🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,652
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 15, 2026
Last Updated

39,652 vulnerabilities found (page 344 of 1587)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f00e8169-3b8f-44a0-9af2-e81777a913f8
< 2.7.2
HIGH 7.2 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection vi… wordfence
efdf76b2-7640-4384-a72b-789159eb9c86
< 2.5.0.2
HIGH 7.2 The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘answer-x’ parameter in vers… wordfence
efc434fd-320a-4808-9289-7c2f63d4f5a4
< 1.2.2
HIGH 7.2 The SMTP Mail plugin for WordPress is vulnerable to generic SQL Injection via the ‘order’ and ‘orderby’ paramete… wordfence
efab7ec7-7143-4556-8d68-4a7e34f46e9e
< 1.2.2
HIGH 7.2 The Woocommerce Support System plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versio… wordfence
ef9d256b-9156-4172-8892-29a26beddb71
< 6.2.1
HIGH 7.2 The Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the booking ID field in versions up… wordfence
ef888b2e-1fc7-442b-8b67-ebfdcbc76696
< 3.8.2
HIGH 7.2 The I Recommend This plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.8.1 … wordfence
ef20b3e6-d8f4-458e-b604-b46ef16e229e
< 1.11.2
HIGH 7.2 The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up … wordfence
ef07d6b0-ccdb-4b33-817f-6d4b3ad96243
< 1.3.7
HIGH 7.2 The TableMaster for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, a… wordfence
eee9e199-00c6-4640-bd7c-e1316e2bba51 HIGH 7.2 The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter wh… wordfence
eee60ee9-ec48-4c09-9905-edd2dbbcccf3
< 1.7.1
HIGH 7.2 The Advanced Booking Calendar plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter in … wordfence
eea05676-aa24-4f60-9a8c-716b8a051be6
< 4.1.2.1
HIGH 7.2 The JetBooking plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4… wordfence
ee7eb754-27f0-47b0-a82f-4781cfbb0fa6 HIGH 7.2 The Neshan Maps plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions up to, and includ… wordfence
ee2bbe3a-b1d2-4266-af55-35f60ac52733 HIGH 7.2 The Arabic Font plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arabic-font.php' and '/inc/pa… wordfence
ee27a988-6afd-4da7-a750-0af801d7fa15
< 2.8.4
HIGH 7.2 The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template. wordfence
ee269bc7-2822-4a07-be91-6763c1cf6cf2
< 1.2.7
HIGH 7.2 The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due … wordfence
ededbe81-6feb-4952-9dc2-12156444ff5c
< 3.5.2
HIGH 7.2 The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vul… wordfence
edb0ee0c-1eab-4988-9eb6-cc0c253fee15
< 2.8.3
HIGH 7.2 The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
edaec73f-25b5-4ace-afef-844eb4143bf2
< 3.39
HIGH 7.2 The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to PHAR Deserialization in all versi… wordfence
ed9ae337-fd2b-49c1-baac-6540f1152f94
< 5.8.4
HIGH 7.2 Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via para… wordfence
ed8f8984-bea6-44aa-9bde-5b40b455767f
< 2.1.77
HIGH 7.2 The WooCommerce Product Vendors plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.… wordfence
ed28fe16-0835-4e94-a30e-305e7ba03740
< 2.5.1
HIGH 7.2 The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 … wordfence
ed1ba10b-bbaf-4753-8ae3-107e2cd3ead3
< 1.3.0
HIGH 7.2 The FluentCart plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.3.0 due to insuffic… wordfence
ecc59a6f-5e4a-44b4-932d-ed990ebb075a
< 3.06
HIGH 7.2 The Media Library Assistant for WordPress is vulnerable to SQL Injection via the ‘post_types’ parameter in versions … wordfence
ec3ef618-27db-4cdd-a1ea-09f7cb24e954
< 2.10.9
HIGH 7.2 The Modula - PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1… wordfence
ec2c0542-b5ae-4595-b712-ddcd27d21183
< 2.15.4
HIGH 7.2 The Tourfic – Ultimate Hotel Booking, Travel Booking & Car Rental WordPress Plugin | WooCommerce Booking plugin for Wo… wordfence
← Prev 341 342 343 344 345 346 347 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top