πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 295 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a1d07e86-e870-4978-a240-4c3e8050c5d6
< 2.5.2
HIGH 7.5 The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
a1708d6e-14f5-418f-81eb-f9269159b5b1
< 5.5.23
HIGH 7.5 The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via… wordfence
a161bd23-0b82-49ef-b3cc-a117823ec8a7
< 1.6.5
HIGH 7.5 The Gmedia Photo Gallery plugin for WordPress is vulnerable to Denial of Service in versions up to, and including, 1.6.4… wordfence
a1373d87-cc75-4f53-8293-eebc5a0ace95
< 9.2.01.001
HIGH 7.5 The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.13.005… wordfence
a10dc207-eb41-407e-a85c-ae5ea4c5d972
< 3.0.11
HIGH 7.5 The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.10 … wordfence
a102478c-c704-47d4-8b2b-492f75ec38b9
< 0.8
HIGH 7.5 The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets… wordfence
a0e54185-a917-49cd-b99d-5b773a7ed06a
< 5.6.2
HIGH 7.5 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, a… wordfence
a0099f55-651c-4997-bf6d-97125c4260e1
< 1.1.1
HIGH 7.5 The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remot… wordfence
9fda8379-0bed-4eae-b3e3-06e35c541323 HIGH 7.5 The Emphires theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9. This makes… wordfence
9fbb4f9a-4c68-4ddb-8e49-9629114b11ec
< 3.3.8
HIGH 7.5 The LTL Freight Quotes – ABF Freight Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and… wordfence
9fad85ef-5ab7-47d9-b4a6-9e1a1f1ff3bb
< 2.1.3
HIGH 7.5 The Koko Analytics plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.2 due to in… wordfence
9f86bb77-7194-4a8d-b862-6f04d850017b
< 1.7.2
HIGH 7.5 The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… wordfence
9f73d5b3-8d7c-43d1-84e4-f8a3976eab8f
< 1.3.1
HIGH 7.5 The Popup | Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data… wordfence
9ee14f5f-c558-43d3-8aae-6ea50933759a
< 3.7.24
HIGH 7.5 The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner… wordfence
9eacc280-c254-487b-9ec7-c1e8cbb5bd4d HIGH 7.5 The Aalto theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8. This makes it… wordfence
9e7e3763-4606-4fc4-aa0f-b67e6087bdc2
< 2.0.7
HIGH 7.5 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV… wordfence
9e6b58b5-6c47-4a83-84be-6c000a218446 HIGH 7.5 The Ajax WooSearch plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0.0 due t… wordfence
9e4a2ba2-16e3-473e-a5fc-6a6437eae55e
< 8.14.1
HIGH 7.5 The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.14.0 due to insuffici… wordfence
9e4a0d10-c798-4bff-9cfe-c9bc6201950e HIGH 7.5 The Struktur - Creative Agency WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up … wordfence
9e3a118f-4321-4579-a986-05ce077dc6b9
< 1.9.5
HIGH 7.5 The Everest Forms (Pro) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path vali… wordfence
9e164966-457f-45a0-acba-4cf12bf08352
< 4.09.86
HIGH 7.5 The WebinarIgnition plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 4.09.86 due to… wordfence
9df75a5c-b70b-452e-a280-29a5005fe60b
< 1.6.6
HIGH 7.5 The Zippy plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.5 via deseria… wordfence
9df6a2b4-2dc4-43dd-8282-5c05b0fa13f6
< 4.0.0
HIGH 7.5 The LoginPress | wp-login Custom Login Page Customizer plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
9db8756a-a177-4d39-b169-dc874cac2b3b
< 1.0.8
HIGH 7.5 The Reviewify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
9d7b7f4b-6acb-4ccb-8f2e-951012996ac7
< 7.1.0.6
HIGH 7.5 The Xagio SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
← Prev 292 293 294 295 296 297 298 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top