πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 315 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4c4d5902-2d01-4e8f-8d98-65e7be32f5c0
< 3.1.5
HIGH 7.5 The WP-BusinessDirectory plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4 due… wordfence
4c447dbb-f8fb-4b46-9c47-20ab7330bbaa
< 2.4.15
HIGH 7.5 The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version… wordfence
4bfa2246-41a8-4d06-8dc9-57fc4be8e1c4
< 1.0.9
HIGH 7.5 The IMDB Profile Widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to 1.0.9 via the 'url'… wordfence
4beafd91-1b89-484b-8053-b1bffdaf163a
< 2.0
HIGH 7.5 The Aspose.Words – Import and Export word documents plugin for WordPress is vulnerable to Arbitrary File Download in v… wordfence
4b9a325d-1291-458a-aa6c-f2ee55b3b6cd
< 3.0.5
HIGH 7.5 The Graphina plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.4. T… wordfence
4b800842-f757-4e1c-8c93-ef21f90a11c7
< 3.6.0
HIGH 7.5 The SSL Wireless SMS Notification plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
4b34dd60-359c-44a0-9e47-dc8c4e66b50e
< 0.9.4
HIGH 7.5 The script pub/sns.php in the W3 Total Cache plugin (versions 0.9.2.6 through 0.9.3) allows remote attackers to read arb… wordfence
4b15c991-5256-405c-8382-85dba6f032ba
< 2.0.3
HIGH 7.5 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all v… wordfence
4ac3dae6-1890-44ba-9671-84f77807ffe5
< 3.0.0
HIGH 7.5 The OneLogin SAML SSO for WordPress is vulnerable to DDoS in versions up to, and including, 2.8.0. This is due to an XML… wordfence
4ac18db7-324f-41f0-b03a-59635dd97d22 HIGH 7.5 The MinimogWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.6. This ma… wordfence
4aa8342f-1f36-4eb5-8b69-ab90fd85e5cb
< 1.4.5
HIGH 7.5 The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Inject… wordfence
4a1a4186-216e-4ed1-860c-fe345ac6e62a
< 3.4.1
HIGH 7.5 includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary… wordfence
49fe8e8b-95fa-4c25-89cf-49566543206c
< 3.1.66
HIGH 7.5 The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in … wordfence
49b36cde-39d8-4a69-8d7c-7b850b76a7cd
< 3.6.2
HIGH 7.5 The Slider & Popup Builder by Depicter plugin for WordPress is vulnerable to generic SQL Injection via the β€˜s' paramet… wordfence
498f7ece-e33a-4489-aeb9-1660abe0b4a5
< 3.4
HIGH 7.5 The Awake Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.3. This is du… wordfence
4985680e-f7ba-40c7-bca9-f347f1c1cb3b
< 2.9.1
HIGH 7.5 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to SQL Injection via the 'lang' parameter in all versions… wordfence
497cfc87-85ac-41d0-aeea-63c5fc64db0d
< 4.1.2
HIGH 7.5 The Team - WordPress Team Member Showcase Plugin for WordPress is vulnerable to directory traversal via the 'resources/d… wordfence
492ce5d0-02b5-4b11-a4a0-ca1a6438faad
< 1.12.1
HIGH 7.5 The belingoGeo plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.0 vi… wordfence
48ebb9d6-05d5-4197-8fa4-cc7154c00669 HIGH 7.5 The Golo Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.3. T… wordfence
48cda7b8-edc8-4c2d-bef9-3ee12dc0ea32
< 12.8.1.1
HIGH 7.5 The The7 theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 12.8.1.1. This make… wordfence
488f1a2f-01c8-40cf-b52f-d707271105f5 HIGH 7.5 The External Login plugin for WordPress is vulnerable to SQL Injection via the 'log' parameter in all versions up to, an… wordfence
48715526-f423-40ce-8c7f-d7713c57ce36
< 5.9.2
HIGH 7.5 The Podlove Web Player plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9.… wordfence
48400e64-40b4-4f96-8346-1a104ae89761
< 4.2.0
HIGH 7.5 The Houzez Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and inclu… wordfence
47a00c6f-958f-41c7-a213-c858d8fac2ed
< 3.5.1
HIGH 7.5 The Stars Rating WordPress plugin before 3.5.1 does not validate the submitted rating, allowing submission of long integ… wordfence
4794858f-ebaf-4adf-ab08-309964c18c00
< 2.5.5
HIGH 7.5 A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and … wordfence
← Prev 312 313 314 315 316 317 318 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top