πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 276 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f5c1f0f4-4557-4ae9-bf0d-14c61721a2c5
< 7.8.8
HIGH 7.5 Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports. wordfence
f5af4aa1-e384-4bc2-a9d2-67e4685eea4e HIGH 7.5 The Miion theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.7. This makes … wordfence
f5319467-92f6-4d4f-a76a-12aeb25d3c6b
< 0.1.3.7
HIGH 7.5 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in al… wordfence
f4ccfeac-e20e-45f3-9c38-a139130b4ab8
< 3.8.2
HIGH 7.5 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to,… wordfence
f4832fbb-94ed-41c4-8434-1972f4d92476
< 2.4.2
HIGH 7.5 The Ultimate Member plugin for WordPress is vulnerable to Username Enumeration in versions up to, and including, 2.4.1 v… wordfence
f43db496-80ea-442c-9417-7aa03ec95f02
< 5.4.02
HIGH 7.5 The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all vers… wordfence
f393c5c0-03e7-4f9b-8714-2b25c1010176 HIGH 7.5 The Uroan Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.4 due to insuff… wordfence
f37cc880-d8a4-431a-9639-abf01163030a
< 1.15.43
HIGH 7.5 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL I… wordfence
f2febf69-b146-4ca5-bfa9-f5477da5cd6c
< 3.1.6
HIGH 7.5 The Memphis Documents Library plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and incl… wordfence
f2db06b1-c823-45db-b6f5-b656978cc779
< 0.6.67
HIGH 7.5 A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attac… wordfence
f2c20cde-012c-4dca-a8ae-2229131c08e1
< 7.34.0
HIGH 7.5 The Modern Events Calendar (Lite & Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… wordfence
f2891f3d-9081-4a9f-8408-2373ce1d0306
< 4.6.3
HIGH 7.5 The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v… wordfence
f26f1613-5fb4-4c4b-a993-15089b53af2e HIGH 7.5 The WP HRM LITE plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 due to insuffi… wordfence
f24e753e-2eb0-49a2-9fb1-68daaca12816
< 1.0.8
HIGH 7.5 The sell-downloads plugin before 1.0.8 for WordPress has insufficient restrictions on brute-force guessing of purchase I… wordfence
f24db166-93d6-4a61-a8fe-455eebde0777 HIGH 7.5 Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is autho… wordfence
f218f967-a218-4a5f-991e-cfed226a313f HIGH 7.5 The WPCHURCH plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.0 due to insuffic… wordfence
f214b915-f33a-450f-880b-f08be8284e9c HIGH 7.5 The Sala theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.3 via deseriali… wordfence
f200062a-5f53-4abc-ae96-904f85d8b4e8 HIGH 7.5 The Sales Countdown Timer for WooCommerce and WordPress plugin for WordPress is vulnerable to Local File Inclusion in ve… wordfence
f185709e-0d13-48d3-9c15-03466b72dac2
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
f14a658c-1517-4af4-8bd7-c379ac07ab35
< 5.2.11
HIGH 7.5 The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
f1117b57-bd86-4e90-b1bb-e13939e0e766
< 1.5.1
HIGH 7.5 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.0 due to … wordfence
f10cf49b-1b78-43c1-b0d1-c1dbb74d5696
< 3.8.6.2
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all version… wordfence
f1060875-21dc-41fb-866a-940e6aeb3c22
< 2.5
HIGH 7.5 The Echelon Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This is … wordfence
f0ff2cb3-a385-4f5c-b555-b6a3dadfc458
< 2.2
HIGH 7.5 The Fusion Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.1. This is d… wordfence
f0e97124-641c-4d35-a274-6a127d2d7d18
< 3.8.4.1
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.8.4.1 (exclusive) via d… wordfence
← Prev 273 274 275 276 277 278 279 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top