πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 326 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
16f5a104-dce0-4249-91b9-67f99cce16d3
< 3.5.26.1
HIGH 7.5 The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 … wordfence
1680078c-0dbe-4586-b793-3bf2ddea96ba HIGH 7.5 Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress al… wordfence
1663be8e-a6b8-4e0d-97d0-af7db2a2875c
< 5.7.2
HIGH 7.5 The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to SQL Injection via the 'store_service_date… wordfence
1661bb28-e5b4-4319-84bb-6cbeac266147 HIGH 7.5 The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all… wordfence
15abde72-515a-4e1c-af4c-d9da56a5cbe2
< 3.1.2
HIGH 7.5 The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in th… wordfence
15a533e6-675f-4c32-9b88-111e6a5f6bf7
< 6.5.1
HIGH 7.5 The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection i… wordfence
159e14fc-0512-421a-8bbe-d16c0b04ddf9
< 1.15.9
HIGH 7.5 The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to un… wordfence
158000e9-b8bd-4adb-b634-534d31471def HIGH 7.5 The OneLife theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.9 via deserial… wordfence
157d473d-68f6-40ff-b73c-17e3ca528ee4 HIGH 7.5 The JS Job Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.0.2 due to in… wordfence
156eb99d-087b-4716-8ba8-3a1bdc008f58 HIGH 7.5 The WPB Category Slider for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
14d84ad4-904b-4000-af82-b1b68c724aa2
< 2.5
HIGH 7.5 The Elegance Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.4. This is… wordfence
14894c36-f657-4368-bc7f-60121ec08c13
< 1.4.3
HIGH 7.5 The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin f… wordfence
1485dda6-bf83-4076-80c9-dc7ea9d58155
< 2.1.2
HIGH 7.5 The EventON plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and including, … wordfence
1479071c-85c3-41fd-8ad7-f0dee32f201b
< 4.0.27
HIGH 7.5 The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to arbitrary f… wordfence
1462f52b-98f0-40de-8f95-717992c7cbc6
< 7.3.7
HIGH 7.5 The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.3.6 due to in… wordfence
1410ee86-90ec-4913-bc74-d8954d141d72
< 2.11.1
HIGH 7.5 The WPGraphQL plugin for WordPress is vulnerable to SQL Injection in versions up to 2.11.1 due to insufficient escaping … wordfence
13d07e9d-0e28-4d28-b1e9-168a83e98bf6 HIGH 7.5 The Vino theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9. This makes it … wordfence
13bde27a-8741-4b86-a45b-7acbaf7d6dde HIGH 7.5 The apptha-slider-gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… wordfence
13b79de0-9ef9-4b7f-aa57-75877b4a39c0
< 2.9.3
HIGH 7.5 The JS Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.2 due to insu… wordfence
13728336-42b8-4857-9753-c91b7cb028fa
< 2.7.8.4
HIGH 7.5 The Participants Database plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.8.3 … wordfence
134e09a8-f89a-4282-b2e8-09b84f04aae7 HIGH 7.5 The wptf-image-gallery plugin for WordPress is vulnerable to Arbitrary File Downloads in versions up to, and including, … wordfence
1301c8af-d81a-40f1-96fa-e8252309d8a4
< 3.2.90
HIGH 7.5 The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization … wordfence
12f0394a-de18-4f61-b93d-34b30ae6106a
< 4.9.2
HIGH 7.5 The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulne… wordfence
12c29a44-f9e4-439a-bc3f-18a3640f7924
< 2.22.8
HIGH 7.5 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerabl… wordfence
12bebb01-74ea-4722-99ed-2322d35da8c2 HIGH 7.5 The WPJobster theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.3.5 due to insuffic… wordfence
← Prev 323 324 325 326 327 328 329 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top