🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 323 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
24b319e6-1903-44a9-9f69-0e5ebe891870 HIGH 7.5 The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter. wordfence
24902fab-44ea-44c9-bcf5-70960cfeb402
< 3.14.1
HIGH 7.5 The Ninja Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… wordfence
2480091f-2b5d-440c-9617-934d097b3a63
< 3.4
HIGH 7.5 The InFocus Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 3.3. This is … wordfence
247b1921-70a6-4e65-819a-2895bc395e9f
< 1.4.19
HIGH 7.5 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all… wordfence
245e9117-ca63-458e-a094-60a759f5ec19
< 0.0.5
HIGH 7.5 The Getnet Argentina para Woocommerce plugin for WordPress is vulnerable to authorization bypass due to missing validati… wordfence
242b274d-a922-4db5-ac7a-b74cbf8212da
< 1.6.4
HIGH 7.5 The Nest Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.3 due to insuf… wordfence
242819d5-0cc5-463f-984a-8e70e032bfe4
< 3.0.10
HIGH 7.5 The Exhibz theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.0.9. This makes… wordfence
24225f47-cec2-4270-88f0-8696ebfb7168 HIGH 7.5 The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed… wordfence
241d9cd3-9331-49b2-8083-dc646070488e
< 1.1.0
HIGH 7.5 The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve… wordfence
2403dd59-7b9e-490e-86d8-5a10f9eee616
< 3.6.5
HIGH 7.5 The LTL Freight Quotes – TForce Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id'… wordfence
23bcd8b4-04c9-4b7e-b114-70f2675ca2bd
< 1.5
HIGH 7.5 The Multiple Shipping And Billing Address For Woocommerce plugin for WordPress is vulnerable to SQL Injection in version… wordfence
22c6f81b-d456-44b9-ba6c-8b207a9ee6e1 HIGH 7.5 The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 … wordfence
22be5fb5-143e-4934-9f93-e17def18e883
< 7.8.9.3
HIGH 7.5 The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file upl… wordfence
22b55747-8b46-4812-9345-0db03500105f
< 3.15.2
HIGH 7.5 The Avada Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘product_order’ parameter i… wordfence
2295b532-7833-4f5d-9778-de26390b04bd
< 3.7
HIGH 7.5 The Protect WP Admin WordPress plugin before 3.7 does not check for authorisation in the lib/pwa-deactivate.php file, wh… wordfence
2263d356-b2ed-4e16-98ee-b01d4274d1d9
< 2.5.1
HIGH 7.5 The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d… wordfence
2240b2d3-b4cc-445f-b207-0ccbd527a0f3
< 1.26
HIGH 7.5 The RokStories plugin for WordPress is vulnerable to Full Path Disclosure in versions up to, and including, 1.25 via the… wordfence
221dab8e-2f8d-47d7-b9f5-a2f0d4edcef7
< 4.9.3
HIGH 7.5 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulne… wordfence
21cf5a39-831b-4423-b901-98bf15416fc8
< 2.0.0
HIGH 7.5 NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability. wordfence
21cd8cb8-2a29-4b66-ab7a-8d8b2f85e2e0
< 5.26.6
HIGH 7.5 The Event Tickets and Registration plugin for WordPress is vulnerable to payment bypass in all versions up to, and inclu… wordfence
2187311d-6651-4eca-806d-aa2ff9fae4e2
< 2.145.1
HIGH 7.5 The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an auth… wordfence
213fde1b-13dc-442a-8f48-4b1074155a6f
< 19.1.5
HIGH 7.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due t… wordfence
212ee91a-9713-4a1a-ac55-742a89eb2704
< 1.6.27
HIGH 7.5 The Riode Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.26 due to insuf… wordfence
20b9dcd9-d87d-46ef-82b1-30743fcdc909
< 3.1
HIGH 7.5 The Kentha Elementor Widgets plugin for WordPress is vulnerable to Local File Inclusion in versions up to 3.1. This make… wordfence
2049712a-6ff2-4e2a-98f8-93a493a5bfd3
< 8.41
HIGH 7.5 The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8… wordfence
← Prev 320 321 322 323 324 325 326 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top