🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 298 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
96ad872f-9831-4113-99ae-322bcd2b6fbd
< 3.2.16
HIGH 7.5 The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ … wordfence
968ead80-eed6-4a42-a3cd-73cf4cbbb1e5
< 0.94
HIGH 7.5 The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation. wordfence
964601d5-8460-41c5-9791-ff9e3af964e3
< 2.9.4.116
HIGH 7.5 The Simple Ads Manager Plugin for WordPress is vulnerable to Denial of Service in versions before 2.9.4.116. This is due… wordfence
9645b17e-6a7c-4cdd-ae43-7d2c84b624cc
< 3.1
HIGH 7.5 The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in a… wordfence
95d2bf1a-0993-4553-a00e-6f555c3f15be
< 5.27.0
HIGH 7.5 The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to authenticated (Subs… wordfence
95cd2bae-4ab7-4a0c-bb71-c17b119eaaa9
< 2.0.5
HIGH 7.5 The All-in-One WP Migration plugin for WordPress is vulnerable to authorization bypass due to a missing capability check… wordfence
95b36b47-dbb7-47f7-ba0d-ce4c6b183617
< 1.0.9
HIGH 7.5 The Active Products Tables for WooCommerce. Use constructor to create tables  plugin for WordPress is vulnerable to SQL… wordfence
959f7e13-ef58-4b02-a721-7bb10373aaaa
< 1.0.7
HIGH 7.5 The Wholesale Market for WooCommerce plugin for WordPress is vulnerable to arbitrary file download due to missing capabi… wordfence
959a086e-15f0-492a-a19b-3160ad47f1be HIGH 7.5 The North theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.7.5 via deserial… wordfence
9594b351-52ba-48a7-a875-a914b70ce7b8
< 4.4.8
HIGH 7.5 The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to PHP Object Injection in versions up t… wordfence
9545cff3-fa65-4f2e-8a9f-98d884e5608f
< 4.0
HIGH 7.5 In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an… wordfence
953e10a1-df11-40d3-869c-2974a344630e
< 2.7.7
HIGH 7.5 The Advanced AJAX Page Loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files … wordfence
9529babf-bf5e-4de1-bf84-2eae11832379
< 3.0.2
HIGH 7.5 The Decent Comments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 3.0.2 (ex… wordfence
951b2a15-04c1-4c5b-9cef-146628079c36
< 2.731
HIGH 7.5 The Post Pay Counter plugin before 2.731 for WordPress has no permissions check for an update-settings action. wordfence
94932f9a-89d4-47f1-941e-eb1bdd2df63f HIGH 7.5 The Dental Care CPT plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 20.2 vi… wordfence
93e0a1a1-fba6-4209-b679-e66d77870be2
< 2.1.4
HIGH 7.5 The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr… wordfence
93ca1959-1747-4141-9b48-1ae782b9700a HIGH 7.5 The Devnex Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
936d8c03-31e4-4fd6-94f6-8b81afce315f HIGH 7.5 The WP Google Review Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.1 du… wordfence
93224641-2079-4eb5-bf8f-82298d9d5ef6
< 2.8.2
HIGH 7.5 The Meloo theme for WordPress is vulnerable to PHP Object Injection in versions up to 2.8.2 via deserialization of untru… wordfence
92e404ab-fe2b-45b3-b8ff-672f7888b747
< 6.15.17.1
HIGH 7.5 The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.… wordfence
92dd10fa-0241-4238-9ed2-31de0dc450d7
< 3.7.9
HIGH 7.5 The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to,… wordfence
92dbc405-a11c-4c2e-a98c-8dcb4e0b64e8 HIGH 7.5 The eMagicOne Store Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and i… wordfence
92cdf0ca-8e63-4b2a-8bbc-d4ddf87eb6ca HIGH 7.5 The Electio Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due to insuff… wordfence
9264d7f3-cbd2-4528-8222-93a456332e9c
< 1.0.6
HIGH 7.5 The TableOn – WordPress Posts Table Filterable  plugin for WordPress is vulnerable to SQL Injection in versions up to… wordfence
925402a5-e203-4976-b0a9-88c974b540b9
< 6.6.4
HIGH 7.5 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injec… wordfence
← Prev 295 296 297 298 299 300 301 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top