πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 293 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aac3ef07-f9b1-4f92-8d0a-8597c4eb8d94
< 4.1.4
HIGH 7.5 The StoreContrl Woocommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi… wordfence
aab42989-b928-492f-a610-d2a5546751e0
< 2.5
HIGH 7.5 The Persuasion Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This … wordfence
aaad8b81-d08b-4346-9167-defb6bc01ead
< 3.8
HIGH 7.5 The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.7. This… wordfence
aa4244d3-a611-416d-8159-2f6a8cf61b30
< 3.05.5
HIGH 7.5 The Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition plugin fo… wordfence
aa1ed81c-04cb-4ccd-8c30-b1d943730909
< 3.7.9
HIGH 7.5 The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via th… wordfence
aa157c80-447f-4406-9e49-9cc6208b7b19
< 1.12.1
HIGH 7.5 The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and includ… wordfence
aa13c293-0530-478c-acfc-f7d69edae318
< 1.0.5
HIGH 7.5 ansi-regex is vulnerable to Inefficient Regular Expression Complexity. Some WordPress plugins and themes use this depend… wordfence
a9f17d4a-62b2-433e-bbba-551081a72fcb
< 1.0.9.4
HIGH 7.5 The Goya Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to 1.0.9.4. This makes it possib… wordfence
a9d7aa30-421f-4d25-8e01-460069ef857d
< 2.14.19
HIGH 7.5 The Modula Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in ve… wordfence
a9b6f7a3-83eb-4352-9db6-ab4b03241702
< 3.4.2
HIGH 7.5 The LTL Freight Quotes – For Customers of FedEx Freight plugin for WordPress is vulnerable to SQL Injection via the 'e… wordfence
a9743351-9f28-49bf-8b08-85ffbdcfa5f0
< 3.5.2
HIGH 7.5 The Co-Authors Plus plugin for WordPress is vulnerable to sensitive information disclosure via the /wp/v2/coauthors REST… wordfence
a96f99ba-982b-4dac-a9ce-e75af85cd5d5
< 6.0.7
HIGH 7.5 The Course Booking System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.0.6 du… wordfence
a96d0979-a40b-4ced-872f-c5a8116471a1 HIGH 7.5 The Visual Art | Gallery WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to, an… wordfence
a963cd9b-9f8f-4bd2-92cd-74c5e85e1d96
< 3.4.8
HIGH 7.5 The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
a95f5aa7-6ff1-4ebf-9b5a-17ad784eefe7
< 1.0.7
HIGH 7.5 The Fable Extra plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.6 due to insuf… wordfence
a94708ec-ab09-4604-80ec-5bd85799c6e4
< 2.2.3
HIGH 7.5 An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin in versions up to, and inc… wordfence
a9057fc2-f346-47e5-964a-f3c5b1653c03
< 4.21.2
HIGH 7.5 The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.… wordfence
a9000c52-fdd7-43e2-ae6a-9f127c4a9fcd
< 4.7.52
HIGH 7.5 The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on sev… wordfence
a8dc0712-f78e-46c5-a0d1-2db752498d54
< 3.9.9
HIGH 7.5 The Eventer plugin for WordPress is vulnerable to SQL Injection via the 'event' parameter in the 'eventer_get_attendees'… wordfence
a84da684-17b3-43d7-b8dd-2570ee44851e
< 3.15.5
HIGH 7.5 The Avada (Fusion) Builder plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … wordfence
a83e7d8b-a93a-4347-bb59-de1e2fd954a5
< 2.8.154
HIGH 7.5 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… wordfence
a78998da-1cb1-4991-95a8-a551bde04064 HIGH 7.5 The ZoomSounds - WordPress Wave Audio Player with Playlist plugin for WordPress is vulnerable to Arbitrary File Read in … wordfence
a770204d-d89f-4c3e-a667-06ec1d96dbf7 HIGH 7.5 The Medinik Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.6 due to insu… wordfence
a7689a95-7f63-46e1-b5fd-4279be66e0f0
< 5.0.9
HIGH 7.5 The Event Booking Manager for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up … wordfence
a73f7812-771d-4d9f-9a7c-e4e01ec05023
< 7.11.2
HIGH 7.5 The Avada theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_i… wordfence
← Prev 290 291 292 293 294 295 296 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top