πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 317 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4209eddd-47ac-4802-b309-e42e5907a0cd
< 2.5
HIGH 7.5 The Echelon Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This is … wordfence
41e2dd3e-8e50-4f55-aa35-ff9d16e63a05
< 4.5.4
HIGH 7.5 The RH - Real Estate WordPress Theme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and in… wordfence
41d7b3f1-a133-4678-b2d9-3f9951cbc005
< 1.4.0
HIGH 7.5 The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object… wordfence
4192f1eb-e52a-4b79-8795-ef79c687e9ae
< 1.2.4
HIGH 7.5 The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to SQL Injection in versi… wordfence
416ab7d5-9f3b-4ccc-9a0f-bfe5d38b6f97 HIGH 7.5 The KenBurner Slider plugin for WordPress is vulnerable to Path Traversal in all versions via the kbslider_show_image fu… wordfence
4143635d-00f0-4065-8670-5962d87940ee
< 2.0.0
HIGH 7.5 The Download Manager Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… wordfence
412d555c-9bbd-42f5-8020-ccfc18755a79
< 5.0.4
HIGH 7.5 The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3… wordfence
4107362f-ae21-4509-b83a-0bffbde23330
< 4.1.3
HIGH 7.5 The GDPR Cookie Consent plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… wordfence
40e2e8fb-ea36-4602-bead-8daf75d6dfb9
< 2.5
HIGH 7.5 The Ultimate GDPR & CCPA plugin for WordPress is vulnerable to unauthenticated settings import and export via the export… wordfence
40e09aec-48af-4bf9-9254-b34bad7008c3
< 1.1.6
HIGH 7.5 The Easy Photo Album plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.1… wordfence
407d8ebe-f3fc-433a-856f-de2ad4e58b9e
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
407351fe-4148-4872-9a18-f05de0d5075b
< 3.3.0
HIGH 7.5 The JobSearch WP Job Board plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.9 d… wordfence
3f80902e-edc8-4cac-a50d-6332fef35356
< 7.6
HIGH 7.5 The Super Store Finder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.5 due to … wordfence
3f4893b9-e032-45d6-a542-0ead70c61e2f
< 0.14.11
HIGH 7.5 The webp-express plugin before 0.14.11 for WordPress has insufficient protection against arbitrary file reading. wordfence
3f389cbf-a327-46a1-9fb7-ed393212033a
< 3.0
HIGH 7.5 WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, w… wordfence
3f36839b-850e-4c39-aa61-4fd7a89cd5bc
< 7.4
HIGH 7.5 The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sens… wordfence
3f244b8e-94ae-4d95-83a7-53b826e98656
< 1.2.2.38
HIGH 7.5 The WP Stripe Checkout plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
3ef98c6f-4243-46bf-8231-3c751473fff7
< 4.11.0
HIGH 7.5 The JupiterX Core plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.10.1 vi… wordfence
3ed92523-e0e4-4e2a-b727-325e8dff37d9
< 5.7.7
HIGH 7.5 The Eduma theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.7.6. This makes … wordfence
3e9672b1-6d00-45bc-91ef-0c5583b5306e
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due … wordfence
3e63ce97-40af-493d-9376-231a99d9bd58 HIGH 7.5 The Popup – MailChimp, GetResponse and ActiveCampaign Intergrations plugin for WordPress is vulnerable to SQL Injectio… wordfence
3e4da578-aa8d-40b4-98c7-3efef911f850
< 2.4.20
HIGH 7.5 The ad-inserter plugin before 2.4.20 for WordPress has path traversal. wordfence
3e0f0a0c-8ef8-419d-92bf-964166508ebc
< 1.4.110
HIGH 7.5 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to SQL Injection in versio… wordfence
3e0b66b9-2e33-41e0-a024-35574716c91d HIGH 7.5 The Downloable by American Osteopathic Association plugin for WordPress is vulnerable to Directory Traversal in all vers… wordfence
3debeffa-5cc3-4d13-aed8-72753a62d8fc
< 3.6.0
HIGH 7.5 The Real Estate 7 WordPress theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.9 d… wordfence
← Prev 314 315 316 317 318 319 320 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top