🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 328 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0d379aab-9fc7-4012-83d9-f55a1bd26918
< 5.0.21
HIGH 7.5 The LTL Freight Quotes – Worldwide Express Edition plugin for WordPress is vulnerable to SQL Injection in versions up … wordfence
0d04b822-a48a-485e-b9b5-f5a213307c71
< 1.29.2
HIGH 7.5 The Forminator plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
0cedce2a-b261-4e3f-b901-fa73ab49ca15 HIGH 7.5 The Directorist Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.1 due … wordfence
0ce8ed18-2164-4b5a-b1d3-fda8d348ebf9
< 2.2.4
HIGH 7.5 The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp… wordfence
0cd880c9-75fe-420b-ae41-558678adb57b HIGH 7.5 The Jssor Slider by jssor.com plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and inclu… wordfence
0cad8c48-5c96-484c-acda-b33d8d8d10d3
< 1.4.4
HIGH 7.5 The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the selec… wordfence
0c81eabe-93c2-4838-af35-ad1c0ba458af HIGH 7.5 The Tonda Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.2. This … wordfence
0c747bc9-582c-4b9f-85a4-469c446d50f5
< 9.8.0
HIGH 7.5 The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is… wordfence
0b738d0a-39e2-46e3-9b62-920599543220
< 2.6.0
HIGH 7.5 The Booking and Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includi… wordfence
0b3798e3-45fe-4829-9012-dc728d4af87f
< 2.9.6
HIGH 7.5 The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass in all versi… wordfence
0b2a2a47-0650-4f80-9b67-017f35954db0
< 8.7.4
HIGH 7.5 The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to 8.7.4 due to insufficient escaping on t… wordfence
0afcdec7-dd22-4f10-b8f9-96a1e57d8f0b
< 1.1.4
HIGH 7.5 The Thinkun Remind plugin for WordPress is vulnerable to arbitrary file reading via directory traversal in versions up t… wordfence
0aeaf421-513b-4c9d-bd36-58af28c86bc1
< 1.1.3
HIGH 7.5 The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu… wordfence
0abad47f-a806-4cdd-a11f-015b997b5e86
< 5.8.0
HIGH 7.5 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to security feature bypass in all versions up t… wordfence
0a8127e5-b5e6-4545-9e38-f3fa9daabcf2 HIGH 7.5 The Access Code Feeder plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on t… wordfence
0a6615fd-7c37-45d9-a657-0ba00df840e5
< 1.7
HIGH 7.5 The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisti… wordfence
0a5f2e1a-2216-4885-9b74-a08142816f2b
< 2.9.2
HIGH 7.5 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap… wordfence
0a37f3bf-5eaf-449d-a1d0-c86ae1a61078 HIGH 7.5 The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘fmcfIdSelecte… wordfence
0a2e1c32-cf0e-4733-babd-d8b9cfe68535
< 8.6.9
HIGH 7.5 The Soledad theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.6.8. This make… wordfence
09fc8d80-8231-4183-9626-c90f4fee5eb4 HIGH 7.5 A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25,… wordfence
09ac96f8-e138-48fe-bd95-5356fc222004
< 3.1.6
HIGH 7.5 The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unseria… wordfence
099dd38b-29f0-4b37-bb79-c7297baa9617
< 3.21.2
HIGH 7.5 The MyStyle Custom Product Designer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… wordfence
092061a5-5315-4401-8503-6153f660acdc
< 1.18.1
HIGH 7.5 The Omnisend for WooCommerce plugin for WordPress is vulnerable to an unauthenticated account takeover via insufficientl… wordfence
08f55882-d19f-43a3-a370-17d041493944
< 1.0.75
HIGH 7.5 The BookingPress plugin for WordPress is vulnerable to booking price manipulation in all versions up to, and including, … wordfence
08801f53-3c57-41a3-a637-4b52637cc612
< 1.3.7
HIGH 7.5 The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to insufficient path and file… wordfence
← Prev 325 326 327 328 329 330 331 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top