🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 320 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3486c8c8-5402-4f94-a03d-bcdff07ad53f
< 2.0.0
HIGH 7.5 The Trust Payments Gateway for WooCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, an… wordfence
34618970-a4b6-456b-9d01-a09e7a977724
< 1.3.4
HIGH 7.5 The Exploit Scanner plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.3.3 v… wordfence
3443950f-1f94-4e0b-8906-1a9b9602a746
< 3.1.5
HIGH 7.5 The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including… wordfence
33699d52-fc94-4485-8db7-f75c65237a3f
< 1.1.1
HIGH 7.5 The Majestic Support plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.0 due to … wordfence
3340e02a-4280-4422-a666-379725efb902 HIGH 7.5 The WPSmartContracts plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.10 due to… wordfence
32f3dfe1-816a-486c-8996-cc340af51638
< 3.2.68
HIGH 7.5 The Cost Calculator Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.65… wordfence
32c99b96-4e89-41c0-b3d1-9c6d6537b4eb
< 1.7.5
HIGH 7.5 The FundEngine plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.4. This … wordfence
329aae11-a141-4c61-8198-1cd8e4e6bfea
< 2.8.0
HIGH 7.5 The Product Filter by WBW plugin for WordPress is vulnerable to time-based SQL Injection via the filtersDataBackend para… wordfence
3283f2b7-28a5-4c39-aeef-3237ecc57cf3
< 6.2.4
HIGH 7.5 WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrie… wordfence
32594284-a7ed-4f43-b0cf-dc0e561768c2
< 2.1.3
HIGH 7.5 The export/content.php exportarticle feature in the wordpress-mobile-pack plugin before 2.1.3 for WordPress allows remot… wordfence
324e3762-a55c-4693-9621-a228f5943837
< 4.8.3
HIGH 7.5 The Jobmonster theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.8.2. This m… wordfence
32346090-ef3e-4a42-b7e2-7f3b7a9221e0
< 3.1.24
HIGH 7.5 WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and… wordfence
31edd562-b015-403a-960b-8c2396e8104a
< 3.5.17.1
HIGH 7.5 The JetSearch plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.17 due to insuff… wordfence
31a54705-99e8-4e41-bf57-9365ab387228
< 2.2.0
HIGH 7.5 The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to… wordfence
31196bdf-2ddd-49ea-840d-8fd78611629e
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
31173691-28fb-46fd-a7da-28bf9c46e2bc
< 6.5.0.1
HIGH 7.5 The LiteSpeed Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl… wordfence
30a15a22-d6f3-4829-995d-7fa14d1db7a9
< 2.8.98
HIGH 7.5 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable t… wordfence
303fc526-ffaf-4266-a606-4d21ac4c295f
< 3.8.10.2
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.10.1 due to insu… wordfence
2fe8c203-e86f-4dee-8faa-06b0cae86bfc
< 5.1.2
HIGH 7.5 The Church Admin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.1 due to insu… wordfence
2fa5ae9a-532c-40f9-b70a-217f0f9cd473
< 1.13.19
HIGH 7.5 The Geo Mashup plugin for WordPress is vulnerable to Time-Based SQL Injection via the 'sort' parameter in all versions u… wordfence
2f80c3b9-5148-42eb-9137-9c538184cda3
< 3.0
HIGH 7.5 The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' p… wordfence
2f21139b-75ef-4631-b88d-23eebbdefee0 HIGH 7.5 The Cost Calculator WordPress plugin through 1.7 allows authenticated users (Contributor+ in versions < 1.5, and Admin+ … wordfence
2f085925-fe08-41a8-85c4-39309acf2a96
< 1.9.9.7.7
HIGH 7.5 The VibeBP plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.7.7 due to insufficient escaping … wordfence
2eafe150-2178-4355-88a8-67687bd446e4 HIGH 7.5 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability … wordfence
2e602223-8571-42e1-9b3f-e7cc51f8fa58
< 3.6.27
HIGH 7.5 The DirectoryPress – Business Directory And Classified Ad Listing plugin for WordPress is vulnerable to SQL Injection … wordfence
← Prev 317 318 319 320 321 322 323 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top