πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 291 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b2ad5698-4299-48a4-bcc1-5f4436dfab27 HIGH 7.5 The Dynamically Display Posts plugin for WordPress is vulnerable to SQL Injection via the 'tax_query' parameter in all v… wordfence
b2a8c307-2430-4ea9-afe0-e5e758eabdd1
< 9.1.10
HIGH 7.5 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Refer… wordfence
b2971aa0-8287-4142-bd04-7aec1ed92e7b
< 2.0.10
HIGH 7.5 The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, … wordfence
b288386c-709c-49a6-9b46-28bf46c3c303
< 7.0.0
HIGH 7.5 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to SQL Injection via the 'cod… wordfence
b251cc43-155a-4f73-9819-4805de3686bc HIGH 7.5 The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to SQL Injection in versions … wordfence
b24625d7-2a38-451b-ab79-a1d9c5b8822a
< 19.1.5.1
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to … wordfence
b20fa367-a12f-402a-a74a-2bb5fe090036
< 7.3.1
HIGH 7.5 The plugin Directorist for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 7.3.0. T… wordfence
b1e9c2c9-b306-44a5-9919-9b5f13fa3fcc
< 1.5.6
HIGH 7.5 The ModelTheme Addons for WPBakery and Elementor plugin for WordPress is vulnerable to PHP Object Injection in versions … wordfence
b19794de-b623-4017-bd91-73986383c58b
< 1.3.7
HIGH 7.5 The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the… wordfence
b1695816-0f54-4095-8884-bc9856b4dac1
< 1.1.8
HIGH 7.5 The ThemeMakers Almera Responsive Portfolio theme through 2015-05-15 for WordPress allows remote attackers to obtain sen… wordfence
b157356c-a4be-48d6-8c58-ad1a9c96cda3
< 1.1.0
HIGH 7.5 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin f… wordfence
b0f3cdce-e239-4c2f-83e3-e8d0b528d39e
< 3.3.5
HIGH 7.5 The LTL Freight Quotes – R+L Carriers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' an… wordfence
b0bce89d-6b1d-4e7f-bd7f-6143a3b622de
< 2.0.29
HIGH 7.5 The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for cour… wordfence
b0ae27c4-0381-4622-90e8-f4fee29767a3
< 5.0.2
HIGH 7.5 inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /w… wordfence
b073edd0-3f40-423e-976e-996b29caf66e
< 6.0.7
HIGH 7.5 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file d… wordfence
b06d4731-111d-43b5-a0ca-afc877c37001 HIGH 7.5 The Goodlayers Hostel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.2 due to… wordfence
b0696cbe-70e0-402d-bcfd-40907a973785
< 1.4.8
HIGH 7.5 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'hide_fields' and the 'attr_search' par… wordfence
afcccbd2-8f84-4d46-a8c4-8d83266d51f9
< 1.5.2
HIGH 7.5 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.1 due to … wordfence
afbd5080-8a25-4230-8836-20ffeca3f39d
< 2.3.3
HIGH 7.5 The WP Job Portal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.2 due to ins… wordfence
afa90746-2932-44fe-baf0-c251b5a063f3
< 3.7.2
HIGH 7.5 The Support for CitiLights - Real Estate WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in ve… wordfence
af871d3d-2dc0-49c3-a697-2635e4aa8f70
< 2.6.7
HIGH 7.5 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
af343f4d-8e0f-463f-bc5f-e48c6d6d11f7 HIGH 7.5 The Tonda theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5. This makes it… wordfence
af06ed29-00a0-4741-be69-44554156615b HIGH 7.5 The Post Ideas plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2 due to insufficie… wordfence
aef584bd-60a5-4bf2-b8d3-58e3b45e785e
< 1.8.3
HIGH 7.5 The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
aee59a8f-7f21-4572-b146-ab1b6350ddb1
< 1.4
HIGH 7.5 The WP Hide & Security Enhancer plugin for WordPress is vulnerable to Arbitrary File Download in versions before 1.4. Th… wordfence
← Prev 288 289 290 291 292 293 294 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top