πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 303 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7eb7c846-c82b-40c8-a5ae-88b30c761ba9
< 2.3.12
HIGH 7.5 The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_sav… wordfence
7ea72320-0e1e-45e3-987d-9ab7eecf1aee
< 1.1.31
HIGH 7.5 The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1… wordfence
7e963601-dc41-4218-9119-708c74e51bc2
< 2.3.0
HIGH 7.5 The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind … wordfence
7e8ab165-57b8-4509-86b8-6e5226812264
< 2.7.8
HIGH 7.5 The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper f… wordfence
7e61a7ae-b9c9-44ca-81b7-db8323ee66a3
< 2.0.88
HIGH 7.5 The Ads by WPQuads plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.87.1 due to… wordfence
7df452c9-4e73-40d7-88a3-d38ae1309d8f
< 2.5.9
HIGH 7.5 The LTL Freight Quotes – Unishippers Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' par… wordfence
7dc02b21-5102-4789-8db4-84014f8807ca
< 6.7.5
HIGH 7.5 The Consulting theme for WordPress is vulnerable to Local File Inclusion in versions up to 6.7.5. This makes it possible… wordfence
7dba6e37-3d16-428f-9c68-724c850ef53d HIGH 7.5 The Flow theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.8. This makes it … wordfence
7db401e4-59d5-4a04-84bb-061098bf9e66 HIGH 7.5 The Appsplate plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insuffi… wordfence
7dab03b8-6ed9-4f08-bd52-0f507de882de HIGH 7.5 The Real3D Flipbook plugin for WordPress is vulnerable to file uploads to user controlled locations due to missing direc… wordfence
7da40b9c-5fb0-49d7-b0d7-bca32209d40d
< 1.2.0
HIGH 7.5 The FileOrganizer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.0. Th… wordfence
7d7da9c3-dc46-4c61-8737-052844939e93 HIGH 7.5 The 123ContactForm for WordPress plugin for WordPress is vulnerable to Arbitrary Post Creation in versions up to, and in… wordfence
7d604ef5-7c49-44af-8e4f-242b98ba4ab8 HIGH 7.5 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to Local File Inclusion in versions up … wordfence
7d51ce34-3768-4dc6-bb28-ac59284d4945
< 1.1.5
HIGH 7.5 The Jobmonster Elementor Addon plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includi… wordfence
7cf6421c-7b92-4624-9c8a-2a2ab0ca9b28
< 1.7
HIGH 7.5 The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
7c9c36b3-f76b-4af9-bb2d-8b16e021cf12
< 3.8.1.1
HIGH 7.5 The JetSmartFilters plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.1 due to i… wordfence
7c69d0ec-d533-416b-9bc1-a3d5a871469a
< 1.6.9.29
HIGH 7.5 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
7bbead7c-47b9-473f-b335-6fae4b5998d6
< 1.0.7
HIGH 7.5 The Contact Form Extender for Divi Builder plugin for WordPress is vulnerable to Arbitrary File Deletion due to insuffic… wordfence
7b73d309-5c3a-4a46-95df-fd7a59c66275
< 2.3.0
HIGH 7.5 The wp-db-backup plugin up to 2.2.4 for WordPress relies on a five-character string for access control, which makes it e… wordfence
7b5ef9de-ba5e-463e-a528-098d724b1657
< 4.16.2
HIGH 7.5 The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders. wordfence
7b4e9cf7-e60c-414d-94fa-a43191baf9ac HIGH 7.5 The Cherry Framework theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
7b0eff94-6fb9-4caf-b60d-f92f63a41915
< 5.6.4
HIGH 7.5 The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to… wordfence
7b00d175-261d-46e3-bf3c-2d18f4e4972d
< 3.1.2
HIGH 7.5 The Insert Headers And Footers plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a… wordfence
7af97962-52fc-42d3-9499-41ee9424bb3e HIGH 7.5 The Photo Contest | Competition | Video Contest plugin for WordPress is vulnerable to PHP Object Injection in versions … wordfence
7ab99751-24b7-41db-8a27-d86eda3eeee5
< 7.1.0
HIGH 7.5 The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score plugin for WordPre… wordfence
← Prev 300 301 302 303 304 305 306 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top