πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 294 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a6d636a6-108c-40c5-b7c9-e3dee6bcaa0b
< 7.9.8
HIGH 7.5 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… wordfence
a65eb62d-847b-4f3a-848b-1290e3118c01
< 2.9.4
HIGH 7.5 The W3 Total Cache plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 2.9.… wordfence
a6505b91-ffca-4ec4-9fd5-a9a5adbd2b0e
< 1.3.3.8
HIGH 7.5 The MDTF plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.3.7 due to insufficie… wordfence
a646da21-9ccb-427b-9d06-7d295c8b5d18 HIGH 7.5 The WP Cloud plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.3. This make… wordfence
a644ac90-6cc4-495c-b880-4ebbc237bb57 HIGH 7.5 The Chocolate WP – Responsive Photography Theme for WordPress is vulnerable to Denial of Service and Abuse of Function… wordfence
a63b2091-1502-4d9f-98c4-ce9d2f923dc4
< 1.3.9
HIGH 7.5 The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object I… wordfence
a61d8d2a-742f-45f1-9146-f733b80ef195
< 1.1.5
HIGH 7.5 The VidShop – Shoppable Videos for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the … wordfence
a5da47f6-4cfe-480e-9472-bd5efc8bac71
< 3.0.2
HIGH 7.5 The Verowa Connect plugin for WordPress is vulnerable to SQL Injection via the 'search_string' parameter in all versions… wordfence
a5c7a019-953f-441e-b4d5-26f406f9853d
< 1.9
HIGH 7.5 The aDirectory – WordPress Directory Listing Plugin plugin for WordPress is vulnerable to PHP Object Injection in all … wordfence
a594ae11-3e8f-4cb6-b0c6-65f4e68d8b90 HIGH 7.5 The Stockholm Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.6. T… wordfence
a56874fe-cb2b-4024-a8db-9cf6c4d0012a
< 1.1.1
HIGH 7.5 The "Accio | Responsive Onepage Parallax Agency WordPress Theme" theme for WordPress is vulnerable to sensitive informat… wordfence
a52fb5f4-60ba-4077-95cd-e160a6d9a419
< 2.2.51
HIGH 7.5 The Post Grid plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on mul… wordfence
a482f6bb-5277-480b-8ec9-230dd4135f7c
< 1.10.12
HIGH 7.5 The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection … wordfence
a4766651-92a6-42c9-81bc-7ea25350f561
< 5.5.3
HIGH 7.5 The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
a39dccb6-b635-44af-b0e0-c3010b719773
< 1.3.4
HIGH 7.5 The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is… wordfence
a3808160-7291-4833-ade6-c60b7feef81a HIGH 7.5 The Cookiteer theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.8. This ma… wordfence
a37478a1-3e3e-4be0-aa96-ddafac0ff6c1
< 2.5
HIGH 7.5 The DejaVu Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This is d… wordfence
a36c9a7e-830d-4a92-a330-29279387b3be HIGH 7.5 The Riaxe Product Customizer plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter keys within… wordfence
a33af8c8-09a7-4f2d-9af3-c0c49a53a0e9 HIGH 7.5 The Boutique theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.3. This mak… wordfence
a2f9da0c-aff8-4b48-901c-1199c95afdeb
< 2.24120000-WP6.7.1
HIGH 7.5 The Click & Pledge Connect Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
a2e7a86b-8c5d-46d1-a51e-1368c6a880fd
< 4.7.11
HIGH 7.5 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to SQL Injection in versions up to,… wordfence
a2c4b389-4a43-4b6d-ad19-1d6c201580cc
< 1.24.0
HIGH 7.5 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
a241db4e-bd13-461f-9603-d3a28ba9e018 HIGH 7.5 The Crete Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.3 due to insuff… wordfence
a23bb496-06f0-4c4b-91db-c82b07824213
< 1.1.12
HIGH 7.5 The Premmerce Wishlist for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
a1f258b0-041e-4795-95a4-66431f8c84b2 HIGH 7.5 The WPAMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 44.0 (17-08-2023) due to… wordfence
← Prev 291 292 293 294 295 296 297 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top