πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 314 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5214a399-21a4-4573-9840-1d5043781bc0
< 1.6.9.13
HIGH 7.5 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to b… wordfence
51b0c1e5-08f7-44b3-8518-6b0902b84758 HIGH 7.5 The Ebook Downloader plugin for WordPress is vulnerable to SQL Injection via the 'download' parameter in all versions up… wordfence
515a6a42-f353-47ae-9e74-4f9b2000bcb8
< 3.2
HIGH 7.5 The WP ULike plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wp_ulik… wordfence
51381ef9-7fac-4a1a-8c39-6a32f87ea5d5
< 1.4.3
HIGH 7.5 The Consulting Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
50d1b8f6-8b60-4c49-a41c-4d5e0df2e7e2
< 9.6.1
HIGH 7.5 The XStore theme for WordPress is vulnerable to Local File Inclusion in versions up to 9.6.1. This makes it possible for… wordfence
509a40d2-a33a-49ba-b858-fa8805127a1b
< 6.3.8
HIGH 7.5 The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization… wordfence
504fca80-7e81-412b-891f-2679451ff6e6 HIGH 7.5 The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI. wordfence
502cf45c-1350-4534-a806-6e248912ef6d HIGH 7.5 The Floating Tweets plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 1.0.1 vi… wordfence
50192909-9351-4cf5-b578-f34be72aeda6 HIGH 7.5 The Revy plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.18 due to insufficient … wordfence
4fce3965-3b91-4d19-ac58-2b5475d59c35
< 2.5.2
HIGH 7.5 The WP Multistore Locator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.1 du… wordfence
4f69c239-d429-4970-bc1b-b2a7d96f4b7a
< 5.11.1
HIGH 7.5 The TheGem Theme Elements (for Elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, … wordfence
4f4a7933-7e93-4d8e-a51a-57ab63e26644 HIGH 7.5 The EduMall theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.4.7. This make… wordfence
4eea120e-839e-4b01-a5a8-af21f5ab99f5
< 2.2.4
HIGH 7.5 The CarSpot – Dealership Wordpress Classified Theme for WordPress is vulnerable to Insecure Direct Object References i… wordfence
4ede9023-732d-43e4-9c19-7cf704c95c29
< 1.9.5.6
HIGH 7.5 participants-database.php in the Participants Database plugin 1.9.5.5 and previous versions for WordPress has a time-bas… wordfence
4e88efe0-ffad-4d66-bb03-3f3a9dcbe5b1
< 2.3.16
HIGH 7.5 The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, … wordfence
4e72828e-a6f6-43fc-8a10-d9908004c0fc
< 5.0.21
HIGH 7.5 The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropsh… wordfence
4e534021-1c63-4db9-914b-7f9b3b613087 HIGH 7.5 The WP Hide plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when updating t… wordfence
4e27137d-1120-4ca5-8560-bbd5a382222e HIGH 7.5 The Terms descriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
4e219891-7342-4dd9-ac4f-636a5058ecad HIGH 7.5 The Travel & Tours Meta Search plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3… wordfence
4dd7d751-961a-4167-bb4a-2bcd66fc3c46
< 4.5.2
HIGH 7.5 The Order Delivery Date for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… wordfence
4d19c023-4aa1-40ec-a87b-dcde945e7a2c
< 4.4.5
HIGH 7.5 The AWP Classifieds plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
4ccc2f0c-07d5-45a5-86ec-1e6b6c5a316d
< 8.3.2
HIGH 7.5 The WoodMart theme for WordPress is vulnerable to Local File Inclusion in versions up to 8.3.2. This makes it possible f… wordfence
4c9cbe99-699a-4812-a8ae-aefd2b1e2c00
< 3.9.16
HIGH 7.5 The WP Import Export WordPress plugin (both free and premium versions) is vulnerable to unauthenticated sensitive data d… wordfence
4c842ece-f4d4-4ba5-8676-da99994609d5
< 3.1.0
HIGH 7.5 The HiStudy - Online Courses & Education Template theme for WordPress is vulnerable to SQL Injection in all versions up … wordfence
4c716fd3-6297-4b3a-a796-65f68f2986cf
< 1.2.1
HIGH 7.5 The GeekyBot β€” Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to S… wordfence
← Prev 311 312 313 314 315 316 317 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top