πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 277 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f0de8ff3-ac03-4640-829d-66a8496aa8aa
< 2.1.57
HIGH 7.5 The Imagely NextGen Gallery plugin for Wordpress prior to version 2.1.57 does not properly validate user input in the cs… wordfence
f0b9c46d-72db-43f3-b17b-0747375d45c9 HIGH 7.5 The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
f0a5771b-0108-4393-a54e-b5e2c35caeb0
< 2.0.0
HIGH 7.5 A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type paramete… wordfence
f0882205-3037-4ada-9e44-ddd55d88fcb1
< 2.17.6
HIGH 7.5 The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to PHP Object Injection in all vers… wordfence
f0328885-acc2-428f-a834-f837bff200f3 HIGH 7.5 The Knowledge Base theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9 via d… wordfence
f0235347-75ef-458e-97ec-bb9b00e1f9de
< 5.2.19
HIGH 7.5 The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit… wordfence
f01302aa-00ef-440a-9c37-4fde6bb4bb4d
< 1.4.2
HIGH 7.5 The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and… wordfence
f004c401-6b71-413c-bbbd-229b6ddfffe4 HIGH 7.5 The Zingiri Tickets plugin for WordPress is vulnerable to Sensitive Data Exposure via the 'log.txt' file. This can allow… wordfence
ef9f03e9-11cb-489f-9322-b6f17335794f
< 5.1
HIGH 7.5 The Export All URLs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 5.1 (excl… wordfence
ef9b9628-bb56-470c-ba58-228b137963c4 HIGH 7.5 The ServerBuddy by PluginBuddy.com plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
ef61aeba-2105-4da8-8e9c-480e6ed820b7
< 8.2
HIGH 7.5 The Greenly Theme Addons plugin for WordPress is vulnerable to Local File Inclusion in versions up to 8.2. This makes it… wordfence
eefcc290-b7f7-4cf0-9ccc-db4c883d6426
< 33.0.16
HIGH 7.5 The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the … wordfence
eef040b0-445e-4717-905b-a8697c783483 HIGH 7.5 The JNews - Pay Writer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 11.0… wordfence
ee7e8d76-a461-4b0b-a312-c6ea4b8ac375 HIGH 7.5 The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File In… wordfence
ee7555a1-18dc-4b00-81f6-b26706cfb573
< 2.1.2
HIGH 7.5 The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table'… wordfence
ee57a2d6-4c27-48a1-b9b3-2e43054acbc4 HIGH 7.5 The Overworld - eSports and Gaming WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions… wordfence
ee3bbf20-43fd-4977-b0ba-b81e7a3810d0
< 4.4.2
HIGH 7.5 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensiti… wordfence
ee29caa0-6354-4700-9725-56b05c87a9ed HIGH 7.5 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to SQL Inje… wordfence
ee1ac4b5-0d2a-48ee-aad3-e27ccae5f217 HIGH 7.5 The Apptha Slider Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due … wordfence
ee0a762e-9159-4dab-a7be-9cbe332effb1
< 4.3.0
HIGH 7.5 WCAPF – WooCommerce Ajax Product Filter plugin is vulnerable to time-based SQL Injection via the 'post-author' paramet… wordfence
ed8636bf-229a-42a5-a19c-332679613dd2
< 1.9.8
HIGH 7.5 The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection i… wordfence
ed7da783-7c93-4847-9939-e88251930b70
< 3.2.5
HIGH 7.5 The MooWoodle – WordPress & Moodle LMS Integration Bridge plugin for WordPress is vulnerable to Sensitive Information … wordfence
ecfe024a-7bb2-45b1-849e-e6dd22666e56 HIGH 7.5 The DigiPass plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.3.0. This make… wordfence
ece722f3-b250-4ebf-9ce2-49e200b6873d HIGH 7.5 The Homey theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.5 due to insufficient… wordfence
ecd68933-e808-4816-b9d2-7491194f2347
< 3.0.6
HIGH 7.5 The Stream plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.0.5. This c… wordfence
← Prev 274 275 276 277 278 279 280 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top