πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 278 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ecd28218-6b43-4f61-bcca-117c353e79be
< 3.21
HIGH 7.5 The TicketBAI Facturas para WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… wordfence
ecc34552-c9b0-455f-b1c7-b31cc847cb22
< 2.4.9
HIGH 7.5 The WP Job Portal plugin for WordPress is vulnerable to SQL Injection via the 'radius' parameter in all versions up to, … wordfence
ec6a9d6b-8440-40e8-8281-78a6299654de HIGH 7.5 The WhatsCart - Whatsapp Abandoned Cart Recovery, Order Notifications, Chat Box, OTP for WooCommerce plugin for WordPres… wordfence
ec1de1f5-6530-4cca-8b9e-3cb7e01e3cf2 HIGH 7.5 The Qode Tours plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.3.1 due to insu… wordfence
ec002a5a-1965-4828-8a0a-19941af98e2d
< 1.3.2
HIGH 7.5 All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users,… wordfence
ebd3b70e-a06a-4dcc-a6af-dbe64fd57c82
< 2.0.8
HIGH 7.5 The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 … wordfence
ebc8d724-3936-42d8-8850-bc330c5221dc
< 6.5.2
HIGH 7.5 The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthoriz… wordfence
ebb6afd7-6bc4-4c8a-a645-04f64d5adff4
< 1.9.1
HIGH 7.5 The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing ca… wordfence
ebb4bc5a-9469-4733-acf3-d2dda5edb7af
< 6.29
HIGH 7.5 The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and includi… wordfence
ebaec880-0d1c-4725-a746-530f48821279
< 1.3.7.2
HIGH 7.5 The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to blind SQL Injection via… wordfence
eb5749c1-b092-4fb9-8c04-f750bc5ae5e0
< 5.1.0
HIGH 7.5 The Software Issue Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.0 d… wordfence
eb51f6c6-8685-4b09-8b5f-78884d01bbe4 HIGH 7.5 The NewsPlus Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2… wordfence
eb0bbf47-a8c7-489d-a758-7b5771c2fcbd HIGH 7.5 The Export User Data plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.6 … wordfence
eb064156-f54b-4401-9d4f-29f0952deb24
< 5.6
HIGH 7.5 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
eae1ee2c-1be5-4be5-8873-f99c8fdd41ba HIGH 7.5 The lote27 theme for WordPress is vulnerable to Arbitrary File Download via the 'download' parameter found in the 'downl… wordfence
eac6481a-8605-45e4-b5cf-fa8d79fde63a
< 5.5.0
HIGH 7.5 The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to SQL Injec… wordfence
ea54436c-b623-4049-af19-9995c312476e
< 7.3.2
HIGH 7.5 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… wordfence
e9dd26b9-433c-4560-b507-69d0245ba789
< 3.1.0
HIGH 7.5 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is… wordfence
e9b6fe22-330a-4c24-9fdf-16f35516fb2a HIGH 7.5 The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via… wordfence
e99d4ec2-692a-43aa-8273-ec64d27a8baa
< 3.6.34
HIGH 7.5 The My auctions allegro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6… wordfence
e96cfa07-2640-4d5e-8057-28e42f0425b0 HIGH 7.5 The Woocommerce Category Banner Management plugin for WordPress is vulnerable to PHP Object Injection in versions up to,… wordfence
e9612b5c-ed04-41f6-9936-c850b0ef04d0
< 1.3.16
HIGH 7.5 The Diza theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.15. This makes … wordfence
e95ecb22-7946-4830-95a4-f145f0f99d68
< 1.3.16
HIGH 7.5 The Invite Anyone plugin before 1.3.16 for WordPress has incorrect access control for email-based invitations. wordfence
e92cc06d-006f-4bba-a4ef-b23d80c00085
< 2.10.0
HIGH 7.5 The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4… wordfence
e91b8082-e1c7-4989-82db-20e255b52854
< 10.30.26
HIGH 7.5 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, a… wordfence
← Prev 275 276 277 278 279 280 281 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top