πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 290 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b8d5bb6c-2021-4fc0-bede-8da1c3fb591a
< 5.5.2
HIGH 7.5 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Es… wordfence
b841531b-8728-4933-b3c4-d4e10cbdca79
< 2.8.3
HIGH 7.5 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the '… wordfence
b8085c94-5aa9-447a-bd79-41168d279040
< 7.3.0.7
HIGH 7.5 The Uncanny Automator Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7… wordfence
b7d46e8e-0f90-4379-98d0-13d0bd1f2e66
< 1.0.8
HIGH 7.5 The Majestic Support plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.7.… wordfence
b78a0c28-5121-4d07-b6ee-ada752688e56
< 3.5.8
HIGH 7.5 The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.… wordfence
b77e2abd-ad9c-4c0a-a467-c52767a6a97d HIGH 7.5 The WooCommerce Infinite Scroll plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includ… wordfence
b77b064d-ab8c-4e84-b5cc-efbdeefbf502
< 3.3.8
HIGH 7.5 The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' … wordfence
b76b3dd2-bf6b-4b18-9666-2ecbf628437c
< 4.8
HIGH 7.5 The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/u… wordfence
b73bbe27-a162-4518-b09a-c69f82150994 HIGH 7.5 The CWD – Stealth Links plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 due … wordfence
b6c3daf6-2225-4929-8e76-169d680118ba
< 4.8.0
HIGH 7.5 This plugin Affiliate For WooCommerce premium for WordPress is vulnerable to Insecure Direct Object Reference in version… wordfence
b6a99135-c12e-435c-bd81-ddd3414d178a
< 12.0.3
HIGH 7.5 The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Local File Inclusion in versions up to 12.0.3. This m… wordfence
b68daf12-f84b-4a77-9376-7a4c3ff16c72
< 1.2.6
HIGH 7.5 The GeekyBot β€” AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content plugin for WordPress is vulnerable to S… wordfence
b63bc2b6-1abc-4cfa-a7e5-3995640f66a7
< 2.38.9
HIGH 7.5 The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to… wordfence
b612267c-a125-4153-9de7-bb12a7646021
< 4.9.2
HIGH 7.5 The WP Maps plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'location_id' parameter in all … wordfence
b606c7eb-39ce-40a0-b642-6f240f7c8c42
< 1.1.8
HIGH 7.5 The ThemeMakers Almera Responsive Portfolio Site Template component through 2015-05-15 for WordPress allows remote attac… wordfence
b605027a-4d65-4bfe-9daa-5b2f88811bc7
< 3.0
HIGH 7.5 The Aspose Importer & Exporter (Discontinued) plugin for WordPress is vulnerable to arbitrary file download in versions … wordfence
b5ff1f14-c31e-450f-88d0-0a2bbe637d29
< 8.8.3
HIGH 7.5 The Directorist: AI-Powered Business Directory, Listings & Classified Ads plugin for WordPress is vulnerable to PHP Obje… wordfence
b5f6d2a2-ad3e-4afc-b6fd-745881d85b6b
< 7.3.2
HIGH 7.5 The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory… wordfence
b5e0b875-ba8c-438f-b2b1-6c713ef604e5
< 4.4
HIGH 7.5 WordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach… wordfence
b594d0e9-d805-48b9-bfd4-4cc77dd3a70e
< 1.1.13
HIGH 7.5 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to… wordfence
b56a5ff2-10cb-4eee-9409-7f8a22d00358
< 2.0.1
HIGH 7.5 The WP Hotel Booking plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on set… wordfence
b4ca985e-cae1-4e26-ad2d-413724cfd45d
< 1.6.5
HIGH 7.5 The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.4 via th… wordfence
b40c89e5-d291-45b7-b84a-6fee75e5b7eb HIGH 7.5 The Ajax Store Locator plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1… wordfence
b3b658f0-b9d8-4b7f-8d40-39ce185ef797
< 2.4.0
HIGH 7.5 The JobWP – Job Board, Job Listing, Career Page and Recruitment Plugin plugin for WordPress is vulnerable to SQL Injec… wordfence
b3a058d6-ca9e-4241-b6dd-307efa7689ab HIGH 7.5 The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable t… wordfence
← Prev 287 288 289 290 291 292 293 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top