πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 319 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
38826657-ee20-4743-baef-de735a01f4d5
< 10.11.1
HIGH 7.5 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
387f7ee0-6b1e-4862-8270-dbb3aee70a7e
< 3.1.0
HIGH 7.5 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection in versio… wordfence
38672a45-b7a7-445f-9e77-7050df6920fa
< 1.7
HIGH 7.5 The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is… wordfence
3852cdf8-70f7-4eba-9083-def6e5299043 HIGH 7.5 The Neon Product Designer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 du… wordfence
38391221-c435-4672-809a-ebabf639c9bb HIGH 7.5 The Spirit Framework plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.… wordfence
37e84cab-746a-4b64-b9a1-7232584d1f19 HIGH 7.5 The Woocommerce Product Design plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… wordfence
37d13a43-13f4-460d-b5ea-5def8a379d54
< 4.3
HIGH 7.5 The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?a… wordfence
3776c594-5c67-4331-a95b-051fc58b214e
< 6.5.1
HIGH 7.5 The PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection … wordfence
375aab8b-d46b-48b1-874b-0fb7136cb312 HIGH 7.5 The WOOEXIM – WooCommerce Export Import Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versi… wordfence
37053b53-8308-4e54-99c2-7616ed8cb379
< 9.0
HIGH 7.5 The Email Newsletter for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 8.0. This … wordfence
36dec90a-fead-48f5-a88b-dfbc6d8bffb4
< 2.3.12
HIGH 7.5 The NotificationX plugin for WordPress is vulnerable to generic SQL Injection via the β€˜id’ parameter found within th… wordfence
36daf2af-1db3-4b35-8849-480212660b2f
< 2.0.1
HIGH 7.5 The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions … wordfence
36d3dae0-4705-487a-a4a4-c12280e866a3 HIGH 7.5 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads via the 'dl' parameter found… wordfence
36629099-eb8d-4ddb-ba85-e1506262e245 HIGH 7.5 The Triply theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.7. This makes… wordfence
36615cae-418f-48b0-ba69-b54515cbe1d7
< 2.5.3
HIGH 7.5 The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … wordfence
35e33e30-e102-445a-99d0-27adb7fc4638
< 4.0.3.1
HIGH 7.5 The JetBooking plugin for WordPress is vulnerable to SQL Injection via the 'check_in_date' parameter in all versions up … wordfence
35c12f80-d069-44ed-b6a5-caa060fbd281
< 2.4
HIGH 7.5 Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem… wordfence
35acdb85-e463-46b1-aea7-a6d4c3581499
< 3.4
HIGH 7.5 The Advance Seat Reservation Management for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'pro… wordfence
35a55336-2cd1-41a8-b9ef-09ab4a8dd632
< 8.0.2
HIGH 7.5 The ActivityPub plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to 8.0.2 (exclus… wordfence
359b596e-1973-4bf6-a012-84b422c0f2c1
< 2.6.91
HIGH 7.5 The Customizable WordPress Gallery Plugin – Modula Image Gallery plugin for WordPress is vulnerable to authorization b… wordfence
355d6e61-a45b-4682-bfad-77df18ae79f4
< 1.55.1
HIGH 7.5 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Director… wordfence
3528acaa-0068-4476-82d7-fe7d68a55743 HIGH 7.5 The Brook - Agency Business Creative WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versio… wordfence
351a035a-9768-4efd-9887-e0905e129634
< 1.2.1
HIGH 7.5 The GeekyBot β€” AI Copilot, Chatbot, WooCommerce Lead Gen & Zero-Prompt Content plugin for WordPress is vulnerable to S… wordfence
34f8d60e-01c8-40d6-b655-1dce127b607c HIGH 7.5 The Multiple Carousel plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0 due … wordfence
34adbae5-d615-4f8d-a845-6741d897f06c
< 2.10.1
HIGH 7.5 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plu… wordfence
← Prev 316 317 318 319 320 321 322 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top