🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 301 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
898c5554-fd02-47a2-a1f9-1c488cfab57e
< 1.5.1
HIGH 7.5 The Passwords Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit… wordfence
894080c3-f00a-491b-bebf-469e35118965 HIGH 7.5 The Download Media Library plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
88f8fa25-e3d5-4dfd-aae5-68b5880ffd53
< 3.5.2
HIGH 7.5 The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word… wordfence
88f1eb9a-f3bb-4b62-975f-a6cb95850966
< 8.3.10
HIGH 7.5 The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing fi… wordfence
88b3a69d-2c94-48e6-b965-8a67b2fe42b2
< 2.3.11
HIGH 7.5 The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.10 via … wordfence
88a46a24-6d46-44cc-ac01-70a1c329cb51
< 6.11.11
HIGH 7.5 The WP Compress – Image Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a mis… wordfence
886b612a-d0d1-4880-b423-eb62410a28cd
< 8.3.2
HIGH 7.5 The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress … wordfence
883e1f3c-7e47-4522-ae8c-a9a6b4160be2
< 2.10.8
HIGH 7.5 The PowerPack Pro for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
8815abff-6bd5-4ce4-9adf-afd699f628c4
< 2.6.3
HIGH 7.5 The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related t… wordfence
87d4dd4a-b1e2-4d08-aef1-77e58aa7531d
< 3.3.30
HIGH 7.5 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function… wordfence
875b15a1-c747-4a74-a77e-d541f92468a3
< 1.5.8
HIGH 7.5 The Maps Marker Pro plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1.5.7. This a… wordfence
8755ab3f-ee77-44ea-8620-590f1f1cb333
< 3.18.1
HIGH 7.5 The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
871f6611-3b5e-4e36-992c-726b31e88c95 HIGH 7.5 The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of th… wordfence
86d8ea64-39a7-46c1-bc21-39814c2ac869
< 11.6.8
HIGH 7.5 The RSVPMarker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.6.7 due to insu… wordfence
86a5adaf-02b7-4b42-a048-8bc01f07656b
< 1.14.10
HIGH 7.5 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Se… wordfence
85fdf21b-0d16-4404-aad0-a2eae12f5db5
< 2.2.6
HIGH 7.5 The Frontend Dashboard plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.5 due t… wordfence
85abf905-ec47-4847-b3d6-8570fd5eb287
< 4.0.4
HIGH 7.5 The BackWPup – WordPress Backup Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all ver… wordfence
8520ae92-0b37-4f7a-afd1-427e1a9a31f1 HIGH 7.5 The Kids Heaven theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.2 via dese… wordfence
8457c5e1-9c31-4a1a-a221-36647753a877
< 5.1.2
HIGH 7.5 In BuddyPress before 5.1.2, requests to a certain REST API endpoint can result in private user data getting exposed. Aut… wordfence
843ef712-6ca6-44d2-825f-7ce9a82d74e6
< 1.4.7.1
HIGH 7.5 The Duplicator – WordPress Migration Plugin WordPress plugin is vulnerable to Unauthenticated System Information Discl… wordfence
83e396c3-e843-4337-bf90-894d9d7de2a8
< 1.4.1
HIGH 7.5 When visiting a site running Web-Stat < 1.4.1, the "wts_web_stat_load_init" function used the visitor’s browser to sen… wordfence
83c4a78e-f3e9-442d-99de-915a64132c32
< 3.0.8
HIGH 7.5 The JobSearch plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 3.0.8. This m… wordfence
83b0534e-1b8d-46a8-9698-e7ca73e5ab57
< 2.6.1
HIGH 7.5 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side reques… wordfence
838ccf02-2b01-42f8-b5bf-6fafbb2db673
< 2.9.10
HIGH 7.5 The plugin Simple Job Board for WordPress is vulnerable to Information Disclosure in versions up to, and including, 2.9.… wordfence
836bac94-fd74-4ef9-a79b-4ea13de8f44f
< 0.9.2.5
HIGH 7.5 W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the … wordfence
← Prev 298 299 300 301 302 303 304 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top