πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 324 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
20140f76-b369-4191-bfd1-0f508112ce0a HIGH 7.5 Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows … wordfence
1fa69450-cf44-42d2-80c8-a0fd6d669510
< 5.1
HIGH 7.5 The WooCommerce Coming Soon Product with Countdown plugin for WordPress is vulnerable to Local File Inclusion in version… wordfence
1f955d88-ab4c-4cf4-a23b-91119d412716
< 1.2.7
HIGH 7.5 The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versi… wordfence
1f90b93a-8f8f-4403-94dc-ae222622b96d HIGH 7.5 The Nuss theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.3 via deseriali… wordfence
1f8cca7b-c674-4d07-9ec2-9c9b9ebb492f HIGH 7.5 The Dental Clinic theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7 via de… wordfence
1f846ffa-0dfa-4549-845a-7884a390462a
< 3.7.28
HIGH 7.5 WordPress Core versions before 5.0.1 contain a CWE-20 Input Validation vulnerability in thumbnail processing that can re… wordfence
1f7f6713-a29d-429f-9882-3527da8d9b5b
< 2.1.4
HIGH 7.5 The PostaPanduri plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insu… wordfence
1f402bc3-c63c-43ef-9fca-11bdd7c2b529 HIGH 7.5 The Aora theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.15. This makes … wordfence
1e3ee917-6022-413c-a575-d4eb4e210700 HIGH 7.5 The Lead Capturing Pages plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5 due t… wordfence
1e3d70f2-11c1-4e3e-a409-bd4571165d60 HIGH 7.5 The Greenmart theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.2.11. This m… wordfence
1e1e8486-22ed-4034-bdfc-6c9f0e2fbc95
< 1.7.7
HIGH 7.5 The Web Directory Free plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.6 due t… wordfence
1de12d1c-5ac4-4f80-b33d-a689a6916ee0
< 0.0.14
HIGH 7.5 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in… wordfence
1dccdbbd-fd3c-4d76-a05a-42f1c7f7132f
< 2.1.2
HIGH 7.5 An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment … wordfence
1dcab187-c26e-43cb-bd6a-ff05041626da
< 5.0.11
HIGH 7.5 The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and… wordfence
1da8894c-fd19-4ea1-9c05-e519c0131061
< 1.22.16
HIGH 7.5 PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated atta… wordfence
1d8f3874-dca7-404c-802a-a6b5d935e3a3
< 5.2.18
HIGH 7.5 The Small Package Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection in versions u… wordfence
1d8e07b0-428f-4089-9ada-f9d2475bfe91 HIGH 7.5 The Applay - Shortcodes plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7… wordfence
1d6c9765-6936-4b22-835e-e899f62c14c9
< 2.2.1
HIGH 7.5 The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data due to missing capability checks on vari… wordfence
1d5ef241-d517-4ac3-8416-eed1428ae7ba HIGH 7.5 The RSVP ME plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.9 due to insuffici… wordfence
1d5987cd-1304-487c-8d1c-cab0510fbb84
< 5.0
HIGH 7.5 In WordPress before 5.0, unauthenticated attackers can cause a denial of service (resource consumption) by using the lar… wordfence
1cebcf16-ae7f-45c4-8e1d-80ede4c32106
< 2.3.40
HIGH 7.5 The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions … wordfence
1cac2397-bb38-40d6-b90d-68e3ea136267
< 2.0.4
HIGH 7.5 The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameter… wordfence
1c8bcbf8-1848-4f7a-89d8-5894de0bb18b
< 5.2.14
HIGH 7.5 The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
1c667631-7934-467e-baa2-7c3b0160c3a5
< 4.1.10
HIGH 7.5 The Active Directory Integration / LDAP Integration plugin for WordPress is vulnerable to Sensitive Information Exposure… wordfence
1bfa1538-7722-458d-a6a5-adde03e21e1a
< 7.4.0
HIGH 7.5 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder plugin for WordPress is vulnerable t… wordfence
← Prev 321 322 323 324 325 326 327 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top