ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 304 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7a9cfd7a-7e6a-4a1f-86bc-b53ef461dde2 HIGH 7.5 The Recent Backups plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 0.7 via t… wordfence
7a7677a4-0cd5-496e-82cb-f6582e63475d
< 1.5.9
HIGH 7.5 includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes … wordfence
7a5e08d8-c6ef-42a3-9599-28c3bfb35017
< 2.9.18
HIGH 7.5 The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in … wordfence
7a46c049-367d-4a67-9607-c74ef0b96c71
< 3.6.75
HIGH 7.5 The Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including… wordfence
7a1a46b3-77a1-4d69-9a0d-90794e78f828 HIGH 7.5 The Apptha Slider Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.5… wordfence
7a140b07-e8b4-48a5-8585-79ad2744f3f3 HIGH 7.5 The GG Bought Together for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
7a0ed307-091a-473f-a95f-f270ec4dc2f1
< 10.3.1
HIGH 7.5 The SmartMag theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 10.3.0. This ma… wordfence
79ffe548-0005-4f5e-873f-a1afec64a251
< 1.3.8.9
HIGH 7.5 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
795002a5-1233-4472-93fe-78e33e53aa80 HIGH 7.5 The WP Multistore Locator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.2 du… wordfence
793e650c-27f7-4eff-9922-8e01ba24e96d
< 2.1.1
HIGH 7.5 Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers t… wordfence
793a2096-3332-412e-a45a-a7367b1209a3
< 1.1.2
HIGH 7.5 The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act… wordfence
7914ebe6-b5e1-4a1a-8794-80f515e6c9f6
< 2.9.1.7
HIGH 7.5 The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_… wordfence
790f93b0-eb69-473f-a726-bfe215f5d870
< 10.14.9
HIGH 7.5 The Booking Calendar plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'dates_to_check' param… wordfence
7908d167-f831-4ed0-b754-2b390b5c3b2c
< 4.4.6.1
HIGH 7.5 The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection via the 'regions' parameter array keys in versio… wordfence
78f964a7-bed3-435e-94c5-750883a0c836 HIGH 7.5 The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type param… wordfence
78e7b65d-91f8-477e-b992-3148c1b65d7b
< 1.0.8
HIGH 7.5 The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Exp… wordfence
78ba132c-b5b4-4999-a0ec-67d17ae2857f
< 4.1.12
HIGH 7.5 The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directo… wordfence
78914fef-6ab4-49b8-8c67-3a634759194c
< 1.1.0
HIGH 7.5 The Tinymce Thumbnail Gallery plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
788422c4-e070-48aa-a85d-a5d5a25a6a1d
< 1.52.2
HIGH 7.5 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Tra… wordfence
786b1b8f-7f63-4ac4-a808-668b38bf0fb4
< 2.2.1
HIGH 7.5 The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all version… wordfence
784998a7-550d-4299-9995-af01e5ee1d21 HIGH 7.5 The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() functi… wordfence
782d91d4-4e52-4ce6-9fd3-8f9a816856ce
< 2.32.7
HIGH 7.5 The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is … wordfence
7809f5ec-0b76-4244-ab9d-b6a90cf74716 HIGH 7.5 The WP AutoKeyword plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insu… wordfence
77d6d38a-f590-4188-8941-ea6936ae5cf4
< 3.8.9.1
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to 3.8.9.1 due to insufficient escaping… wordfence
77cea6a1-d5e8-459c-97cc-9dc8f7c0f48f
< 1.0
HIGH 7.5 Absolute path traversal vulnerability in lib/download.php in the IBS Mappro plugin before 1.0 for WordPress allows remot… wordfence
← Prev 301 302 303 304 305 306 307 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top