πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 424 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
dc878508-200d-4bc7-aa99-c34e63cba4b3
< 3.1.5
MEDIUM 6.6 The Intuitive Custom Post Order plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.… wordfence
d4e97c01-7e8a-41b7-90ad-029d8c5fd37c
< 2.4.4
MEDIUM 6.6 The Booking Calendar | Appointment Booking | BookIt plugin for WordPress is vulnerable to SQL Injection via an unknown p… wordfence
cf3916fc-f652-4615-872c-3f007b8999df MEDIUM 6.6 The Woocommerce Blocks – Woolook plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and… wordfence
ceba35c3-16b0-4366-b33c-603bdc2c1006
< 5.1.1
MEDIUM 6.6 The Advanced File Managerplugin for WordPress is vulnerable to improper access control in versions up to, and including,… wordfence
ce4b7710-f579-4fa7-a7a3-f7da61bd813e
< 1.2.7
MEDIUM 6.6 The LTL Freight Quotes - TQL Edition plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and i… wordfence
cd7dba3a-eb76-48f2-9656-7621c7406c05
< 1.4.1
MEDIUM 6.6 The HUSKY - Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in v… wordfence
cd731f89-8811-4068-ab34-3cee8cc7d089
< 5.3.3
MEDIUM 6.6 The WP Activity Log plugin for WordPress is vulnerable to PHP Object Injection in version 5.3.2 via deserialization of u… wordfence
ca1dec2a-c3a1-4edc-b9f6-7504c1830d29
< 2.2.8
MEDIUM 6.6 The LTL Freight Quotes – Daylight Edition plugin for WordPress is vulnerable to PHP Object Injection in versions up to… wordfence
ca195af0-9b51-4eca-b1ca-309b4b26ed4e
< 3.107.0
MEDIUM 6.6 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to PHP… wordfence
c72aa934-3925-49ee-95cb-e81316865d4a
< 5.9.11
MEDIUM 6.6 The Email Subscribers & Newsletters plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and in… wordfence
c5782b71-3234-4e53-9b26-225472f604c5
< 1.76.0
MEDIUM 6.6 The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for… wordfence
c0754c1d-378c-47d4-9b67-0916d89bb327
< 2.1
MEDIUM 6.6 The Social Counter plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.5 vi… wordfence
bfbc406b-49af-419e-adeb-0510794b7e3f
< 5.2.1.0
MEDIUM 6.6 The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and inc… wordfence
bf7f8954-53bf-49fa-b91b-f968a734027a
< 4.13.4
MEDIUM 6.6 The Ajax Search Lite plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.13.3… wordfence
bf172a41-31dc-4864-9385-53decdc70aeb
< 2.14.4
MEDIUM 6.6 The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize … wordfence
baca279b-0c42-48a9-930a-8d0525066e0a
< 2.8.57
MEDIUM 6.6 The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl… wordfence
b5ebc99d-b82a-452b-8f53-bd96135aeecb
< 3.7.37
MEDIUM 6.6 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a mu… wordfence
b4f8c1a4-a309-4852-a066-0644ce175abc
< 2.11.17
MEDIUM 6.6 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.11… wordfence
b409d2a5-3c4c-4a1e-b222-e2df7257b81f
< 4.9.3
MEDIUM 6.6 The Newsletters plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.9.2 via … wordfence
b3d48aca-3db5-4585-bd71-5548f3b36ea1
< 2.3.29
MEDIUM 6.6 The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to … wordfence
b2ea3a9e-2a9a-4628-8ea1-e18e756f915f
< 0.5.1
MEDIUM 6.6 The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… wordfence
b26996cf-acea-41fb-ad2f-167f41d31cea
< 4.7.3
MEDIUM 6.6 The Malware Scanner plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, … wordfence
b10c7619-85b0-4d06-b48c-248fa3f66229 MEDIUM 6.6 The Social Login and Register plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
af387cb8-583f-4bc6-9de7-fc03fd12d01a
< 3.5.2
MEDIUM 6.6 The JetFormBuilder plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.2 … wordfence
ade6f9f2-2a35-4bb0-ab13-33b84394d965
< 22.4
MEDIUM 6.6 The Bookly plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including… wordfence
← Prev 421 422 423 424 425 426 427 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top