πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 329 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
083dd550-6d62-4e2e-8571-ef3c5597e816
< 3.8.11
HIGH 7.5 The JetEngine plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.10.2 due to insu… wordfence
0838daec-6e83-4e19-93e1-a7645daf1294
< 1.0.4
HIGH 7.5 The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress i… wordfence
0823d1d9-4f3b-4ac0-8cd1-ad208ebc325f
< 7.90
HIGH 7.5 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to PHP Object Injection in all versions up to,… wordfence
081bd3a9-2139-416f-bb36-b86aef6fa6db
< 1.7.0
HIGH 7.5 The Jetpack Scan team identified a Local File Disclosure vulnerability in the Patreon WordPress plugin before 1.7.0 that… wordfence
0814e7b3-404a-4db5-b564-46c9086ec048
< 5.1.17
HIGH 7.5 The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner… wordfence
07ebb176-a1f8-4a5c-8d81-a83fda4b0af3 HIGH 7.5 The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient… wordfence
07cdc2db-e748-40c9-a2fe-31aef0725dad
< 2.2.6
HIGH 7.5 The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in t… wordfence
07b34541-25df-407b-8d56-16e3e510d83a
< 1.0.5
HIGH 7.5 guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header par… wordfence
07aee46a-a32d-4d31-9541-4e183299b09c
< 1.2
HIGH 7.5 The ebook-download plugin before 1.2 for WordPress has directory traversal via ebookdownloadurl parameter. wordfence
0788e172-c9f0-4aa5-806b-183491f92bc3
< 4.2.2.1
HIGH 7.5 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner β€” Groundhogg plugin for WordPress is vuln… wordfence
077c36f3-91ee-4fac-8303-2222816e4707
< 2.2.7
HIGH 7.5 The WBW Product Table PRO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.2.6 du… wordfence
075709e0-5f00-4d7b-80f6-96e3b4b4a895
< 2.10
HIGH 7.5 The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Sensitive Information Expo… wordfence
0733261f-a2e1-4bd1-a57d-fdaaa8c904db
< 2.5
HIGH 7.5 The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vu… wordfence
06fc92e9-b2c0-46a0-99b2-10cf0d564f7b
< 1.4.110
HIGH 7.5 The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Local File Inclusion in… wordfence
06e4d7e3-c800-4b3d-9504-c69aa9a918fb
< 2.0.2
HIGH 7.5 WordPress 2.0.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) default-… wordfence
06dcb84f-8293-403d-a3f2-7c5bea7aaae3
< 1.5
HIGH 7.5 The Construct Theme for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 1.4. This i… wordfence
069bd7ab-1b78-4465-8e13-5ef903f7e45f
< 2.2.6
HIGH 7.5 admin/includes/class.actions.snippet.php in the "Woody ad snippets" plugin through 2.2.5 for WordPress allows wp-admin/a… wordfence
06919817-a2ce-4914-bf1c-7763c1cde543
< 1.9.9.5.3
HIGH 7.5 The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping o… wordfence
06900b4b-6607-4b25-b4bc-2e2906160421
< 1.7.2
HIGH 7.5 The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in… wordfence
0640538c-b076-453c-a32e-f33b4e1c77ae
< 1.1.0.54
HIGH 7.5 The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1… wordfence
063abf5d-d704-4e16-8ee7-58a3370993b9 HIGH 7.5 The Hospital Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 47.… wordfence
06359274-37ae-47f5-824c-25600c5b06eb HIGH 7.5 The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the β€˜br’ parameter… wordfence
0605bc15-3a97-46f4-8244-29220ed5ab31 HIGH 7.5 The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to SQL Injection via… wordfence
05d633f5-151a-4462-a6a0-5a638d7c3404
< 2.8.7
HIGH 7.5 The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action… wordfence
05d063e3-4863-4dd5-9219-6240b9b3f939
< 1.15.39
HIGH 7.5 The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL I… wordfence
← Prev 326 327 328 329 330 331 332 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top