🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 305 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
773ed184-1478-417d-9a57-93f3971d4bc8
< 2.3.4
HIGH 7.5 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce … wordfence
76d8c4dd-6ab2-4c48-b7d9-104ffdba55c6
< 67.8.0
HIGH 7.5 The WPGYM plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 67.8.0 due to insufficie… wordfence
76bb0578-d562-4612-b7aa-db49c43b2fe1 HIGH 7.5 The ThemeMakers SmartIT Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sens… wordfence
76b75e61-e7f8-41cc-ab4f-e6ca42d68308
< 5.1.3
HIGH 7.5 The InfusedWoo Pro plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.1.2… wordfence
768d0d53-8724-4598-ae73-305225b52633
< 28.1.7
HIGH 7.5 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to SQL… wordfence
766003e7-712e-481b-b09d-91d62a325718
< 1.4.8
HIGH 7.5 The Get URL Cron plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and includin… wordfence
764041ca-65cd-498c-97e5-a33d7b54a2b9
< 1.5.21
HIGH 7.5 The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all… wordfence
760e999e-cac9-493f-9737-ad0cf055c880
< 3.2.22
HIGH 7.5 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… wordfence
75de6387-fac7-403d-9e6c-89570658d978 HIGH 7.5 The افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce plugin for WordPress… wordfence
75d66a45-5bb9-4e82-acd5-e0b92e3870a9
< 3.2.0
HIGH 7.5 The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' … wordfence
75c9c106-d1f9-43ee-be1f-3eddec8f2529
< 2.4.4
HIGH 7.5 The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter … wordfence
75c6697c-bc1d-456f-baee-ee9c57e40d21
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
7598b38b-26b1-4640-9bd7-60613a5f704d
< 3.8.4
HIGH 7.5 The WPGSI: Spreadsheet Integration plugin for WordPress is vulnerable to unauthorized modification and loss of data due … wordfence
757e7f3d-8e16-4a1d-9760-257cf382ab74
< 1.4.4
HIGH 7.5 The Themify Popup plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.3 via… wordfence
750ff77f-3591-43e9-8763-56e3b6006adc
< 1.3.8
HIGH 7.5 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
74fa4240-6f62-4db6-b7e7-56998fc29e42 HIGH 7.5 The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi… wordfence
74f15066-097d-4d4f-9cf2-a4889043496b HIGH 7.5 The Office Locator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.0 due to in… wordfence
74c71541-6706-43d2-af3d-0655e59f997c
< 1.5.8
HIGH 7.5 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
74c2c447-2ec5-4bba-a884-a366c5197dbb
< 3.7
HIGH 7.5 The GD Rating System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.2 due to … wordfence
74c169b9-4207-4cd8-89df-084db2bb947b
< 1.1.9
HIGH 7.5 The Express Payments Module plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.8 … wordfence
74a566ea-fffc-4e7e-b6bf-086aeb5b7ce1
< 10.1.04
HIGH 7.5 The WP Go Maps – Google Map, OpenStreetMap, Leaflet Map plugin for WordPress is vulnerable to SQL Injection in version… wordfence
748c4ca8-fcbf-43e5-ab70-721e83253663
< 6.3.8
HIGH 7.5 The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat… wordfence
7477ecd2-904b-4c1a-bc77-5d99ec207310 HIGH 7.5 The History Log by click5 plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.13 d… wordfence
73a049de-f4b2-4b87-a78b-62cd333853b8 HIGH 7.5 The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1… wordfence
738e5946-65e4-4403-bb23-f84910289a45
< 3.3.0
HIGH 7.5 An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object r… wordfence
← Prev 302 303 304 305 306 307 308 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top