πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 327 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
12be30fc-2d7e-4326-b949-45138796c1a9
< 5.3.7
HIGH 7.5 The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPre… wordfence
121a65ba-2d14-462e-bf2b-10210430e07a HIGH 7.5 The Ronneby Theme Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.5.… wordfence
11e7e798-9fb9-4cff-a96f-a0003f203f5f
< 2.0.1
HIGH 7.5 The Shipping Rate By Cities plugin for WordPress is vulnerable to SQL Injection via the 'city' parameter in all versions… wordfence
119fe499-88c4-413f-a44a-2b3acfdbdeb5 HIGH 7.5 The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl… wordfence
1134c9ea-bbec-4f5d-acb0-1ae978346cfc
< 3.9.5
HIGH 7.5 The WP Travel Gutenberg Blocks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9… wordfence
110f4ca6-3e59-4348-bb45-6e5fcfa81491
< 0.9.2.5
HIGH 7.5 W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download th… wordfence
10ee015a-c60b-4236-bb7a-9d3ffd944bf9
< 2.2.0
HIGH 7.5 The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provision… wordfence
10ea2183-3f4e-44bd-a726-0910fe71df13 HIGH 7.5 The Video List Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7 due to … wordfence
10e4c52d-c82f-4393-9a56-5714b3a108d1
< 1.16
HIGH 7.5 The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1… wordfence
1079b96d-0435-42f1-b5b2-d36e674c0c9c
< 6.4.4
HIGH 7.5 The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object… wordfence
1057b1ee-9bcb-4b3b-bbc0-3262e658bb97
< 3.1.3
HIGH 7.5 The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to SQL Injection in versions up to 3.1.3 du… wordfence
102ed3c9-33ed-462a-83df-5a57f2621780
< 3.1.1
HIGH 7.5 Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remo… wordfence
1005eb8c-da5a-4422-9d65-0f341ad755b2
< 1.3.9.7
HIGH 7.5 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t… wordfence
0ff96c12-1388-48a9-adf4-feca77a37ba7
< 3.8.4
HIGH 7.5 Sliced Invoices plugin for WordPress 3.8.3 and earlier allows unauthenticated information disclosure and authenticated S… wordfence
0fe89884-b428-4caf-b67a-5aaa41fafa9d
< 1.2.18
HIGH 7.5 The Hara theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.2.17. This makes … wordfence
0fbc5cd6-7a81-4c85-b51b-9a3f27b923e2
< 4.0.4.2
HIGH 7.5 The JetBooking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.4.1 due to insu… wordfence
0fa4585d-9ffa-4a32-aeb7-60cdad63187b HIGH 7.5 The WP Backup+ plugin for WordPress is vulnerable to Sensitive Data Exposure via the temp directory. This can allow unau… wordfence
0f8c0697-73dc-481e-8d9b-d3e0de4bded3 HIGH 7.5 The Billey theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.8. This makes… wordfence
0f54f61c-f75d-4640-8150-e8b60b26dcf9
< 2.0.1
HIGH 7.5 The Corpkit theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0. This makes … wordfence
0f4c9abb-d42d-4f59-8364-f1fb4d06ffbc
< 3.1
HIGH 7.5 The Addon Jobsearch Chat plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0 due t… wordfence
0f3b74db-22a4-4638-8662-0c8cfbee6493
< 1.14.2.2
HIGH 7.5 The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. wordfence
0e725ec0-4897-4ba7-a803-80e8aafacbd1
< 8.0.4
HIGH 7.5 The WPCargo Track & Trace plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.0.3 du… wordfence
0e22815e-1f06-4a46-90eb-98125ae97ba4
< 2.6.32
HIGH 7.5 The LikeBtn WordPress Like Button Rating β™₯ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Fu… wordfence
0e0ebe1d-b6cf-4ff5-ae6c-c8c226a000d4 HIGH 7.5 The Emailing Subscription plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.1 du… wordfence
0d50f217-7a53-49bf-9ce9-9922d0b3e18b
< 3.7.1
HIGH 7.5 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to authorization bypass due to a missing capability chec… wordfence
← Prev 324 325 326 327 328 329 330 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top