πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 296 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9d4ff5ed-8857-46b8-942b-ac0f47880a95
< 5.2.5
HIGH 7.5 The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
9d4f47af-294a-4c3a-accd-9ae674916a38
< 2.5.4
HIGH 7.5 The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploade… wordfence
9d17f26b-e8b7-480d-bf03-2cfdb261fa28
< 3.0.0
HIGH 7.5 An unprivileged user could use the functionality of the NS WooCommerce Watermark WordPress plugin through 2.11.3 to load… wordfence
9cecce4d-5d4a-4286-97dc-88a379e21b60
< 1.9.1
HIGH 7.5 The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 v… wordfence
9cec4d7a-81e0-489a-b549-5848ed9a8449
< 3.1.1
HIGH 7.5 Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Sour… wordfence
9cbba523-8f9f-421d-9305-4b52e8eef726 HIGH 7.5 The Paid Downloads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.15 due to ins… wordfence
9cb96b56-82cb-4429-b645-dfe8a14931e5
< 5.0.7
HIGH 7.5 The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_… wordfence
9c92dbe9-faeb-4ea9-9657-ed7accf63cc1
< 2.3.3
HIGH 7.5 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
9c8ab916-240d-43c3-92d4-7efd75862a5e
< 4.9.58
HIGH 7.5 The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrus… wordfence
9c2e8932-f207-40f2-85c9-5d1f28f859f2 HIGH 7.5 The WordPress Auction Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 3… wordfence
9c226d83-2886-4b7c-978c-ad723709145f
< 2.5.4
HIGH 7.5 Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2… wordfence
9bfd6ec9-51e1-41a3-9db1-3b44d6eba958 HIGH 7.5 The Responsive Posts Carousel Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… wordfence
9bf472f1-5980-48ee-aa10-aad19b6f2456
< 2.7.10
HIGH 7.5 The Groundhogg plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.9.… wordfence
9bd873e5-fd65-48c3-a71d-aaf6d8372606
< 21.8.0.100
HIGH 7.5 The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to SQL Injection via the β€˜id’ par… wordfence
9bcd18bd-032e-4a97-83aa-a377f9b1f435
< 1.5.5
HIGH 7.5 The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all ver… wordfence
9b871957-a2b3-492f-b461-7040d9098b2b
< 2.2.14
HIGH 7.5 The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to… wordfence
9b1dc818-75c6-45b7-9f0f-88275cc6e946
< 6.9.1
HIGH 7.5 The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page. wordfence
9b0f6653-471b-4cee-9c92-f24dbe2c2dbd
< 6.2.0
HIGH 7.5 The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.1… wordfence
9b0e973b-f0bf-44d1-b964-e259f68291aa
< 1.2.3
HIGH 7.5 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to generic SQL Injection … wordfence
9b0d1174-b94f-4b44-8b88-bc4355f0d165
< 1.9.2
HIGH 7.5 The WeMusic theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.9.1 via deseri… wordfence
9b09bf42-a85d-4a5b-9acc-609e0a5d7748
< 2.2.50
HIGH 7.5 In the nextgen-gallery plugin before 2.2.50 for WordPress, gallery paths are not secured. wordfence
9b00da60-7d2d-467e-ab58-0bb4af0cbda5
< 2.9.1
HIGH 7.5 The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vu… wordfence
9abfd0f5-f665-4745-9756-8445ddbdc29d
< 0.6.4
HIGH 7.5 The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions… wordfence
9aad7539-071e-474b-a2db-0f496aac2995
< 11.15.11
HIGH 7.5 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to PHP Object Injection in all versions u… wordfence
9a7ad642-ace5-41c9-bd33-44e532326f25 HIGH 7.5 The WP Pipes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.3 due to insuffic… wordfence
← Prev 293 294 295 296 297 298 299 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top