πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 282 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
db0feb49-35c3-4bb1-9ec9-2b5bdbb28189
< 1.3.2.1
HIGH 7.5 The "Blessing Premium Responsive WordPress Theme" theme for WordPress is vulnerable to sensitive information disclosure … wordfence
da533426-16bf-4eef-b113-c41b256952e6
< 7.4
HIGH 7.5 The wpDataTables (Premium) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.6 d… wordfence
da13130f-9483-4e84-b652-faa248bf1047
< 14
HIGH 7.5 The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Path Trave… wordfence
da0c91e5-d9dc-413a-95f6-9e2fc6746ec0
< 3.1.9.1
HIGH 7.5 The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts… wordfence
d9ff985d-1bb3-4976-9385-0dc48d94b542 HIGH 7.5 The CTL Behance Importer Lite plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, … wordfence
d9ee66e8-e601-405a-88b8-4805d425dd75 HIGH 7.5 The Allmart plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 due to insufficien… wordfence
d9d7dc61-1e28-426b-a9da-3a36134e7821 HIGH 7.5 The SCv1 Theme for WordPress is vulnerable to Arbitrary File Download in all known versions. This is due to insufficient… wordfence
d99614e6-4543-4594-9a46-71ecc986be45
< 1.0.5
HIGH 7.5 The Wishlist and Compare for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap… wordfence
d928b738-d8ed-447a-b604-e71e90d4d23d
< 2.8.4
HIGH 7.5 wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the … wordfence
d8ec7d25-1574-416c-b5fd-3a71b1cc09d2
< 6.4.22
HIGH 7.5 The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-base… wordfence
d8d17ee3-73b3-4f58-8d08-14bbf2d9d9d8
< 0.6.67
HIGH 7.5 An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote a… wordfence
d889257e-b7a6-4704-876d-4b49f92a0849
< 3.4.3
HIGH 7.5 The NGG Smart Image Search plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.1 d… wordfence
d874a041-1cd4-4ca1-85bd-4050630d8502 HIGH 7.5 The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm(… wordfence
d83e0495-bfa6-4034-88db-7e4182977a94
< 8.0.7
HIGH 7.5 The LifterLMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.6 due to insuffi… wordfence
d830b73c-0666-4632-8001-fe2c467a37a0
< 7.6.3
HIGH 7.5 The Salon booking system Free and Pro WordPress plugins before 7.6.3 do not have proper authorisation in some of its end… wordfence
d7c72de0-b9d0-47aa-8836-faf7ad8f9746 HIGH 7.5 The Wr Age Verification plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.0 … wordfence
d7c72608-a348-4ae5-ae85-d87955bfad32
< 2.9.2
HIGH 7.5 The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Path Traversal in all… wordfence
d791cd67-03a8-4408-8ca7-7b1ea613e660
< 1.4.4
HIGH 7.5 Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugi… wordfence
d6d69ffd-bb39-4fcc-9444-27d1a901e7c9
< 2.14.6
HIGH 7.5 The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is vulnerable to Sensitive Infor… wordfence
d6a7f882-4582-4b08-9597-329d140ad782
< 1.2.1
HIGH 7.5 The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
d684efcd-74fa-4b0c-b8dd-9674a2748fc3
< 6.8.2
HIGH 7.5 Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with … wordfence
d6203331-4fe0-4eba-bbe7-52a55549fd25
< 2.0.7.5
HIGH 7.5 The Spice Blocks plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.7.4. Thi… wordfence
d6077842-cc17-48c6-be3b-9149e4b87235 HIGH 7.5 The SW Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.18. This ma… wordfence
d5e0d192-17ee-42bd-9368-c8449d8e0d08
< 2.2.11
HIGH 7.5 The LTL Freight Quotes – SAIA Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'drops… wordfence
d556e65f-da13-4880-84d6-0b881be7c407
< 6.4.4
HIGH 7.5 The Fancy Product Designer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.4.3 d… wordfence
← Prev 279 280 281 282 283 284 285 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top