🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 300 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8e2672b5-64a2-4b30-b0be-2a9303d46ac1
< 4.14
HIGH 7.5 The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter… wordfence
8e0ff2d6-65d2-4a54-b3e5-64b424013313
< 2.5.1
HIGH 7.5 The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is… wordfence
8def156a-f2f2-4640-a1c9-c21c74e1f308
< 5.1.16
HIGH 7.5 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
8db434d3-1bbc-499c-a2b2-0e2e86d7a088 HIGH 7.5 The Laurent theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1. This makes … wordfence
8d9a779f-870c-4e57-88fb-c98c8b3cf15d HIGH 7.5 The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Inj… wordfence
8d954868-eff2-497d-84e7-cc42da8a4c6f
< 4.9.2
HIGH 7.5 The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulne… wordfence
8cee662f-f639-47ba-9534-92f4c1fe7068
< 3.8.3.1
HIGH 7.5 The JetSmartFilters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.3 due to i… wordfence
8c5adae3-b242-4408-bcff-93d8fb976b38
< 2.0.1
HIGH 7.5 The XV Random Quotes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.0 due to … wordfence
8c5a065a-a81e-4963-af54-21f145632bed
< 1.5.29
HIGH 7.5 The Booking Package WordPress plugin before 1.5.29 requires a token for exporting the ical representation of it's bookin… wordfence
8bcfbc26-9b5d-4df8-9f16-293734bd2805
< 4.3.8
HIGH 7.5 The LTL Freight Quotes – XPO Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and 'dropsh… wordfence
8bc86a29-cb1f-4711-925c-51dbbf682477
< 1.7.21
HIGH 7.5 The Booking Package plugin for WordPress is vulnerable to generic SQL Injection via 'email' Form Parameter (form<N>) in … wordfence
8bb2ce22-077b-41dd-a2ff-cc1db9d20d38
< 4.4.0
HIGH 7.5 The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type val… wordfence
8b411b23-1bf9-4f9f-9791-59dabbd2ce0c
< 7.8
HIGH 7.5 The Boldman theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.7. This makes … wordfence
8b0e0f22-de42-4da9-a0c1-ae41ba57be03
< 2.2.2
HIGH 7.5 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validati… wordfence
8aeaba0e-0a23-48f6-aa42-7f2f3bd741f1
< 1.0.3
HIGH 7.5 The ZIP Code Based Content Protection plugin for WordPress is vulnerable to SQL Injection in all versions up to, and inc… wordfence
8ad52e6f-0dbf-459c-badb-86b9036760d7
< 6.2.0
HIGH 7.5 The JS Archive List plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.1.7 v… wordfence
8ad473d5-f54b-4801-9ba3-54e4dddf26f7
< 3.7.1.1
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to Remote Code Execution via SSTI in all versions up to, and including,… wordfence
8ab5ca55-0a8a-45a8-9ab0-aa3bbfa85417
< 1.13.18
HIGH 7.5 The Geo Mashup plugin for WordPress is vulnerable to SQL Injection via the 'sort' parameter in all versions up to, and i… wordfence
8a9742e8-92c1-46f9-b8c6-4f9b26d59dcb
< 2.1.29
HIGH 7.5 The Blocksy Companion Pro plugin for WordPress is vulnerable to SQL Injection in versions up to 2.1.29 due to insufficie… wordfence
8a87bbfe-8cf5-4bba-90bc-902071b72bca
< 2.0
HIGH 7.5 The Aspose.PDF Exporter plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, … wordfence
8a7e2ad0-8427-450d-aa7e-abdbbc668247
< 1.7.15
HIGH 7.5 Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress… wordfence
8a5bcf8f-9aa0-4a78-b3a8-21571700ea8b
< 2.0
HIGH 7.5 The Spam Free WordPress plugin for WordPress is vulnerable to full path disclosure in versions up to, and including, 1.9… wordfence
8a420f63-2d8e-49c9-baaa-a7476a1b9128
< 3.1.6
HIGH 7.5 The Quotes Llama plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.5 due to insu… wordfence
89f7c342-1526-4702-88ac-ce37d158d9b2
< 3.13.3
HIGH 7.5 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized acce… wordfence
89cd5429-39a0-441f-ba69-dea111eae5ed
< 3.2.79
HIGH 7.5 The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missin… wordfence
← Prev 297 298 299 300 301 302 303 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top