🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 297 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9a47e6ff-a1d2-40f0-b4d2-8ee8394ce603
< 1.1.17
HIGH 7.5 The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification a… wordfence
9a455340-4d07-4f02-9dcb-835fcd43985d HIGH 7.5 The Productive Commerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.22 due… wordfence
9a09425f-f18d-40c3-888d-0845e4ebdc77
< 1.2.9
HIGH 7.5 The Quentn WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.8 due to insuffi… wordfence
9a047577-d5eb-425b-9318-4473d052a223
< 2.8.1
HIGH 7.5 The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2… wordfence
99fa7f41-f3ac-435c-af1b-4a965291de37
< 1.9
HIGH 7.5 The RokIntroScroller plugin for WordPress is vulnerable to Denial of Service via the 'src' parameter in the 'thumb.php' … wordfence
99e34600-7eba-473f-91c0-82e45a48c419
< 1.2.9
HIGH 7.5 The Vex theme for WordPress is vulnerable to PHP Object Injection in versions up to 1.2.9 via deserialization of untrust… wordfence
99a9d844-305d-445d-947d-060920e8a229
< 1.3
HIGH 7.5 The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to SQL Injection in version… wordfence
999b2249-5bfb-4add-b955-e82ab0308d2f
< 3.15.4
HIGH 7.5 The Avada theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.15.3 via deseria… wordfence
997918b9-2ccd-413e-9df2-d24bc3820ba1
< 2.7.0
HIGH 7.5 The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is … wordfence
996697c7-39a9-411e-a1cf-c9bb7c34b258 HIGH 7.5 The RealPress – Real Estate Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
99433521-721b-41c3-8736-fd2943901b4f
< 4.2
HIGH 7.5 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. wordfence
99418bd5-041a-4210-9571-fee6842fb692
< 1.11.5
HIGH 7.5 The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.1… wordfence
992a91da-724f-40cc-b552-113d62fe20c1
< 1.1.0
HIGH 7.5 Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to … wordfence
9909b7e3-4c6b-478e-8775-99779b21b0c1
< 2.2.2
HIGH 7.5 The Gyan Elements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.1. Th… wordfence
98f16e3a-4ef3-43f9-86b2-2cf8e26f9c80
< 6.0.5
HIGH 7.5 The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in vers… wordfence
98c263b5-8de6-4a75-9f4c-9756d6f3a050 HIGH 7.5 The Valenti theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.6.3.5 via dese… wordfence
98ab264f-b210-41d0-bb6f-b4f31d933f80
< 5.4.0
HIGH 7.5 The Jetpack CRM plugin for WordPress is vulnerable to PHAR deserialization via the ‘zbscrmcsvimpf’ parameter in the … wordfence
982817f8-c85c-4e25-a33a-6fbf3ab06808
< 2.5.4
HIGH 7.5 Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t… wordfence
97fdd2f9-02ad-492c-88d1-1e7bd9c404a5
< 3.9.7
HIGH 7.5 The Tutor LMS Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.6 due to ins… wordfence
97da8e3d-0e29-423a-bd59-dbcff1eb1249
< 3.1.3
HIGH 7.5 The MailerLite – WooCommerce integration plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… wordfence
97677968-9231-4a6b-ad81-ddb9eb9791dd
< 2.0.4
HIGH 7.5 The Activity Log plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.0.3 v… wordfence
975f7c66-033d-47b2-9e7a-b33b8fe06b17 HIGH 7.5 The UDesign Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.14.0. Th… wordfence
973ebafc-85c0-4cc5-b307-2fdb0a4a7577
< 3.14.2
HIGH 7.5 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized acce… wordfence
970c7495-e43c-4606-8154-e2ac7d1c4816
< 1.2.3
HIGH 7.5 The TAX SERVICE Electronic HDM plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1… wordfence
96c77102-3293-476c-93bd-5bbbe39f3a5e
< 3.5.6
HIGH 7.5 The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to… wordfence
← Prev 294 295 296 297 298 299 300 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top