πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 306 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7370e3c3-90e6-4698-88e7-baf56832528d HIGH 7.5 Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attacke… wordfence
7365d3ba-e983-464e-9a15-90195a08290a
< 2.3.8
HIGH 7.5 The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection in versions up to 2.3.8 due to insufficient es… wordfence
7320c06e-a7a7-4ed0-93cd-e85d74bae73f
< 6.6.5
HIGH 7.5 The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injec… wordfence
7320421b-6b88-452d-a363-a71cdf7953a6
< 2.0
HIGH 7.5 The Web Directory Free plugin for WordPress is vulnerable to generic SQL Injection via the 'levels' parameter in all ver… wordfence
72d9efad-9afd-4d7a-a1dd-7623a9e5a7db
< 1.0.2
HIGH 7.5 The Sell Downloads plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 1.0.1 via… wordfence
72d325c5-ea41-45c7-97d7-c15c0038ade6
< 5.2.19
HIGH 7.5 The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection in versions u… wordfence
72857d52-ac81-4eb2-93fa-7bb03265bccf
< 6.1.6
HIGH 7.5 The JS Archive List plugin for WordPress is vulnerable to time-based SQL Injection via the build_sql_where() function in… wordfence
7267ede1-7745-47cc-ac0d-4362140b4c23
< 5.6.6
HIGH 7.5 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to authorization bypass due to a missing capabi… wordfence
725bce1b-ec76-411d-928c-2aea47867292
< 2.17.0
HIGH 7.5 The Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugin for WordPress is vulnerable to unauthorized … wordfence
724a2da0-e4e7-4868-a1ad-fce69a915981
< 1.4.5
HIGH 7.5 The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the… wordfence
7206b32a-3aaa-47c5-9489-11252a8434a3
< 1.4.5
HIGH 7.5 The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to SQL Injection in v… wordfence
71f2f8c4-00ee-4ab4-b0e0-9ddac46818b3
< 28.1.7
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to… wordfence
71e9ff91-4137-4c66-959b-f4ffb8d3ba32
< 12.8.7
HIGH 7.5 The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includ… wordfence
71a3502a-60cc-4861-8654-42536010db92 HIGH 7.5 The ThemeMove Core plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.… wordfence
7193b373-a0c9-4cd7-8a53-4f35ceff8f23
< 3.0.0
HIGH 7.5 The Alkubot – Gamify discounts, sell more and give less at the right time plugin for WordPress is vulnerable to Cross-… wordfence
718615b1-9c25-4119-bc30-683ef51e5861 HIGH 7.5 The Organizer plugin 1.2.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors… wordfence
71772131-812e-4561-bab1-d4cf0832d777
< 2.4.1
HIGH 7.5 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versi… wordfence
71642341-9fe0-44a9-88f3-70167dc6ca62
< 1.6.9.29
HIGH 7.5 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to b… wordfence
715332d3-fa63-4036-8b10-3d500ca8963f
< 1.1.0
HIGH 7.5 The WP Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to SQL Injection in versions up to, an… wordfence
71371a44-fed4-4aea-9f86-a37ca26a57b1
< 2.0
HIGH 7.5 The Link Log plugin for WordPress is vulnerable to HTTP Response Splitting in versions up to, and including 1.4. This is… wordfence
70b2f35d-c58b-480c-a893-e970daca5f3f
< 3.3
HIGH 7.5 The Library Management System plugin for WordPress is vulnerable to SQL Injection via the 'bid' parameter in all version… wordfence
70b00cfc-4a9b-442a-9c80-fd080924ca34
< 1.6.30
HIGH 7.5 The salesking plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
70971072-d743-466b-affe-d7f79d5712aa
< 5.5.1
HIGH 7.5 The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in version… wordfence
70744b6b-faac-4b08-bf0f-10c0a01250eb
< 2.6
HIGH 7.5 The Select Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to 2.6. This makes it possible… wordfence
7065f038-2dd0-447d-bea6-385f6e9657d5 HIGH 7.5 The OrganicFood theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.6.4. This … wordfence
← Prev 303 304 305 306 307 308 309 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top