🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 325 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1bd80ab9-260a-46c5-949e-c1d5dcb32523
< 2.1.4
HIGH 7.5 The profile-builder plugin before 2.1.4 for WordPress has no access control for activating or deactivating addons via AJ… wordfence
1b5a4289-6228-4b77-9929-864b88c34dbe
< 2.2
HIGH 7.5 The Fusion Theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.1. This is d… wordfence
1b4d798e-75f2-4fc9-9d1f-1345a80623ee
< 2.1.7
HIGH 7.5 The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.6 due to insuffic… wordfence
1b1338c4-36a8-47b0-b3cf-c5dc690f8c1c
< 5.4.1
HIGH 7.5 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Inp… wordfence
1b0c1afc-0e77-4a56-89cb-84e2fcc8aa21
< 1.16.2
HIGH 7.5 The WP Crontrol plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.16.1… wordfence
1af2bb8c-b168-40bb-a172-a7c9d7531e1f HIGH 7.5 The Blog Designer PRO for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, an… wordfence
1acaa09d-762b-47df-97a1-cf5681fb19b3 HIGH 7.5 The Media folder Addon plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.1.6.… wordfence
1ab970f5-35d1-43e9-891c-87a2a3e464c6
< 4.7.10
HIGH 7.5 The MasterStudy LMS Pro plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… wordfence
1a7dbb6e-abb3-4fd9-8ca8-a3cd628fcf5b
< 4.5.5.1
HIGH 7.5 The GEO my WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.5 due to insuffi… wordfence
1a67b1b3-eb39-4e9a-ba44-ea637fc3bba1
< 1.5
HIGH 7.5 The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including… wordfence
1a5d4e67-3faa-4da2-be9b-65cf6fd03c53 HIGH 7.5 The Likes and Dislikes Plugin plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all versio… wordfence
1a46da16-2442-45cf-858f-0681b1106cc2
< 6.1.5
HIGH 7.5 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Directory Traversal in versions up to 6.1.5 via the… wordfence
19d12676-dbab-4954-90f7-cd8125bca881 HIGH 7.5 The Homeo theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.59. This makes… wordfence
19bd105a-823d-4a85-87e1-54291274a842 HIGH 7.5 The Export to Text plugin for WordPress is vulnerable to unauthenticated post exporting due to a missing capability chec… wordfence
197be163-4504-4caa-b729-c3293463cfb5
< 2.27.6
HIGH 7.5 The Relevanssi – A Better Search plugin for WordPress is vulnerable to time-based SQL Injection via the cats and tags … wordfence
193bd3b8-1af9-496a-ad77-dd5253612272
< 6.0.13
HIGH 7.5 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to SQL Injection in… wordfence
192728d1-786d-41eb-9133-ad8517052478
< 1.1.1
HIGH 7.5 The AliExpress Dropshipping and Fulfillment for WooCommerce Premium plugin for WordPress is vulnerable to Sensitive Data… wordfence
1894a25e-c004-4e0f-8064-66470eebdb7f HIGH 7.5 The WP Online Users Stats plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 du… wordfence
188eef67-de66-49c2-aa6c-2cf3b886ff66
< 3.9.29
HIGH 7.5 The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
1801fd3e-d56f-4540-9700-9e9de8b465e1
< 3.5.6.3
HIGH 7.5 The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a… wordfence
17f40832-8ae5-443a-aa98-f0e61d1152cc
< 1.8.6
HIGH 7.5 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Informa… wordfence
17ee6e87-2534-4397-833e-e0a1cd5d947c
< 1.5.22
HIGH 7.5 The CleverReach® WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.21 due to… wordfence
178e2537-e900-4264-9b29-1bb5bac36f48 HIGH 7.5 The PickPlugins Question Answer plugin for WordPress is vulnerable to SQL Injection in versions up to and including 1.2.… wordfence
174064fb-b222-4820-b175-980aa8ff8383 HIGH 7.5 The Amazon Native Shopping Recommendations plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… wordfence
1729d0de-1f5f-4349-b592-5841d01ed33a
< 4.8
HIGH 7.5 The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… wordfence
← Prev 322 323 324 325 326 327 328 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top