πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 280 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e44a73d3-9e0b-4fa7-ab1f-c6751e541559 HIGH 7.5 The Accordion FAQ plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.1. Th… wordfence
e416f70f-4f62-4abf-990e-acef51c603c0 HIGH 7.5 The Smart Notification plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.3 due to… wordfence
e413fe96-ca6d-49b6-9fb8-59eb9a63e559
< 27.8
HIGH 7.5 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to SQL Injection in v… wordfence
e3e5bb98-2652-499a-b8cd-4ebfe1c1d890
< 2.9.2
HIGH 7.5 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
e37cabad-c41c-4fba-b01d-a5eb5c7d5254
< 3.8.8.2
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.8.1 due to insuf… wordfence
e3147a94-056a-4454-8815-44c0b9d1de81
< 1.3.0
HIGH 7.5 The decode-uri-component is vulnerable to Denial of Service due to improper input validation in versions up to, and incl… wordfence
e2cbb4b5-cf6e-4cd1-ba36-0fe746b68514
< 7.0.0
HIGH 7.5 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection in versions … wordfence
e271effa-2c40-4635-ad6b-ca82b4742567
< 3.4.2
HIGH 7.5 The Poll Maker WordPress plugin before 3.4.2 allows unauthenticated users to perform SQL injection via the ays_finish_po… wordfence
e2510cee-d9d7-4b30-bf94-254a1dec9bd8
< 3.4
HIGH 7.5 The Awake Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 3.3. This is du… wordfence
e2422f54-244c-4e69-8174-ee462a861e98
< 2.5
HIGH 7.5 The Modular Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This is … wordfence
e231c77b-01f8-408f-82ae-4efb6fcc4184
< 1.2.3
HIGH 7.5 The Relevanssi Light plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.2 due to … wordfence
e1f636fe-fea7-4252-8f95-cd8f17f57fc4
< 9.1.11.001
HIGH 7.5 The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to 9.1.11.001 due to insuffic… wordfence
e1bdda78-e0e3-4d0b-81b8-9c018f445225
< 4.1.1
HIGH 7.5 The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit. wordfence
e1b3d106-445b-455f-b3d7-3318f5c35191 HIGH 7.5 The Aqua theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.1.2. This makes i… wordfence
e17b3cbe-3c87-4a40-8047-33dba0154f97
< 8.4
HIGH 7.5 The LabtechCO theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.3. This make… wordfence
e1334ab5-515c-4bce-b437-ee68a3315b78
< 25.09000000-WP6.8.2-JB5.12.0
HIGH 7.5 The WordPress-WPJobBoard plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 25.07… wordfence
e11fb463-6d2a-40eb-8ca5-4a54025991f9
< 1.5.3
HIGH 7.5 The Turitor theme for WordPress is vulnerable to Local File Inclusion in versions up to 1.5.3. This makes it possible fo… wordfence
e10873f0-135e-4229-8b7a-6c1d69599c1d
< 3.8.6
HIGH 7.5 The SMS Alert Order Notifications plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
e0fdeb83-78c3-4b29-809c-662bd2a2bb51
< 1.1
HIGH 7.5 The Simple Download Button Shortcode plugin for WordPress is vulnerable to Arbitrary File Downloads in version 1.0. This… wordfence
e0e67883-1f6c-4454-8d51-96fa2d1366d7
< 1.3.6
HIGH 7.5 The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' paramete… wordfence
e0d6c8dc-d32b-4ac8-8b0d-6d7ecbac86b5
< 2.3.1
HIGH 7.5 The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the … wordfence
e0cac17e-3dfa-4148-b087-3f29f053b568 HIGH 7.5 The Werkstatt - Creative Portfolio WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions… wordfence
e0a3910b-adc4-4633-a6a1-32ba50894be4
< 5.1.3
HIGH 7.5 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to product price manipulation in all versions up t… wordfence
e044c51c-40e0-4d33-8921-616d59e0e0d8 HIGH 7.5 The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via th… wordfence
dfa34dd5-5c80-40d3-8bb0-83c13cbab7f3
< 1.7.5
HIGH 7.5 The Learts Addons plugin for WordPress is vulnerable to SQL Injection in versions up to 1.7.5 due to insufficient escapi… wordfence
← Prev 277 278 279 280 281 282 283 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top