🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 279 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e8f73f1e-8f0a-4c4c-aca2-c9ae9bc4f63d
< 3.5.2
HIGH 7.5 An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web… wordfence
e8efc5cf-3497-4426-a8a5-740783a7c2c9
< 1.0.4.1
HIGH 7.5 The Acumbamail plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0.4 via… wordfence
e8ed5d5d-86b0-40ac-a093-31392dea13a2
< 2.8.9
HIGH 7.5 The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information… wordfence
e8ec1bc6-cca5-4b0a-944c-47de0fa46ec9
< 1.2.5
HIGH 7.5 The Product Table For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and … wordfence
e8e5f9f1-af2b-4a4f-ae5c-145252cd0ed5 HIGH 7.5 The Post Slides plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.1. … wordfence
e8a7d3b1-ceb7-4ff9-84e4-bc58a597b2cf
< 1.4.1
HIGH 7.5 Multiple directory traversal vulnerabilities in the BackWPup plugin before 1.4.1 for WordPress allow remote attackers to… wordfence
e85ff3b3-de41-4ac4-b825-b3238725ca44
< 5.0.4
HIGH 7.5 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to unauth… wordfence
e80a74f7-7983-4d66-a038-3c57c5d94ea1
< 1.2.9
HIGH 7.5 The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includi… wordfence
e7ba37ac-908f-4766-a208-d28191f8296d
< 2.2.8
HIGH 7.5 The Bookory theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.7. This make… wordfence
e78c539c-5b72-4043-aa5a-6234913364ac
< 1.0.5
HIGH 7.5 An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an at… wordfence
e739e7d3-756a-4c93-9ca7-f7b9f9657033
< 23.6
HIGH 7.5 The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability ch… wordfence
e6df591d-110d-4b0f-a651-2efdb0f1e1f7
< 3.15.0.2
HIGH 7.5 The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to SQL Injection in version… wordfence
e681aa8e-522e-4092-aa1f-8ada3097c8d6
< 3.12.22
HIGH 7.5 The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in… wordfence
e6504623-5356-4eba-97e7-c6dc1245e9c1
< 1.1.0
HIGH 7.5 The GIFT4U – Gift Cards All in One for Woo plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
e64bb998-277c-4e83-892f-dc9cd74a11e6
< 3.1.6
HIGH 7.5 The Quotes llama plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.5 due to insu… wordfence
e6139543-81e3-480a-93a4-1d87b3f3f51e HIGH 7.5 The Latest Registered Users plugin for WordPress is vulnerable to unauthorized user data export in all versions up to, a… wordfence
e5da24fa-fc7c-406b-896d-8cb8cc107cff
< 2.2.1
HIGH 7.5 The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users… wordfence
e5c62e54-da06-4b44-ba70-63065e664b0d
< 6.1.18
HIGH 7.5 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in… wordfence
e55ff883-1796-4282-b005-26dfd154b11f
< 4.2.1
HIGH 7.5 The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to arb… wordfence
e54d94e5-819b-47f1-86d9-71e3873f70bc HIGH 7.5 The Anona theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.0 via deserializ… wordfence
e54d79d5-38c2-49ba-9bb8-e57dacf165f5
< 1.13
HIGH 7.5 The Facturante plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.11 due to insuffi… wordfence
e52289fe-9a38-4ebf-b24a-034768fa56b7
< 67.8.0
HIGH 7.5 The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to SQL Injection via several parameters i… wordfence
e4c58479-2924-4b56-9c27-3bdf4be388a3
< 3.4.2
HIGH 7.5 Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download. wordfence
e492029d-6613-4881-b986-9fe14cb2cf74
< 1.5.3
HIGH 7.5 The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all v… wordfence
e47509e8-d2b9-4f23-b02c-434762ddba95 HIGH 7.5 The EduBlink Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7. Th… wordfence
← Prev 276 277 278 279 280 281 282 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top