πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 318 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3d1e49cf-86ac-4368-800a-4e46f72c975d
< 1.2.20
HIGH 7.5 VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of t… wordfence
3d1cbf17-11ec-4de6-879f-9ca8d53f3e91 HIGH 7.5 The hb-audio-gallery-lite plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… wordfence
3d18099c-03e6-4a90-88ed-099451a221c0 HIGH 7.5 The Hub Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.0.8. This ma… wordfence
3c835763-a53f-4447-ac9d-39488535b5fd
< 5.3.1
HIGH 7.5 The Feed KuantoKusta for WooCommerce – Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and… wordfence
3c7d63fc-288b-4f2f-85cd-e94add07a536
< 4.2.11
HIGH 7.5 The LTL Freight Quotes – Old Dominion Edition plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' an… wordfence
3c731e39-998e-44d2-8cf9-4d9c39731c5d
< 1.0.34
HIGH 7.5 The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a m… wordfence
3c3df9c2-b481-4233-9ad9-495efcdcb73d
< 3.5.10.1
HIGH 7.5 The JetSearch plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.10 due to insuff… wordfence
3bcd4675-e930-44d9-8278-c4c9e877656a
< 8.0
HIGH 7.5 The MP3 Sticky Player plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.… wordfence
3bcb60a8-220f-45a4-a9a9-10f64acf470c
< 4.89
HIGH 7.5 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via… wordfence
3ba84be8-c6dc-4cb7-b93c-38c69ab07154
< 1.2.1
HIGH 7.5 The WP REST API (WP API) plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including,… wordfence
3b8cfb2b-8f08-4d35-a3d9-ced734f7960e
< 4.5.7
HIGH 7.5 The Free Follow-Up Emails & Marketing Automation for WooCommerce – ShopMagic plugin for WordPress is vulnerable to Sen… wordfence
3b712d05-3369-41b6-9e68-8f2a8c5b477b
< 4.8.4
HIGH 7.5 The Noo JobMonster theme for WordPress is vulnerable to SQL Injection in versions up to 4.8.4 due to insufficient escapi… wordfence
3b3e2629-f50e-4d8f-9a9c-534fbe0ecb3a
< 20.8.10
HIGH 7.5 The Client Invoicing by Sprout Invoices plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
3b2074d3-f9ea-48c0-82f6-a515e41c6082 HIGH 7.5 The Goodlayers Hotel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.4 due to … wordfence
3b1b1a55-7872-456f-a754-023aad354359
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
3ad2651c-5541-4508-9da1-37838a4df901
< 4.0.32
HIGH 7.5 The Eventin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.0.31 via dese… wordfence
3ad075f5-189d-42c4-88d5-67aab321dfb6
< 2.0.9
HIGH 7.5 The Lumise Product Designer plugin for WordPress is vulnerable to SQL Injection in versions up to 2.0.9 due to insuffici… wordfence
3ac72d7a-9540-435f-93cb-fdd4104b18f7
< 1.7.7
HIGH 7.5 The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Arbitrary File Read in all ver… wordfence
3a4a97f1-f3da-45b4-98c9-f4afd5fa2eb1
< 3.5.2
HIGH 7.5 The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Local File Inclusion in versions u… wordfence
39f5777b-38b0-4fc6-909d-61eaa1de6173
< 1.4.4
HIGH 7.5 The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions… wordfence
39c17935-a853-407f-a99d-3828561919e6 HIGH 7.5 The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection… wordfence
396ba24f-e0f7-4374-a9ce-d9abddb87b39
< 12.7.3
HIGH 7.5 The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp… wordfence
3969e890-76e0-484a-ad16-6e2642e2ae53 HIGH 7.5 The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter. wordfence
38f950b7-e3a0-4e05-a8b0-9cc6b6c66b0c
< 2.1
HIGH 7.5 The security scanner that prevents XXE attacks in the XLSX reader can be bypassed by slightly modifying the XML structur… wordfence
38b27ee7-0e92-47ad-89f8-1a3c8d5c9442
< 2.5.1
HIGH 7.5 Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and … wordfence
← Prev 315 316 317 318 319 320 321 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top