πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 321 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2e5eee1d-4e0a-4ec2-93ff-86f0b3942ae2
< 2.7.8
HIGH 7.5 The Multi Step for Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.… wordfence
2e41eaf6-bb59-41a5-9c19-c119528287e9
< 3.8.16
HIGH 7.5 The Easy Form Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.15 due t… wordfence
2e3e3b0d-21cb-4b19-ba14-580b3d2802ab HIGH 7.5 The Testimonial Slider plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.5.… wordfence
2dfeeff5-5fcf-445b-af66-33ec873b7e44
< 2.9.0
HIGH 7.5 The Email Verification for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
2db0b8c9-7908-484d-9a02-1c50f88efdd0
< 2.2.4
HIGH 7.5 The LTL Freight Quotes – Purolator Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_… wordfence
2d6e3a66-4c25-485b-ad49-7ab083a59dd2 HIGH 7.5 The Constant Contact for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and… wordfence
2d49fa2d-0625-40a4-b3dd-13679b806bc1
< 1.1
HIGH 7.5 The AntiVirus plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 1.0 via th… wordfence
2d044e0a-a956-4319-985d-6a9a276daf49 HIGH 7.5 The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss… wordfence
2cde1f4d-0212-48b1-a0ef-ba923c37ab50
< 3.1.25
HIGH 7.5 Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files w… wordfence
2cd53590-ded1-4e68-a9a3-aa1d2d880b80 HIGH 7.5 The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/… wordfence
2cc737b3-4072-4dd4-8e50-ec94dc2a17d5
< 2.6
HIGH 7.5 Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attack… wordfence
2ca30fef-a014-4d19-b9f8-c51db512795b HIGH 7.5 The "WP Intercom - Slack for WordPress" plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to,… wordfence
2c0082ff-2a33-44e9-b0d0-8b9a404ab648
< 2.6.5
HIGH 7.5 The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 vi… wordfence
2bc5451c-c43e-4286-8a72-5bb41cfdc064 HIGH 7.5 The Slider Responsive Slideshow – Image slider, Gallery slideshow plugin for WordPress is vulnerable to PHP Object Inj… wordfence
2bb1aadd-5a7d-4a0c-8e5e-9ba7024e9c55
< 3.2.6
HIGH 7.5 The Shopper plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.5 due to insuffici… wordfence
2ba4a8bb-c67c-42c5-8c4e-229756babc5f
< 1.2.0
HIGH 7.5 The Multi Plugin Installer plugin for WordPress is vulnerable to Arbitrary File Read in versions before 1.2.0. This is d… wordfence
2b8da4db-65f4-4c94-91c9-186d3abb7d51
< 2.0.0
HIGH 7.5 The HieCOR Payment Gateway Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
2affce7c-6c59-4a50-ab26-5da2e18120d7
< 1.4.7
HIGH 7.5 The Medilazar Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to 1.4.7. This makes it pos… wordfence
2afe77cc-88f5-4778-893a-26517bd520cb
< 4.0.7
HIGH 7.5 The Easy Form Builder by WhiteStudio β€” Drag & Drop Form Builder plugin for WordPress is vulnerable to SQL Injection in… wordfence
2ad47937-8125-405c-9fd3-9b3b210942fa HIGH 7.5 The ThemeMakers GamesTheme Premium theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive in… wordfence
2ac3ffcf-50e0-42fc-a88d-cd7a51fbe1a9
< 1.5.7
HIGH 7.5 The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to Sens… wordfence
2a99a21c-d4f1-4cdb-b1f1-31b3cf666b80
< 5.6.1
HIGH 7.5 The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi… wordfence
2a06dc0d-f002-4f82-b380-0e329b022dc9 HIGH 7.5 An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../… wordfence
29a5701f-92f7-4a02-a990-b189a381cff5
< 3.8.6.2
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endp… wordfence
2959c04a-70bd-4f5c-a61a-1eab2609f8ef
< 3.0.5
HIGH 7.5 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `… wordfence
← Prev 318 319 320 321 322 323 324 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top