πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 307 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
704fd636-04f6-4620-85a2-1c08f93125fe
< 3.2.2
HIGH 7.5 The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.2 due to insufficient escaping on … wordfence
6fd646c7-f1b5-4ae7-adee-1e427fc4cf0a
< 1.4.2
HIGH 7.5 The Jobica Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.1 via d… wordfence
6fc53814-05d6-4c8f-9e1d-ecb0f19dd7ab
< 2.9.13
HIGH 7.5 The User Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.12 via… wordfence
6f9cedea-086c-479b-a1ae-e124df1e09f1 HIGH 7.5 The Shopify plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0. This mak… wordfence
6f946251-c7be-4ef6-885f-8b378c0c234c
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
6f561cce-1c0c-40f5-abba-ada8bc503aa8
< 13.0.8
HIGH 7.5 The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimit… wordfence
6f1fc61a-9760-430e-a8ba-139ffef1a60d HIGH 7.5 The MAS Videos plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2. This … wordfence
6eed2941-d9fe-4020-b1ab-fb0885f47d80 HIGH 7.5 The Correos Oficial plugin for WordPress is vulnerable to the unauthorized download of files in versions up to, and incl… wordfence
6ee6abb4-eeb7-4ea3-912d-cb86d189b3bf
< 2.9.11
HIGH 7.5 The ListingPro Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.10 due t… wordfence
6eb5c8f1-d71d-4995-8242-abf9ef248b75
< 1.1.0
HIGH 7.5 The Tainacan plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.3 due to insuffic… wordfence
6eab3497-bf77-43a8-962d-d63db7290777
< 3.1.2
HIGH 7.5 The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under t… wordfence
6e6cda1a-e137-4c30-a66b-c10a88070c50
< 1.6.2
HIGH 7.5 The NativeChurch theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1.6.1 vi… wordfence
6e0945eb-ceec-4536-822a-fe864c21b580
< 5.1
HIGH 7.5 The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-jso… wordfence
6d4394fd-7063-4792-83a7-5c419fac5652
< 1.7.0
HIGH 7.5 The Panorama – 360 degree Virtual Tour, Panoramic Image viewer and More plugin for WordPress is vulnerable to Local Fi… wordfence
6d359a5c-db11-416e-a329-c3ed67b1a925
< 2.3.7
HIGH 7.5 The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to SQL Injection via the '… wordfence
6d14a90d-65ea-45da-956b-0735e2e2b538
< 2.8.8
HIGH 7.5 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… wordfence
6cdd662b-09b9-4c0e-a543-51866f6a9d71
< 2.3.12
HIGH 7.5 The LTL Freight Quotes – FreightQuote Edition plugin for WordPress is vulnerable to SQL Injection in versions up to, a… wordfence
6cdc0096-8e21-4b82-b9d0-961f48907a09
< 4.0.24
HIGH 7.5 The WC Marketplace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c… wordfence
6cd116e5-2b1f-4a76-be3b-06a3a5df85d2
< 2.6.2
HIGH 7.5 The Noisa theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.6.0 via deserial… wordfence
6c694bce-e389-492a-827d-ae5293730612
< 1.9.36
HIGH 7.5 The usc-e-shop (aka Collne Welcart e-Commerce) plugin before 1.9.36 for WordPress allows Object Injection because of usc… wordfence
6be4d4ca-d9cf-4361-8763-3a34e756c9c6 HIGH 7.5 The Anona - Pest Control WordPress Theme theme for WordPress is vulnerable to Path Traversal in all versions up to, and … wordfence
6bcc353f-cdf2-4e28-a0e0-ad149ecb1c3b
< 1.0
HIGH 7.5 Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attacker… wordfence
6b5a2a2a-a204-4265-b81e-4b785a407871
< 4.16.0
HIGH 7.5 The MultiSafepay plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary file read in versions up to, and… wordfence
6b1bf4e0-b4e1-4c3f-ae17-ffbf31849651
< 1.9.7
HIGH 7.5 The Wolmart Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.6 due to insu… wordfence
6b0b2cac-cf4f-46cd-abe9-8ac6ff763a5d HIGH 7.5 The WP Attractive Donations System - Easy Stripe & Paypal donations plugin for WordPress is vulnerable to SQL Injection … wordfence
← Prev 304 305 306 307 308 309 310 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top