql' parameter in all versions up to… wordfence
f64bc3c4-da89-4470-8353-d490f8bec408
< 2.2.0
HIGH 7.5 The WPC Name Your Price for WooCommerce plugin for WordPress is vulnerable to unauthorized price alteration in all versi… wordfence
f63db09e-4bba-45e5-a8c5-6f02c0010e8b HIGH 7.5 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Director… wordfence
f62fa18a-dfb3-4738-a308-96e9f8e04e90
< 1.0.4
HIGH 7.5 The Togo theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.0.4 via deserialization of untrus… wordfence
f613411e-2b2e-401d-87cd-a002e9c2fc08
< 1.3.0
HIGH 7.5 The WP Popup Builder plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.9… wordfence
f5dfafee-9b6c-4e57-b263-39ff15cd3b51 HIGH 7.5 The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, … wordfence
← Prev 272 273 274 275 276 277 278 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top