🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 309 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
65c8ea6c-85f1-4e96-995f-57200819280e
< 2.1
HIGH 7.5 The Myriad Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.1. This is d… wordfence
659eb886-dbee-4e5f-a769-17447aad8f33
< 9.3
HIGH 7.5 The LMS theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.2 due to insufficient esc… wordfence
6565e345-3374-43d9-9789-f0d9138dc3e8
< 5.0.5
HIGH 7.5 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' para… wordfence
653e20ae-f018-41b5-a973-f73fddae70e5
< 1.2.13
HIGH 7.5 The Quentn WP plugin for WordPress is vulnerable to SQL Injection via the 'qntn_wp_access' cookie in all versions up to,… wordfence
653ab9cb-7084-47e4-b5e3-6788fa5d7496
< 2.2.5
HIGH 7.5 The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti… wordfence
649cbd38-d926-4638-9fb9-6704befa1660
< 0.9.7
HIGH 7.5 Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earli… wordfence
648941b8-d1ab-4587-bd87-f23008ac9a00 HIGH 7.5 The Infility Global plugin for WordPress is vulnerable to unauthenticated SQL Injection via the 'infility_get_data' API … wordfence
6481f4c7-2a62-457f-b21e-57e762aab29e
< 3.0.5
HIGH 7.5 The BuddyBoss Platform plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.… wordfence
640d36ac-7a25-437e-8b0a-8c5beceb14bf
< 2.1
HIGH 7.5 The Myriad Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.0. This is d… wordfence
6404476e-0c32-4f8e-882f-6a1785ba5748
< 7.9.9
HIGH 7.5 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing… wordfence
63ae3a9d-1e6b-4784-8429-04be2a89b6cb
< 1.9
HIGH 7.5 The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the … wordfence
6351d3f7-2d10-4fcf-b7c1-88ce529cd9f4
< 2.3.1
HIGH 7.5 The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the … wordfence
634f6c42-6708-4e39-afdc-7838d3368fb4 HIGH 7.5 The Schedule plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insuffic… wordfence
62eb136f-3cb0-40dc-a154-015a7fa1077b
< 1.2.6
HIGH 7.5 The ContentStudio plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including,… wordfence
62e223a5-768f-4743-99a5-2797fff7e976
< 8.14.1
HIGH 7.5 The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to SQL Injection in versions up t… wordfence
62bb2fef-60aa-4c88-8cef-a832d65b4945 HIGH 7.5 The WordPress Upload Files Anywhere plugin for WordPress is vulnerable to Path Traversal in all versions up to, and incl… wordfence
62b56147-4cb2-4824-aa49-74ef80d373e1 HIGH 7.5 The Soledad theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.7.0. This make… wordfence
62654952-830d-430c-b852-11ba8652716d
< 3.5
HIGH 7.5 The Wilmër theme for WordPress is vulnerable to Local File Inclusion in versions up to 3.5. This makes it possible for … wordfence
6122682d-6725-422c-9be8-339e4fb039a7 HIGH 7.5 The Boldermail plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.0 via de… wordfence
6113e51e-d842-433a-ab0a-92ea108917a3
< 6.2.1
HIGH 7.5 The WP OAuth Server ( Login with WordPress ) plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
60e2f3d3-c9f0-4d06-960a-6d796a280433
< 5.6
HIGH 7.5 The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to SQL Injection in all versions up to, an… wordfence
60cd2178-858e-4e24-8967-13b04f675d2d HIGH 7.5 The ArielBrailovsky-ViralAd plugin for WordPress is vulnerable to SQL Injection via the 'text' and 'id' parameters of th… wordfence
608d46e3-ef56-48b1-b965-b324e68e8a8b
< 2.3.4
HIGH 7.5 The Fraud Prevention For WooCommerce and EDD plugin for WordPress is vulnerable to unauthorized access due to a missing … wordfence
607073ad-3a4a-4a21-af0f-3ade81382605
< 1.5.4
HIGH 7.5 The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensit… wordfence
603f0c9d-6964-4911-b4a5-bdad24a1a8dd HIGH 7.5 The Kiwiz - Certification de facturation - Woocommerce plugin for WordPress is vulnerable to unauthenticated arbitrary f… wordfence
← Prev 306 307 308 309 310 311 312 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top