πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 313 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5536905a-8036-4d9a-a28b-fbd7ae689751 HIGH 7.5 The Laurent Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.1. Thi… wordfence
55315ba1-cbb8-4ce1-96c6-30a02611ba47 HIGH 7.5 The Woocommerce Category and Products Accordion Panel plugin for WordPress is vulnerable to Local File Inclusion in all … wordfence
54db4d53-7c4f-47d9-811d-8282eaf2d074
< 1.2.0
HIGH 7.5 The ChatBot Conversational Forms plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, an… wordfence
547a0c73-044e-49ba-9bec-4f80b41b8ea2
< 1.0.9
HIGH 7.5 The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,… wordfence
54756a32-de66-43e4-9596-c55aaf77fd4e HIGH 7.5 The Freeio theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.21. This make… wordfence
544f71f5-1798-40fd-9f55-c25dae4f557a
< 6.24.11.07
HIGH 7.5 The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.… wordfence
5435a8f8-deb7-48c9-9b86-64265e97d602
< 5.7
HIGH 7.5 The Cargo Shipping Location for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and i… wordfence
542b7919-2d59-4f1a-b69e-59977ac8353e HIGH 7.5 The Modal Survey plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.2.0.1 due to … wordfence
54043c6a-48a1-48e8-ba61-a7e8a1773036
< 2.4.7
HIGH 7.5 The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in al… wordfence
53ee7062-85f9-4d12-a432-f373fc25bab6
< 5.5.71
HIGH 7.5 The WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards plugin for WordPress is vulnerable to SQ… wordfence
53c18834-3026-4d4d-888b-add314a0e56e
< 3.6.5
HIGH 7.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'v… wordfence
5394abc6-836f-4b22-a7b6-79d092b93a7e
< 10.1
HIGH 7.5 The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in al… wordfence
5385ffa7-045b-4ed8-b1d1-eed8924eeb9b HIGH 7.5 The All in one Minifier plugin for WordPress is vulnerable to SQL Injection via the 'post_id' parameter in all versions … wordfence
5367ca36-e3e0-4bb3-8148-4e7623d35315 HIGH 7.5 The Airtifact theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.91. This m… wordfence
535d3934-6117-46ee-87b8-fbefb58ba272
< 6.1.6
HIGH 7.5 The JS Archive List plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.1.5 due … wordfence
52c94317-862f-45e5-8cf8-0fa82aa43d49
< 2.2.6
HIGH 7.5 The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to… wordfence
52bb3328-956c-4379-879a-d321d68c39ee
< 1.22.16
HIGH 7.5 Stored Cross-Site Scripting (XSS) vulnerabilities in the Team Showcase plugin before 1.22.16 for WordPress allow remote … wordfence
52943f74-d0a6-43d2-a8e6-d9fd90925b3e HIGH 7.5 The FREE DOWNLOAD MANAGER plugin for WordPress is vulnerable to Arbitrary File Downloads in all versions up to, and incl… wordfence
52719839-9e92-4de6-8f0d-8ee3f3fe00b0 HIGH 7.5 The SportsPress Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.29.… wordfence
526aa14e-42b8-4db4-96a8-6ecc2475ad7f
< 2.1.0
HIGH 7.5 The Subscribe to Download plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2… wordfence
526837cc-ed1d-4d3d-8f75-a2098445dd1d
< 3.0.0
HIGH 7.5 The SEO Flow by LupsOnline plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa… wordfence
5263fa58-18d2-49a2-bc5b-3d3fd3cd1377
< 3.9.001
HIGH 7.5 The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attac… wordfence
5247bf43-ae02-47cb-825e-23821b78eba9
< 1.0.18
HIGH 7.5 The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing… wordfence
5231e229-ba82-40ea-b3c1-9ce159a9d128 HIGH 7.5 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… wordfence
522707e5-dadb-476f-9402-2ccb4f4681f4 HIGH 7.5 The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to… wordfence
← Prev 310 311 312 313 314 315 316 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top