🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 316 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
47687614-bd79-44fd-bc82-eaa801c1387d
< 2.3.1
HIGH 7.5 The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the … wordfence
46e64a82-4d3f-4887-9c03-3285a6ddefb7
< 1.15.38
HIGH 7.5 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL I… wordfence
46b8fac7-fb18-40c8-ab23-d2c14fcf3ac5
< 1.1.0
HIGH 7.5 The Active Products Tables for WooCommerce. Use constructor to create tables  plugin for WordPress is vulnerable to SQL… wordfence
469bf5c9-984e-4107-a8a2-da744a78b8b2
< 1.4.4
HIGH 7.5 The Cimy User Manager plugin for WordPress is vulnerable to Directory Traversal in versions before 1.4.4 via the 'cimy_u… wordfence
468be776-8804-4d2f-8eaf-841bbf598ef9
< 1.3.6
HIGH 7.5 The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne… wordfence
467dd833-2f47-43cd-8d13-dffdad394b3c HIGH 7.5 The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and includ… wordfence
46776cd5-5262-46ea-b56c-0cbf2b9ae43d
< 2.0.1
HIGH 7.5 The Catch Dark Mode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0… wordfence
46438bd3-7c4a-4939-ab46-05dc8bbe461f
< 6.5
HIGH 7.5 mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htacce… wordfence
463da3d5-f2ec-4cf5-a545-c4ea7b8e7fb3
< 3.1.3
HIGH 7.5 The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… wordfence
462606da-34a5-400c-93e8-84c16f71d7e4
< 4.1.4
HIGH 7.5 The Advanced Reporting & Statistics for WooCommerce – Orders, Products & Customers Reporting plugin for WordPress is v… wordfence
45dbcc5e-2746-4a55-a1d1-a7c67fa2950e
< 4.0.4
HIGH 7.5 The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorizatio… wordfence
45527d6c-6866-44e6-85c2-5be984afbbc9
< 5.1.8
HIGH 7.5 The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i… wordfence
44fad31c-6bf7-49c1-a03b-5cda0b26b38f HIGH 7.5 The Woocommerce Quote Calculator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… wordfence
44e3158c-6163-4780-a1d5-ca101ba92074 HIGH 7.5 The Page Flip Image Gallery plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, … wordfence
44210443-26f8-4626-aee2-4a19d87fdd43
< 2.3.1
HIGH 7.5 The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the … wordfence
43ca1393-637d-48e2-84f3-a06a4f0d83d1 HIGH 7.5 The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versi… wordfence
43c7056e-39d8-467e-92ec-33a31e5dafc9
< 2.5.2
HIGH 7.5 The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing … wordfence
43110773-0eba-41dd-adbf-0e21cb69058e HIGH 7.5 The Strategery Migrations plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and inclu… wordfence
42ecfca7-d285-4f14-8389-966b7b6320e7
< 3.11.6
HIGH 7.5 The YMC Filter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.11.5 due to insuf… wordfence
42dd84ea-5d34-465b-bc62-6fa57dc85056 HIGH 7.5 The Mac Photo Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.… wordfence
42acc6e4-ceee-4551-bca4-4f8d0a958eef
< 1.6.12.11
HIGH 7.5 The Simply Schedule Appointments plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… wordfence
42690e4e-e0d5-492c-879b-a16383fe7af3 HIGH 7.5 The Nestbyte Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to insuf… wordfence
424a30d7-4806-4274-8c5e-75dcc12e9f3c HIGH 7.5 Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to… wordfence
4240cdae-9122-443e-8a7e-3369e74384be
< 3.13.3
HIGH 7.5 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct O… wordfence
4223cc80-377d-45a5-8c79-c8f0aa52c01e HIGH 7.5 The Zegen theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9. This makes … wordfence
← Prev 313 314 315 316 317 318 319 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top