πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 302 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
836884b5-f547-4f50-8a97-5d910d877e5e
< 3.0.7
HIGH 7.5 The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift C… wordfence
83460136-5a51-4c11-a695-ea2b2d60d68f
< 1.38.4
HIGH 7.5 The WP Property plugin for WordPress is vulnerable to Information Disclosure in versions before 1.38.3.3 via the get_ins… wordfence
8322fe81-2c2f-4aa6-b08f-fa5c16e62218
< 3.2.5
HIGH 7.5 The LTL Freight Quotes – SEFL Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' a… wordfence
82b59dd0-4101-4bfb-ad3b-ba5a44cebe2a
< 2.0.0
HIGH 7.5 The Backup Migration plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
8224b9ae-799b-4675-b9ae-f6132f86c429 HIGH 7.5 The File Provider plugin for WordPress is vulnerable to SQL Injection via the 'fileId' parameter in all versions up to, … wordfence
820b289c-f907-42b1-8b22-52d614398fba
< 2.2.11
HIGH 7.5 The SEUR Oficial plugin for WordPress is vulnerable to SQL Injection via the 'id_order' parameter of the '/modules/seur/… wordfence
8206d00c-7eb1-4ef2-b3d3-be78d39036db HIGH 7.5 The Accommodation System plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on… wordfence
82016921-4efb-47b4-9a75-45cae4ad80f9
< 3.6.3
HIGH 7.5 The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'wo… wordfence
819542fe-004e-4636-ad38-f11642d52ede HIGH 7.5 The Dokan Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.0.2 via des… wordfence
814b6043-e155-4acb-ba4f-bff7f5953a03 HIGH 7.5 The Wow Viral Signups plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1 due to i… wordfence
813fe9d2-913c-4e04-bcb7-443eef95c62e
< 3.6.5
HIGH 7.5 The Small Package Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' and… wordfence
811dc53c-a701-47fc-be06-bd668e34c99f
< 1.8.0
HIGH 7.5 The bSecure – Your Universal Checkout plugin for WordPress is vulnerable to SQL Injection in versions up to, and i… wordfence
80f8dd28-f01d-457d-986c-58e38d266202
< 2.9.7
HIGH 7.5 The WooCommerce Ultimate Gift Card - Create, Sell and Manage Gift Cards with Customized Email Templates plugin for WordP… wordfence
80b6d533-b282-4c13-bb0b-6be3f456203c HIGH 7.5 The DirectIQ Email Marketing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0 d… wordfence
806d3919-7a10-43f3-9c68-ce38ba359a35
< 1.9.3
HIGH 7.5 The Migrate WordPress Website & Backups – Prime Mover plugin for WordPress is vulnerable to Sensitive Information Expo… wordfence
80544889-8efc-4aa0-a690-774b1ee6a1a0
< 7.0.1
HIGH 7.5 The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptog… wordfence
80436ede-dafb-469c-b97d-ef797e1bed20
< 5.3.0
HIGH 7.5 The Fashion theme for WordPress is vulnerable to Local File Inclusion in versions up to 5.3.0. This makes it possible fo… wordfence
802c83c6-4da2-4286-b1a3-f964cf5e789a
< 3.4.8
HIGH 7.5 An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST… wordfence
801d6cde-f9c6-4e68-8bfc-ff8c0593372d
< 5.2.9
HIGH 7.5 The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php'… wordfence
7ffa92be-9d38-40d9-954d-d890136b5aa1
< 0.6.6
HIGH 7.5 The WPNakama – Team and multi-Client Collaboration, Editorial and Project Management plugin for WordPress is vulnerabl… wordfence
7fe50510-6736-4bcf-b62f-0b8d2cb8ff3a
< 5.153.4
HIGH 7.5 It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiS… wordfence
7fd2d8cd-277d-4951-9445-45e8e37db9b4 HIGH 7.5 The Torod plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to insufficient … wordfence
7fb9ceb4-84a6-41bc-97e4-5e4e12a6ea15 HIGH 7.5 The Awesome Filterable Portfolio plugin for WordPress is vulnerable to unauthenticated plugin settings change due to mis… wordfence
7f365519-dd0a-4f39-880d-7216ce2f7d1e
< 3.9.8
HIGH 7.5 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecure Direct Object R… wordfence
7f20352f-386f-45ab-b719-8a70f5c11b02 HIGH 7.5 Several WordPress plugins using the JqueryFileTree extension are vulnerable to Directory Traversal via the 'dir' paramet… wordfence
← Prev 299 300 301 302 303 304 305 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top