πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 308 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6afd5a43-a835-4251-b7b2-a787582c9e71
< 3.0.15
HIGH 7.5 The Post Duplicator plugin for WordPress is vulnerable to PHP Object Injection in versions up to 3.0.15 via deserializat… wordfence
6a5cc21a-eb3a-429a-a0f9-0181d95a9eeb HIGH 7.5 The Yawave plugin for WordPress is vulnerable to SQL Injection via the 'lbid' parameter in all versions up to, and inclu… wordfence
6a50f6ba-1fc7-4cfb-b419-69ad7e9dacf9
< 2.1.5
HIGH 7.5 The InPost Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.4.6 due to … wordfence
6a4559f8-bd13-4a38-91c2-8569a9967700
< 1.3.16
HIGH 7.5 The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input. wordfence
6a30d572-e086-4b83-8cb7-4cef9a3253bd HIGH 7.5 The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the… wordfence
6a216505-7ab3-4ec7-bb11-e1c6ceaa2aed HIGH 7.5 The RedSteel theme for WordPress is vulnerable to Sensitive Data Exposure via the 'file' parameter in the 'download.php'… wordfence
697105e6-3155-4199-9fee-914830674023
< 1.8.17.0
HIGH 7.5 The WP Mailster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
6931b3b3-b1b5-4ab8-8592-82332d16168c HIGH 7.5 The Virtual Bot plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insuf… wordfence
692fe371-a22c-4144-a17f-bde1c1850bfa
< 1.8.3
HIGH 7.5 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
691eb4c1-18ba-433b-8725-70f2ecf89b0a
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
68d79cb1-c9b9-441a-b265-f21edf99e801
< 1.1.7
HIGH 7.5 The Google Map Targeting plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
68b4ef1f-93cc-4fbd-9713-9cbc6ad59f5e
< 1.5.8
HIGH 7.5 The Leaflet Maps Marker Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and includi… wordfence
68ac08b0-19f7-4e05-80f8-0eb4e7b96a5f
< 2.9.6
HIGH 7.5 The Product Filter Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 2.9.6 due t… wordfence
684b0166-56fc-433f-ae34-0ff5071e7f05
< 2.3.2
HIGH 7.5 The bold-page-builder plugin before 2.3.2 for WordPress has no protection against modifying settings and importing data. wordfence
67ddca02-2e92-4aea-ada9-ace0df29c775
< 1.3.3
HIGH 7.5 The Ninja Job Board plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.3.… wordfence
67db430e-d796-4ace-b5d1-de492edb8ea8
< 2.1.3
HIGH 7.5 The Product Table by WBW plugin for WordPress is vulnerable to SQL Injection via the 'additionalCondition' parameter in … wordfence
67c7b9b2-e73f-47fe-aecc-14e998a607c8
< 1.6.10.2
HIGH 7.5 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
67965a51-39d3-4d14-adf5-d91d4c775baf
< 1.7.1
HIGH 7.5 The CozyStay theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
676c8ed5-5a59-413f-af7a-49d6927cd9b1
< 5.19.1
HIGH 7.5 The Citadela Directory plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
67583814-4180-4db7-ba35-fc9843648341 HIGH 7.5 The Booking Calendar and Notification plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
671f5ba5-1f18-49fa-aa97-eaebdb3417bb
< 2.2.8
HIGH 7.5 The Welcart e-Commerce plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on th… wordfence
6707aa4c-c652-42c0-bdb9-00be984e7271
< 1.44.3
HIGH 7.5 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to PHP Obje… wordfence
663e8611-ce0c-4c09-9fa3-852f287351d4
< 3.0.0.1
HIGH 7.5 The JetReviews plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.0. This … wordfence
6639c3d8-8f26-4ee5-8c4b-2efcf34668a2
< 1.3.57
HIGH 7.5 The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i… wordfence
662ca451-5c69-4973-afc8-5dc1caf57ad7
< 3.3.3
HIGH 7.5 The Defender Security plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and incl… wordfence
← Prev 305 306 307 308 309 310 311 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top