πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 311 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5c0f3248-fef6-48a5-b2e1-f2778528fba1
< 3.9.30
HIGH 7.5 The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
5c0f02ad-f5f1-42b1-8116-e391aaa85430
< 3.7.1
HIGH 7.5 The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_… wordfence
5c03c07f-8f41-47c2-bc95-d92a623f5f7c
< 2.10.5
HIGH 7.5 The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4… wordfence
5be9d0ff-5d9c-4e80-a4d7-66ef4859a959
< 1.9.8
HIGH 7.5 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
5bcf1f02-0946-4e96-a81b-00c7c48d64b3 HIGH 7.5 The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… wordfence
5bae7516-e9dd-4c0c-b687-9cbe09b4c8bc
< 1.0
HIGH 7.5 Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress… wordfence
5baa15a6-c2c5-412d-a065-f13d431df4a5 HIGH 7.5 The Woodly Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due to insuffi… wordfence
5b9e037d-30bd-479b-9c4f-4c9082a04e08
< 1.5
HIGH 7.5 The Construct Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.4. This i… wordfence
5b9a0751-934f-4830-80c9-39260ec1cb4f
< 1.8.13
HIGH 7.5 An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially… wordfence
5b8fb306-cb48-4667-b2b5-e5014ef485e2 HIGH 7.5 The Print Science Designer plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.… wordfence
5b826595-c977-4550-aa52-93bcd4a365fe HIGH 7.5 The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts… wordfence
5b23bd5c-db27-4d63-8461-1f36958a2ff6 HIGH 7.5 The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the… wordfence
5b1b0dbd-084a-44e5-b711-1d5bafb0a300 HIGH 7.5 Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote a… wordfence
5b050546-fe37-4c3b-a9e4-46a65f19e64d
< 6.4.1
HIGH 7.5 The Elessi theme for WordPress is vulnerable to Local File Inclusion in versions up to 6.4.1. This makes it possible for… wordfence
5ae32a38-5be3-47d0-9c56-2fcda7662c71
< 2.29.0
HIGH 7.5 The AffiliateWP plugin for WordPress is vulnerable to SQL Injection via the ajax_get_affiliate_id_from_login function in… wordfence
5ac49a00-dabc-4cd9-9032-c038ede3fd8f
< 2.0
HIGH 7.5 The Bricks theme for WordPress is vulnerable to blind SQL Injection via the β€˜p’ parameter in all versions up to, and… wordfence
5a349c4f-d2e7-47af-9013-3cfa496b3b8c
< 2.5.6
HIGH 7.5 The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the… wordfence
59fe7630-ab94-419f-aca5-39b74d86ae4e
< 1.8.8
HIGH 7.5 The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is… wordfence
59ee0ca2-846d-4ae8-ad19-7c3826861aeb
< 2.13.3
HIGH 7.5 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
59da86c4-1a68-4077-8b56-9c6c8afe26ad
< 7.1.0
HIGH 7.5 The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via … wordfence
59b949ef-6ab2-4381-abf9-aa0c72b654c3 HIGH 7.5 The Kriya theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4 via deserializ… wordfence
5991c86b-6785-41a6-a5df-c65e8a28201c
< 1.9.180
HIGH 7.5 The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi… wordfence
5979f2eb-2ca8-4b06-814c-c4236bb81af0
< 2.12.4
HIGH 7.5 The Paid Memberships Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type vali… wordfence
5970b8d6-0041-4c30-a6ce-fe67ebf415f5
< 1.6.10.0
HIGH 7.5 The Appointment Booking Calendar β€” Simply Schedule Appointments plugin for WordPress is vulnerable to unauthorized acc… wordfence
5900d571-dc97-4c81-8ff3-7d7350b4c89f
< 1.9
HIGH 7.5 The RokIntroScroller plugin for WordPress is vulnerable to Full Path Disclosure via the 'src' parameter in the 'thumb.ph… wordfence
← Prev 308 309 310 311 312 313 314 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top