πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 310 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6038accc-98ac-496c-9c53-ec06b2045324 HIGH 7.5 The Outdoor plugin for WordPress is vulnerable to SQL Injection via the 'edit' action in all versions up to, and includi… wordfence
5fe86ce8-932c-4085-a4e2-023b7d26b718
< 1.2.3
HIGH 7.5 The Easy Quotes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.2 due to insuf… wordfence
5fc9ecf7-2802-433e-832b-731505c5cb9b
< 2.3.26
HIGH 7.5 The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… wordfence
5f788303-6bf1-4b41-b0f7-e0a2d03bba6e
< 27.8
HIGH 7.5 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to SQL Injection in v… wordfence
5f732a77-fa34-402f-8ab4-a4273b7e0b13
< 4.5.5
HIGH 7.5 The GEO my WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.4 due to insuffi… wordfence
5f4767b5-5dd6-4a2a-b44a-5297432286b1
< 2.1.5
HIGH 7.5 The Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers plugin for WordPr… wordfence
5f319613-2709-449c-9e13-b0f95ee0b88b
< 1.3
HIGH 7.5 Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote … wordfence
5f22d77e-e7c3-4239-bec7-668d7483bdb9
< 1.6.1
HIGH 7.5 The Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin for WordPress is vulnerable to … wordfence
5f094fff-04eb-4ea9-b847-4e2e589a96e1
< 4.8.126
HIGH 7.5 The Masterstudy theme for WordPress is vulnerable to Local File Inclusion in versions up to 4.8.126. This makes it possi… wordfence
5ed1978e-1dd7-45d3-829a-1a75c1789827 HIGH 7.5 The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via… wordfence
5eb21153-4c7f-4acc-b1da-6c0a61871db5
< 1.4.0
HIGH 7.5 The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to SQL Injec… wordfence
5e8e2cbf-0cb6-42d1-b653-d6f70eba1357 HIGH 7.5 The Leedo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.0. This makes … wordfence
5e6de586-5621-4eb2-8150-cb42562d289f
< 6.6.2
HIGH 7.5 The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam… wordfence
5e604ad1-c06e-4ec6-9eba-332a3c0b1ed1
< 7.5
HIGH 7.5 The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.2 due to … wordfence
5e51f301-026d-4ed7-82f8-96c1623bf95c
< 4.24.14
HIGH 7.5 The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2… wordfence
5e3b0a3a-ce4b-40fd-9519-a81e315cee42 HIGH 7.5 The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜code’ parameter in all versions … wordfence
5dd962a5-ec0e-415f-8efa-91e78bb80d16
< 4.9.9.3
HIGH 7.5 The Brooklyn theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.9.9.2 via… wordfence
5dbb3c7a-5d2e-4b8a-bf20-af78730c4b02
< 1.7.0
HIGH 7.5 The immonex Kickstart Team plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
5d8961fd-68ac-4a10-ab26-cfcda27c18e8
< 2.2.3
HIGH 7.5 The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
5d74e494-b5a0-4e44-8efe-9f904de6b878 HIGH 7.5 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via… wordfence
5d4ad020-0b40-456b-8f8c-597c7c4ef698
< 7.6.3
HIGH 7.5 The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to privilege escalation in all versions up … wordfence
5d080f5b-6646-47ef-8ae7-8b94270f9f59
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
5c55abc7-b09d-4fea-bc2f-b903d3da119f HIGH 7.5 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to time-based SQL Inj… wordfence
5c39fded-8b32-463f-9d22-adb371ca217e
< 1.1.9
HIGH 7.5 The ThemeMakers Car Dealer / Auto Dealer Responsive theme before 1.1.9 for WordPress allows remote attackers to obtain s… wordfence
5c1dbf60-ef4b-49f3-badd-5e2260eb45ca
< 1.19.7
HIGH 7.5 The Shipping for Nova Poshta plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1… wordfence
← Prev 307 308 309 310 311 312 313 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top