🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 423 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3b515142-4e04-4570-b5cb-18261974c659
< 4.4.7
MEDIUM 6.8 Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <… wordfence
3b497bc0-bf47-43c7-9d5f-8e130dd0bab2
< 3.1.9
MEDIUM 6.8 The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.… wordfence
38d5d951-588f-4808-b691-5105021eb1e8
< 1.1.27
MEDIUM 6.8 The 10WebSocial plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and incl… wordfence
371deb9d-707f-47e4-96d7-1a287926b536
< 3.7.34
MEDIUM 6.8 In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScr… wordfence
314520d5-bd9d-46c1-b903-5e5cb3bb3417
< 6.5.8
MEDIUM 6.8 The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vuln… wordfence
25baf78e-e9bc-421b-8a66-9571ac3625c3
< 6.9.10
MEDIUM 6.8 The Blog2Social plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 6.9… wordfence
21e3d4a5-aaf3-4f42-8868-cd8c9bccd026
< 1.2.13
MEDIUM 6.8 The settings of the iQ Block Country WordPress plugin before 1.2.13 can be exported or imported using its backup functio… wordfence
105dcbbb-9ee2-4a5a-9b65-bbac931d1080
< 2.0
MEDIUM 6.8 The Wp Social plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.9.0. This i… wordfence
fb56c071-d7b9-40e0-8cc5-2dd48c93b8cf MEDIUM 6.6 The Contact Form Maker plugin for WordPress is vulnerable to blind SQL Injection in versions before 1.13.23 due to insuf… wordfence
fab8d770-2add-4470-980b-b1ea84b7ab7e
< 2.3.4
MEDIUM 6.6 The WebToffee WooCommerce Product Feeds – Google Shopping, Pinterest, TikTok Ads, & More plugin for WordPress is vulne… wordfence
f922ea86-5876-40ce-82ee-fb2b6dbddf17 MEDIUM 6.6 The Sendit WP Newsletter plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘id_lista’ par… wordfence
f833e236-2ca6-49bc-9c98-cce06a47f1b1
< 4.8.7
MEDIUM 6.6 The Maps plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.8.6 via deserial… wordfence
f728cc5e-7330-4dda-b5f7-55c33def6f02
< 1.2.1
MEDIUM 6.6 The Interactive Polish Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings i… wordfence
f2967b6a-38e1-405b-83a3-ae6ea07b8840
< 6.6.27
MEDIUM 6.6 The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress i… wordfence
f256518c-9a3e-4e6e-8d49-d309e397c14d MEDIUM 6.6 The Bravo Translate plugin for WordPress is vulnerable to SQL Injection via multiple parameters in versions up to, and … wordfence
e8b62157-8c32-462f-aba7-dab137f98f32
< 9.2.0
MEDIUM 6.6 A Race condition vulnerability in unzip_file in admin/import/class-import-settings.php in the Yoast SEO (wordpress-seo) … wordfence
e58634c3-7fcd-4885-b897-4e6a97fb06ac
< 7.59
MEDIUM 6.6 The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to… wordfence
e48ce7d2-0c57-499a-81b6-2d9488de704c
< 3.12.8
MEDIUM 6.6 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to … wordfence
e31119ab-963d-48a4-9948-0a0dce761918
< 1.26.13
MEDIUM 6.6 The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin … wordfence
e2f5a49a-117a-473c-8853-ed292eece620
< 1.9.8
MEDIUM 6.6 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr… wordfence
e1f0ec5c-6853-4df9-816a-1790f3dc86e0
< 5.9.1
MEDIUM 6.6 The WooCommerce Payments plugin for WordPress is vulnerable to SQL Injection via the ‘currency', 'currency_is', and 'c… wordfence
e0b8c24b-3e51-4637-9d8e-da065077d082
< 3.1.4
MEDIUM 6.6 The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl… wordfence
e0a294c5-dc2f-4739-9519-ae2a1268ff55 MEDIUM 6.6 The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress … wordfence
e09f8e0a-ff68-41be-b91a-5c6951def3f3 MEDIUM 6.6 The uListing plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.2.0 via dese… wordfence
df045b6c-ce8a-494e-a023-ed8165b0634c
< 1.6.20
MEDIUM 6.6 The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection … wordfence
← Prev 420 421 422 423 424 425 426 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top