πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 283 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d52d3291-838a-4b23-b969-8c6273faec1e HIGH 7.5 The Product Filter For WooCommerce Product plugin for WordPress is vulnerable to SQL Injection via the `datastring` para… wordfence
d50eb008-6506-4f5f-b426-49fc61ecd876 HIGH 7.5 The Vivagh theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4 via deseriali… wordfence
d4d5b553-141c-4d3e-b435-41753e3580df HIGH 7.5 The Membership by Supsystic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.7 … wordfence
d4b071a5-66b5-406d-a14f-5ae22ea4b8eb
< 2.7.12
HIGH 7.5 The The7 Elements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 2.7.12. T… wordfence
d4a21d0d-f455-4901-a04b-13c891cf8f75
< 2.5.3
HIGH 7.5 The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up … wordfence
d49bd587-26fc-48fb-86aa-a043a5938d43
< 1.0.7
HIGH 7.5 The CP Image Store with Slideshow plugin for WordPress is vulnerable to an Arbitrary File Download in versions up to, an… wordfence
d49aee72-9854-4f72-993b-967b9d6891b1 HIGH 7.5 The Stockholm theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 9.14.1. This m… wordfence
d41a8c39-8b06-45b2-afe4-8c695faf8cb8 HIGH 7.5 The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and i… wordfence
d3c997cd-37b4-4b9c-b99e-397be484aa36
< 6.0.2
HIGH 7.5 The Soisy Pagamento Rateale plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabilit… wordfence
d3999c59-57a9-410c-a550-7d198bdb25ea
< 1.33.2
HIGH 7.5 The Hubbub Lite – Fast, Reliable Social Sharing Buttons plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
d3849db8-5c9e-410e-be53-c9ab76162630 HIGH 7.5 The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to,… wordfence
d36856c1-5b61-403d-816e-7efa8ca4d41a
< 3.8.10
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8.9.1 via d… wordfence
d3028e36-33e5-43ae-a752-2bcc8ad13a10
< 2.0.9
HIGH 7.5 The Miraculous theme for WordPress is vulnerable to SQL Injection in versions up to 2.0.9 due to insufficient escaping o… wordfence
d2de0442-2a2b-402c-abb9-5f49e172d0c3
< 4.4.4
HIGH 7.5 The Splash - Sport Club WordPress Theme for Basketball, Football, Hockey theme for WordPress is vulnerable to Local File… wordfence
d2ad9184-5047-4037-9791-23dbf93d794b HIGH 7.5 The Omnipress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.7. This m… wordfence
d2a9a2fd-5667-4033-a273-f4f5660cb27e
< 1.22.16
HIGH 7.5 PHP Object injection vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote authenticated… wordfence
d23d2cdf-206e-4714-9753-198519ba737b
< 7.8.1
HIGH 7.5 The WP Travel plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
d1f5e31b-ef43-4fee-840f-873089584a97 HIGH 7.5 The Prowess theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3. This makes … wordfence
d1b3a6d3-94d6-47f1-a3c8-5eb33b1ad392
< 4.2.3
HIGH 7.5 The Custom API for WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.2.2 due to… wordfence
d1772e79-85c7-4a8e-a5d8-8d73013e6de3 HIGH 7.5 The Candidate Application Form plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and incl… wordfence
d16cb094-d1e7-48ca-8baa-8171d02d3ef5 HIGH 7.5 The Subscribe To Unlock plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1… wordfence
d16c13bf-7cab-4870-898e-971b5c4d7b7b
< 4.6.5.1
HIGH 7.5 The SpeakOut! Email Petitions plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.6.… wordfence
d1533e9a-dcb9-4fbb-a1a7-7f4dafd3a1c8
< 2.9.8
HIGH 7.5 The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in … wordfence
d144aab0-a55a-4889-86d9-40534cbec31c
< 2.2.2
HIGH 7.5 The Mikado Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6. This m… wordfence
d12520a0-0fac-46f0-b58f-62bc2f1f86c5
< 5.0.19
HIGH 7.5 The Church Admin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 5.0.18 due to… wordfence
← Prev 280 281 282 283 284 285 286 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top