🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 289 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bdcd9e73-ed37-4a5b-8dfa-6ef5cd6f47e2
< 5.0
HIGH 7.5 The Binary MLM Plan plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0 due to ins… wordfence
bd563af4-b97f-4746-a5e9-8dc5dfda272e HIGH 7.5 The Authentic theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.0.4. This… wordfence
bd3ee85a-324d-4991-bffc-db28ce374bbe
< 4.4.4
HIGH 7.5 The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to SQL Injection via … wordfence
bd087d06-5395-4dfd-a288-2c3271a62842
< 6.8.6
HIGH 7.5 WordPress Core is vulnerable to generic SQL Injection via the 'author__not_in' parameter in versions 6.8 - 7.0.1 due to … wordfence
bcf37d4e-e94a-4046-9949-c208e4e70197
< 2.7.7
HIGH 7.5 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions … wordfence
bcec59c3-dccc-4ddf-920c-76cc7b9685ac HIGH 7.5 The Coven Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 due to insuffic… wordfence
bc927a93-0cb2-4211-9f93-c0671039011e
< 6.15.10
HIGH 7.5 The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15… wordfence
bc860f44-c8ee-4b32-9702-7214e213790b HIGH 7.5 The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is… wordfence
bc84ca1f-747d-444e-b997-a79731b7ab51
< 8.2
HIGH 7.5 The Greenly theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.1. This makes … wordfence
bc74d1a3-5066-4b06-bfed-3b018e844126 HIGH 7.5 The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable… wordfence
bc406e8a-c4eb-45c3-a53c-37644e0dabfa
< 2.4.9
HIGH 7.5 The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() f… wordfence
bc07432e-0f3b-411d-9e38-61e4ed1a854b
< 1.3.15
HIGH 7.5 The Zota theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.14. This makes … wordfence
bbc7704b-8a28-4daf-8b83-bccc3783c43c
< 3.4.9
HIGH 7.5 The Recipe Card Blocks for Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access due to an inc… wordfence
bba4286b-acce-4dff-b809-dbd04d59702b
< 1.2.4
HIGH 7.5 search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes. wordfence
bb8bbfdb-c2a2-49b6-8a24-b788427d72b6 HIGH 7.5 The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - WordPress Plugin plugin for WordPress is vulnerab… wordfence
bb7e9ea4-c450-491f-b924-47ed4abec64a
< 1.6.6
HIGH 7.5 The User Activity Log plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ… wordfence
ba4da955-7651-42e5-aefa-72c70a7b1035
< 2.51.3
HIGH 7.5 The Strong Testimonials plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … wordfence
ba311865-be4b-4c56-a761-409582e981b5
< 4.3.2
HIGH 7.5 The Small Package Quotes – For Customers of FedEx plugin for WordPress is vulnerable to SQL Injection via the 'edit_id… wordfence
b9ffb0ac-84cf-4a82-b89b-05e43608db52
< 2.2.6
HIGH 7.5 The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications. wordfence
b9fa5c83-3701-4017-97c1-75f57e762c4e
< 2.2.261
HIGH 7.5 The Store Locator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.260 v… wordfence
b96f40fe-3ffa-4fc5-b51a-ff3771224bd5
< 1.31.3
HIGH 7.5 TheWP Job Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.31.2 vi… wordfence
b967eb98-69f8-41c5-a19a-9d20979accb0
< 5.4.2
HIGH 7.5 The Mayosis Core plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.4.1 v… wordfence
b939377b-276c-4612-9687-4e1b77e104cd
< 4.0.35
HIGH 7.5 The Classiera theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.34 due to insuffi… wordfence
b8f24fae-6a8b-4c67-a204-c085ae43552f
< 3.2.35
HIGH 7.5 The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpo… wordfence
b8dc0b5e-87b9-4831-a92a-bbf6eb1346e2
< 1.9.9
HIGH 7.5 The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure i… wordfence
← Prev 286 287 288 289 290 291 292 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top