πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 284 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d0abc8f9-7b6f-443d-a17f-8da034359c52
< 3.7.4
HIGH 7.5 The Polylang plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.7.3 via … wordfence
d042649e-abdc-4c9d-a94a-f0cea31f4e91 HIGH 7.5 The Entrepreneur - Booking for Small Businesses WordPress theme for WordPress is vulnerable to PHP Object Injection in v… wordfence
d0215e53-0394-4845-93e4-463cd5642fb3
< 2.0.1.8.2
HIGH 7.5 The Modal Survey Plugin for WordPress is vulnerable to Arbitrary Survey Update, Deletion and Creation in versions before… wordfence
d0029883-79e0-4dd3-85a3-6bbf30452267
< 1.5.43
HIGH 7.5 The Page Builder: Live Composer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and in… wordfence
CVE-2026-6403
< 1.3.3.
HIGH 7.5 The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is… nvd
CVE-2026-4020 HIGH 7.5 The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… nvd
CVE-2026-2471 HIGH 7.5 The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1… nvd
CVE-2026-2428 HIGH 7.5 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in… nvd
CVE-2026-2416 HIGH 7.5 The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and i… nvd
CVE-2026-2232 HIGH 7.5 The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v… nvd
CVE-2026-2020 HIGH 7.5 The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1… nvd
CVE-2026-1581 HIGH 7.5 The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version… nvd
CVE-2026-1557 HIGH 7.5 The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 … nvd
CVE-2025-12707 HIGH 7.5 The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version… nvd
CVE-2025-11754
< 4.1.3
HIGH 7.5 The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… nvd
cffeac2c-8ca3-44f7-b54c-3c23b7a849a3
< 6.50
HIGH 7.5 The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-c… wordfence
cfea0427-78dc-4151-864a-63b6761fc294
< 3.9.1
HIGH 7.5 The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation … wordfence
cfa487fb-c014-47f1-9537-73881ede30b4 HIGH 7.5 The WP JobHunt plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.1. Th… wordfence
cfa375a8-ab07-45da-bc77-1e7edc996e05
< 8.41
HIGH 7.5 The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.4… wordfence
cf91d75e-cef4-4154-aa16-6ca96db9c5bb
< 3.5.2
HIGH 7.5 The Friends plugin for WordPress is vulnerable to PHP Object Injection in version 3.5.1 via deserialization of untrusted… wordfence
cf24ee30-7d9f-47c3-bc2a-1c3c92971ba8
< 19.1.5.1
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to … wordfence
cf245445-27fd-4678-b95d-fb0b1c2aff7b HIGH 7.5 The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.13… wordfence
cf11be7a-0b31-46ce-82ce-5a42898a8a10 HIGH 7.5 The Log WP_Mail WordPress plugin through 0.1 saves sent email in a publicly accessible directory using predictable filen… wordfence
cefb979e-2b5b-4820-a350-ee106131f0f9
< 3.1.1
HIGH 7.5 The make_clickable function in wp-includes/formatting.php in WordPress before 3.1.1 does not properly check URLs before … wordfence
ceef080c-3d3b-494d-8cfa-fe9724b9207f
< 2.0
HIGH 7.5 The SecuPress Free and SecuPress Pro plugins for WordPress is vulnerable to unauthenticated arbitrary IP bans in version… wordfence
← Prev 281 282 283 284 285 286 287 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top