🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 299 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9232b77e-e23f-4e91-8ea3-5e740956f51e HIGH 7.5 The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up… wordfence
922fd4a4-88ea-417e-90c2-0062b5859a14
< 2.1.2
HIGH 7.5 The Active Woot Products Tables for WooCommerce. 100% FREE  plugin for WordPress is vulnerable to SQL Injection in vers… wordfence
91d52a64-8dc1-4923-be0b-06800382151e
< 28.1.5
HIGH 7.5 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to bli… wordfence
917c70f5-154c-4c49-b06b-109cc0277a1a
< 1.1.25
HIGH 7.5 The SMTP Mailer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
9169931c-a679-4801-b33b-08c4f464dc43 HIGH 7.5 The Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App plugin for WordPress is vulnerable to … wordfence
9167e4bd-74be-46c9-b06e-566c13c02c7d
< 2.10.4
HIGH 7.5 In the WP Rocket plugin 2.10.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal charact… wordfence
91654765-6631-4eb4-9971-32b7db7933e1
< 3.1.4
HIGH 7.5 The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
91221712-8f66-4c6f-94fb-75c34a7f1fa8
< 8.7.5
HIGH 7.5 The BackupBuddy plugin for WordPress is vulnerable to unauthenticated arbitrary file downloads via the 'local-download' … wordfence
907a02b8-6965-4d0b-b4bf-c8fc0201ee12 HIGH 7.5 Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authoriz… wordfence
90775c17-4cd5-47e5-afa9-9413988b8638
< 1.6.7
HIGH 7.5 The WerkStatt plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.6.6. This m… wordfence
9040e2bb-e30a-4e18-b486-76aa601ae888 HIGH 7.5 The BookPro - Appointment Booking WordPress Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to … wordfence
901e015c-58fc-40ac-b078-f7040cbed274
< 9.1.08.002
HIGH 7.5 The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.08.001… wordfence
9013e816-1f5c-48cc-b79b-37cd9a75c2f6
< 1.22.16
HIGH 7.5 Stored Cross-Site Scripting (XSS) vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authe… wordfence
8f9cf8d3-ebc1-4d94-909e-938beb58601e
< 4.4.9
HIGH 7.5 The WpEvently plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.4.8 via des… wordfence
8f630a7c-9082-400d-9d09-1280330ffbc6 HIGH 7.5 The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions … wordfence
8f562e33-2aef-46f0-8a65-691155ede9e7
< 5.3.8
HIGH 7.5 The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. T… wordfence
8f539e25-5483-417d-a3c5-e7034c03c673
< 2.10.2
HIGH 7.5 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
8f491d48-935c-4fd9-a342-44d98c5601b3
< 1.7.7
HIGH 7.5 The WPCOM Member plugin for WordPress is vulnerable to time-based SQL Injection via the ‘user_phone’ parameter in al… wordfence
8f18e3b1-4f91-4718-8da8-ad23c8d6da75
< 2.5.5
HIGH 7.5 The Houzez Property Feed plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5.… wordfence
8efe2ccf-33cb-4db3-bc3d-ead826adb7d0 HIGH 7.5 The Easy Captcha plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
8efe0759-a3b6-43b7-b333-0e72df1ff96d HIGH 7.5 The PeakShops theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.9 via dese… wordfence
8ea2ce90-6c8c-4a31-8faa-4ab99879d8b8
< 6.15.1.1
HIGH 7.5 The The Events Calendar plugin for WordPress is vulnerable to time-based SQL Injection via the ‘s’ parameter in all … wordfence
8e8d7aa4-d2df-47ec-a5dc-c2cfd74763aa
< 2.2.7
HIGH 7.5 The Digiqole theme for WordPress is vulnerable to Local File Inclusion in versions up to 2.2.7. This makes it possible f… wordfence
8e68ec8c-e46a-4886-b386-9664a8e5ba26 HIGH 7.5 The CarZone - A Complete Car Dealer HTML Wire-Frame theme for WordPress is vulnerable to PHP Object Injection in all ver… wordfence
8e361473-8ed6-41d0-b409-2436189c1120
< 5.16.5
HIGH 7.5 Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper… wordfence
← Prev 296 297 298 299 300 301 302 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top