πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 330 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
05b44698-c55f-48ff-8f98-8478b2564e38
< 3.9.5
HIGH 7.5 The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
056a8372-82f3-4707-8bff-1ab91595f8dc HIGH 7.5 The Puca theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.6.39. This makes … wordfence
05153b11-2f26-425e-99ab-93216861802b
< 3.0.9
HIGH 7.5 The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-js… wordfence
04f37062-da7e-4c26-ab15-50dcef8ca301
< 1.0.2
HIGH 7.5 The ThemeMakers Diplomat | Political theme through 1.0.1 for WordPress allows remote attackers to obtain sensitive infor… wordfence
04a46249-b5b2-4082-b520-cdc4a1370bb1
< 2.1.4
HIGH 7.5 The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/c… wordfence
048a55a4-f4b3-4203-8c0a-8778189a6a18
< 3.2.1
HIGH 7.5 The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2.0 due to insuffici… wordfence
042f78a4-2256-4286-aa03-8bd8b7a79530
< 4.5.5.1
HIGH 7.5 The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all ve… wordfence
042f7090-2eab-44d2-82b2-ecabdb1d3f99
< 3.2.15
HIGH 7.5 The ninja-forms plugin before 3.2.15 for WordPress has parameter tampering. wordfence
040ae20d-93e3-4c65-ba74-4ff0b5c1afc7
< 5.5.4
HIGH 7.5 The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted inpu… wordfence
03e845c0-5845-4d74-88e6-376c703b6145 HIGH 7.5 The TheGem Theme Elements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5… wordfence
03a96b11-ffda-40a9-897e-657847fc0d40 HIGH 7.5 The Improved Sale Badges – Free Version plugin for WordPress is vulnerable to Local File Inclusion in all versions up … wordfence
0394e4a9-28dc-4e20-8bc3-ed486172dcb8
< 2.5.13
HIGH 7.5 The Urna theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.5.12. This makes … wordfence
0368ec17-107c-476c-9627-b6a7ebc3c365
< 5.1.8
HIGH 7.5 The Iptanus File Upload plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.7 due … wordfence
031c2a61-3547-4c33-8ab8-c52585c8066a HIGH 7.5 The OpenInviter for WordPress plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and inclu… wordfence
0315f5de-7a46-4e16-b080-557ddfd180a2
< 4.2.0
HIGH 7.5 The Javascript library moment.js is vulnerable to a path traversal vulnerability in versions up to, and including, 2.29.… wordfence
0307dbb7-4f82-429b-9be5-9e7c75603074 HIGH 7.5 The Simply Poll plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.1 due to insuf… wordfence
02e918f8-8380-44f6-bd4f-4f58fd47d69a HIGH 7.5 The Eventer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.9.6 due to insuffici… wordfence
029719d5-d7b8-48f5-af97-7a4f55892c4f HIGH 7.5 The WPCRM - CRM for Contact form CF7 & WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to… wordfence
02888538-c2c7-4cba-acf3-77d76cef255e
< 2.1.3
HIGH 7.5 The Organici Library plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.2 … wordfence
01e41573-9329-48e1-9191-e8e1532f7afc
< 1.2.7
HIGH 7.5 The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing cap… wordfence
01d2ebc1-43f1-440f-afde-058e26270066
< 3.1.3
HIGH 7.5 The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
01b3013f-60b9-449b-a2a9-64e37a1454ef
< 6.2
HIGH 7.5 The JM Twitter Cards plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 6.1… wordfence
0180bf61-fdb4-40b3-bbb6-6bc76a85ed4e HIGH 7.5 The Entrada theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.7.7 due to insufficie… wordfence
0139661f-75d2-44b7-8278-e31c24935a85
< 2.3.3
HIGH 7.5 The ZoloBlocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.2. This … wordfence
011d654a-637f-418c-8bd3-e87fd889f1ab
< 3.3.0
HIGH 7.5 The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit plugin for Word… wordfence
← Prev 327 328 329 330 331 332 333 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top