πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 312 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
58e84d8f-a091-493f-8e5d-52c1ad5afcdb
< 2.5
HIGH 7.5 The Elegance Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.4. This is… wordfence
58dfc436-7ef9-4e1e-9cf2-e5da264f7959
< 3.2.11
HIGH 7.5 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is v… wordfence
58754a10-1914-48ce-87b1-3ca566f4e894
< 15.9.5
HIGH 7.5 The Simple Business Directory Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
5850cd12-0a50-4a69-a6bb-8d2d62a28699 HIGH 7.5 The Easy Pricing Table WP plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1… wordfence
5835fed0-5b9d-47b5-82ae-f0f19830ae2a
< 2.3.3
HIGH 7.5 The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.2… wordfence
581792f3-7b57-418c-802b-2ff04f5b83bf HIGH 7.5 The WordPress RokBox plugin is vulnerable to Full Path Disclosure in versions up to, and including, 2.13 via the 'rokbox… wordfence
58063939-5d44-4369-a0f6-c7f1b0271c44
< 4.4.8
HIGH 7.5 The AWP Classifieds plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.4.7 due to i… wordfence
57ea02c2-4399-46d7-b17e-9dcefb7576e8
< 2.0.4
HIGH 7.5 The Salesmate Add-On for Gravity Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
579b6eb0-dbb7-4586-aecc-f295889a2b2b
< 1.5.5
HIGH 7.5 The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions u… wordfence
5797e529-5109-49bf-a687-e5bf8f350c8f
< 1.1.23
HIGH 7.5 The OttoKit: All-in-One Automation Platform plugin for WordPress is vulnerable to SQL Injection in versions up to 1.1.23… wordfence
57888e36-3a61-4452-b4ea-9db9e422dc2d
< 1.0.4
HIGH 7.5 The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inc… wordfence
5783824c-af02-4606-87c6-b58127445230 HIGH 7.5 The VEDA theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.2 via deserializa… wordfence
575d1e24-d23d-4589-bb71-f52efec1ac58
< 1.1.6
HIGH 7.5 The MIPL WC Multisite Sync plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin… wordfence
5749a496-930a-4e31-968e-0c2a72e03555
< 7.7.0
HIGH 7.5 The iThemes Security (formerly Better WP Security) plugin before 7.7.0 for WordPress does not enforce a new-password req… wordfence
573968ec-b4c6-40ec-b75d-f6c92b29763b
< 1.81.282
HIGH 7.5 The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to SQL Injection in versions… wordfence
572f55af-bef6-4cb9-9c6b-741262710c91 HIGH 7.5 The Simple Backup plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.7.11… wordfence
56e3ca66-53c7-4b0c-9a08-0d013c399cb4 HIGH 7.5 The WordPress Local SEO plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.3 du… wordfence
56e3779e-c1e5-46f3-9110-d39587a2f8b8
< 18.7
HIGH 7.5 The Automotive Listings plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 18.6 due t… wordfence
569f1cd4-195b-41d4-85cb-f529a1eb18d4 HIGH 7.5 The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4… wordfence
568254a4-400d-45ea-8a96-1669b0694d70 HIGH 7.5 The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads… wordfence
563b1b9e-260d-4cbc-9479-ad42bcef5012 HIGH 7.5 The Cinerama - A WordPress Theme for Movie Studios and Filmmakers theme for WordPress is vulnerable to Local File Inclus… wordfence
561f171e-f13e-408b-a63e-bf6a512d4463
< 0.1.18
HIGH 7.5 The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0… wordfence
561361da-ea4b-44d0-be77-c622af11f5b4
< 9.85
HIGH 7.5 The Media from FTP Plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 9.84 via … wordfence
55b75c83-2b1d-4870-b5df-74ba50102d2e
< 2.7.2
HIGH 7.5 The Unicamp theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.1. This make… wordfence
5548b97d-14f0-4f50-b213-a19c02c240be HIGH 7.5 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In… wordfence
← Prev 309 310 311 312 313 314 315 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top