πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 422 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ef9010e3-f060-4bef-b62b-4a648f5e5577
< 1.7.6
MEDIUM 6.8 The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is du… wordfence
ee792903-3b55-4f1d-bba1-59ea3f1826a1
< 3.2
MEDIUM 6.8 The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via… wordfence
ea56f0a1-7359-4beb-aae6-e2a3757ec8cd
< 4.0.0
MEDIUM 6.8 The Enable Media Replace plugin for WordPress is vulnerable to path traversal when renaming files in versions up to, and… wordfence
e82cdfab-8090-4979-81b6-5b860e9ae187
< 2.1.1
MEDIUM 6.8 Authenticated (administrator or higher user role) Local File Inclusion (LFI) vulnerability in Wow-Company's Hover Effect… wordfence
dbd76c3d-028a-48e3-9a80-1a8da934d097
< 1.2
MEDIUM 6.8 Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugi… wordfence
ce2b4f93-93a6-480f-a877-ca47bd133bb6
< 5.2.9
MEDIUM 6.8 Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a… wordfence
ca98fbc6-8cfa-4997-8a46-344afb75a97e
< 7.2.6
MEDIUM 6.8 The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 v… wordfence
c9205896-487d-4b8f-84cf-7ba16e1205e3
< 1.9.2
MEDIUM 6.8 The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege… wordfence
c0e53aa4-9acf-4501-9b5e-b7694851fc63
< 2.2
MEDIUM 6.8 Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Popup Box plugin … wordfence
ba4e982d-b8ac-4407-97b0-c725b8f43bbd MEDIUM 6.8 The CaPa Protect WordPress plugin through 0.5.8.2 does not have CSRF check in place when updating its settings, which co… wordfence
a9992d0d-7c6e-4184-8f48-1515d50cc028
< 3.4.2.1
MEDIUM 6.8 The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i… wordfence
a8163dc0-e380-4a0b-bd18-34a3e80ca3dd
< 2.4.5
MEDIUM 6.8 The VR Calendar plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.4. This… wordfence
a626dfd4-d8c3-4cd1-a624-bae719bea93a
< 1.0.173
MEDIUM 6.8 The Music Player for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting several parameters in… wordfence
a2ad2c0d-542e-4b40-91a8-19b27297545e
< 1.7.5.5
MEDIUM 6.8 The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versio… wordfence
9d8304bf-bec2-4fcf-9fe2-46b626b3dae9
< 2.9.13
MEDIUM 6.8 The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, … wordfence
98085a23-0cb6-442a-a28a-cb5c2890b60d
< 4.0.2
MEDIUM 6.8 The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the j… wordfence
81b4302f-1a2f-49f4-8bfc-a511604dc51b
< 1.8
MEDIUM 6.8 The BP Email Assign Templates plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient valida… wordfence
7f559d7f-3faf-4549-b529-f4db03dce2dd
< 5.2.5
MEDIUM 6.8 The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery… wordfence
76c38826-4d49-4204-b6b6-b01d01373fa9
< 1.8.24
MEDIUM 6.8 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all… wordfence
7047d53e-c9e4-46f9-8b5f-3489a1fb7e97
< 1.1.6
MEDIUM 6.8 The Database Management tool – Adminer plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to… wordfence
6ed9a567-fde4-4b6f-81c1-423c5cbba0a9
< 5.8
MEDIUM 6.8 WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database… wordfence
6aa0dfdf-95b0-48a2-8281-1872b99b87d6
< 4.5.98
MEDIUM 6.8 The Download Monitor plugin for WordPress is vulnerable to arbitrary file downloads due to not verifying that downloaded… wordfence
4c72abf9-f63d-4460-8c9b-10e3f65b71ba
< 5.8.2
MEDIUM 6.8 The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5… wordfence
41a362cf-e27e-436a-85f1-7c48e2e098eb
< 5.4.27
MEDIUM 6.8 The Woffice Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … wordfence
3be1a1af-baab-4e57-a2c7-5e6963f986cc
< 1.3.9
MEDIUM 6.8 The Post to CSV by BestWebSoft plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3… wordfence
← Prev 419 420 421 422 423 424 425 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top