πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 16, 2026
Last Updated

39,836 vulnerabilities found (page 363 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b49ae7fc-e860-4387-b596-12640ec7277f
< 2.2.0
HIGH 7.2 The WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation plugin for WordPre… wordfence
b498e274-db8c-438f-8e19-43f3018d1663 HIGH 7.2 The WP AutoComplete Search plugin for WordPress is vulnerable to SQL Injection via an AJAX action in versions up to, and… wordfence
b4967c95-8eb6-4c9b-ae6e-082dbc6af7f5
< 3.7.13
HIGH 7.2 The Dokan plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and including,… wordfence
b4939efc-889a-4d1d-b916-dcf3b064dc81
< 2.5.1.9
HIGH 7.2 There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad… wordfence
b3ece4c3-1f05-4f2d-ba2a-50327106f0fa HIGH 7.2 The Album Reviewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin… wordfence
b3e00e40-cdbb-469f-89ec-6a28bf2014fd
< 7.6.2
HIGH 7.2 The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Stor… wordfence
b3c1edd7-2421-4dfa-8775-ca0497759d52
< 3.1.1
HIGH 7.2 The Product Addons for Woocommerce – Product Options with Custom Fields plugin for WordPress is vulnerable to Code Inj… wordfence
b3c12fdf-347c-4cec-b98c-a29ec8c0aff7
< 1.6.15
HIGH 7.2 The Product Addons and Product Options With Custom Fields – WowAddons plugin for WordPress is vulnerable to Stored Cro… wordfence
b3a670f7-7eca-4e66-9bc9-3c1e92b0c8d7
< 5.7.26
HIGH 7.2 The Quick Paypal Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and inclu… wordfence
b37a2260-0791-435d-8413-2bf68c388906 HIGH 7.2 The Awesome Filterable Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, an… wordfence
b3603994-b12e-4360-a3aa-b93e80ac927b
< 1.3.0.4
HIGH 7.2 The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, … wordfence
b30e84db-c73f-4df2-9c88-c37a7e14c95b
< 1.1.9
HIGH 7.2 The GeekyBot β€” Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to S… wordfence
b306873d-de30-4f5a-b4c8-ba3bf2bc27e1 HIGH 7.2 The WordPress WP-Advanced-Search plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v… wordfence
b303034f-6ef2-4679-be2c-39e1472b30eb HIGH 7.2 The Inline Tweets plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
b2ce5eb3-7a3f-4309-8263-23af334dd1d0
< 3.2.3
HIGH 7.2 The CF7 Views – Complete Entry Management for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site S… wordfence
b2a4a34f-4fc1-4bcd-b70b-8fa7d119f9e7 HIGH 7.2 The Grand Car Rental | Limousine HTML Template theme for WordPress is vulnerable to Stored Cross-Site Scripting in versi… wordfence
b2849cb5-9277-460d-a429-6253c98c1554 HIGH 7.2 The College publisher Import WordPress plugin through 0.1 does not check for the uploaded CSV file to import, allowing h… wordfence
b266bd10-dbc6-4058-a5b2-1578c0814cb4
< 2.5.2
HIGH 7.2 The Prevent files / folders access plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… wordfence
b243beac-1d8e-494d-8009-173a0a6c4d97
< 1.6.0
HIGH 7.2 The Wbcom Designs – Activity Link Preview For BuddyPress plugin for WordPress is vulnerable to Server-Side Request For… wordfence
b23e36f7-ee44-42c6-94b7-e943c6c4a3ad HIGH 7.2 The Search Logger plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.9 due to insuf… wordfence
b1eae4fc-85d1-49ff-9f3b-bf0a3f424ee1 HIGH 7.2 A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for Wor… wordfence
b1c3e480-0221-4913-bcce-f34ded9edca8
< 1.4.30
HIGH 7.2 The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up … wordfence
b1c27c27-f597-4867-a8d8-a83a3a1bf5f6 HIGH 7.2 The PPC Tracker WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via spoofed IP addresses in … wordfence
b18477b2-7b59-4ca2-aa26-d107f83df5a9
< 4.1.15
HIGH 7.2 The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file uploads… wordfence
b16d675f-1b62-4e3e-b91b-7bdb1e70a221
< 2.0.9
HIGH 7.2 Cross-site scripting (XSS) vulnerability in the wp_explain_nonce function in the nonce AYS functionality (wp-includes/fu… wordfence
← Prev 360 361 362 363 364 365 366 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top