πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 322 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
29532f4d-e830-4c99-ad77-076eebbbe98d
< 3.30
HIGH 7.5 The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unautho… wordfence
29482b70-0ff2-4bb1-9d41-9cffb83b5ad0
< 2.7.11
HIGH 7.5 The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10… wordfence
28df760b-6b15-41ca-b93f-9d24dbbd9fc4 HIGH 7.5 The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2… wordfence
28dc6608-8835-4a3c-8e28-b30a2887a2a1 HIGH 7.5 The Social Share And Social Locker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… wordfence
28ccfa60-10ad-47f5-b694-3b96857f8d22
< 3.5.8
HIGH 7.5 The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.… wordfence
28b87050-cd2e-4c9c-992d-892ba571908b HIGH 7.5 The Local Magic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.6.0 due to insuf… wordfence
28b730b3-4260-414f-8a4a-65ba5509449b
< 5.7.8
HIGH 7.5 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based bl… wordfence
28b5238d-5843-433f-b027-5139cc0a0c19 HIGH 7.5 The WPBookit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.0 due to insuffic… wordfence
284daad9-d31e-4d29-ac15-ba293ba9640d
< 1.7.3
HIGH 7.5 The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ… wordfence
27f7bfcc-b4bd-45d0-b75d-9d3264a173c7 HIGH 7.5 The Ajax Rating with Custom Login plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, … wordfence
27eea04f-3f5f-4f13-9553-4fdea9be865b
< 4.1.5
HIGH 7.5 exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct… wordfence
27e85966-0fc7-4a28-bfc2-af62a1a56d0a
< 5.0
HIGH 7.5 The Preserve Code Formatting plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
27a37c36-a2cf-4872-b1c4-f8bf61e3de30
< 6.19.5
HIGH 7.5 The SeedProd Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to 6.19.5. This makes it poss… wordfence
278d7fa3-4ff5-4919-b9a4-e0149e9cae22
< 5.5.0
HIGH 7.5 The Kleo theme for WordPress is vulnerable to Local File Inclusion in versions up to 5.5.0. This makes it possible for a… wordfence
272c824a-0883-4c23-a814-bf0db3fec8a6 HIGH 7.5 The Grou Random Image Widget plugin for WordPress is vulnerable to Full Path Disclosure via the 'g-random-img.php' file.… wordfence
27288836-e5d3-49fc-b1f6-319ea3b70839
< 1.8.7
HIGH 7.5 The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation… wordfence
2611005b-9d7f-4f43-95e4-eb47d2af611b HIGH 7.5 The Tech Life CPT plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 16.4 via … wordfence
25cb57fb-4af5-4f12-a01c-7ffdd8f84219
< 3.4
HIGH 7.5 The inFocus Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 3.3. This is … wordfence
25b93c52-6e91-452c-9cca-f49af97b4e56 HIGH 7.5 The KittyCatfish plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2 due to insuff… wordfence
25a3ec45-aa45-4ffc-be7e-f47100ac4626 HIGH 7.5 The Recover abandoned cart for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… wordfence
258877a7-670c-4a3c-8107-47dc7ba6a5ed HIGH 7.5 The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via several parameters ac… wordfence
25128675-665e-4608-b7a2-5378b0fe8a2c HIGH 7.5 The Bus Ticket Booking with Seat Reservation for WooCommerce plugin for WordPress is vulnerable to SQL Injection in vers… wordfence
250788a8-55d1-416b-bf1c-2170e8483ccc
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
24c78d62-c2d0-4699-bd80-e8deef301eb3
< 1.0.6
HIGH 7.5 The CP Image Store with Slideshow plugin for WordPress is vulnerable to Directory Traversal in versions before 1.0.6 via… wordfence
24c54ef5-ad02-4767-bca6-f74c539d3068
< 6.3.2
HIGH 7.5 The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information … wordfence
← Prev 319 320 321 322 323 324 325 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top