πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 425 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c5782b71-3234-4e53-9b26-225472f604c5
< 1.76.0
MEDIUM 6.6 The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for… wordfence
c0754c1d-378c-47d4-9b67-0916d89bb327
< 2.1
MEDIUM 6.6 The Social Counter plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.5 vi… wordfence
bfbc406b-49af-419e-adeb-0510794b7e3f
< 5.2.1.0
MEDIUM 6.6 The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and inc… wordfence
bf7f8954-53bf-49fa-b91b-f968a734027a
< 4.13.4
MEDIUM 6.6 The Ajax Search Lite plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.13.3… wordfence
bf172a41-31dc-4864-9385-53decdc70aeb
< 2.14.4
MEDIUM 6.6 The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels & Maximize … wordfence
baca279b-0c42-48a9-930a-8d0525066e0a
< 2.8.57
MEDIUM 6.6 The Payment forms, Buy now buttons, and Invoicing System | GetPaid plugin for WordPress is vulnerable to Local File Incl… wordfence
b5ebc99d-b82a-452b-8f53-bd96135aeecb
< 3.7.37
MEDIUM 6.6 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a mu… wordfence
b4f8c1a4-a309-4852-a066-0644ce175abc
< 2.11.17
MEDIUM 6.6 The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.11… wordfence
b409d2a5-3c4c-4a1e-b222-e2df7257b81f
< 4.9.3
MEDIUM 6.6 The Newsletters plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.9.2 via … wordfence
b3d48aca-3db5-4585-bd71-5548f3b36ea1
< 2.3.29
MEDIUM 6.6 The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to … wordfence
b2ea3a9e-2a9a-4628-8ea1-e18e756f915f
< 0.5.1
MEDIUM 6.6 The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… wordfence
b26996cf-acea-41fb-ad2f-167f41d31cea
< 4.7.3
MEDIUM 6.6 The Malware Scanner plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, … wordfence
b10c7619-85b0-4d06-b48c-248fa3f66229 MEDIUM 6.6 The Social Login and Register plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
af387cb8-583f-4bc6-9de7-fc03fd12d01a
< 3.5.2
MEDIUM 6.6 The JetFormBuilder plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.2 … wordfence
ade6f9f2-2a35-4bb0-ab13-33b84394d965
< 22.4
MEDIUM 6.6 The Bookly plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including… wordfence
ac709779-36f1-4f66-8db3-95a514a5ea59
< 1.24.3
MEDIUM 6.6 The Import and export users and customers plugin for WordPress is vulnerable to Directory Traversal in all versions up t… wordfence
a7bd173c-dc61-4cc6-b42f-311acf728080
< 3.12.2
MEDIUM 6.6 The Elementor plugin for WordPress is vulnerable to blind SQL Injection via the 'replace_urls' functionality in versions… wordfence
a4531261-d76e-4419-b915-749c72830608 MEDIUM 6.6 The Amr Ical Events Lists plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versio… wordfence
a3171015-227d-420a-ba3a-e6e2dc17ba8c
< 1.9.171
MEDIUM 6.6 The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to SQL Injection … wordfence
9f23bf62-6008-4a9c-a7ae-a2e513699684
< 5.4.2
MEDIUM 6.6 The ShortPixel Image Optimizer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includi… wordfence
9b378df7-b182-4a56-a7fa-3228c06f960f
< 5.2.4.6
MEDIUM 6.6 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is … wordfence
96a2e7cc-23ae-404a-9889-e7bf9f744ec5
< 2.2.0
MEDIUM 6.6 The CartFlows – Checkout & Funnel Builder for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection i… wordfence
966fdfc9-7c8d-4912-80d7-7371b6fce0f3
< 7.5.2
MEDIUM 6.6 The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to PHP Object Injection in versions up to,… wordfence
94f118c3-d470-43c4-a61a-1ec998694880
< 4.0.3
MEDIUM 6.6 The GEO my WordPress plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.0.3 (exclusive) due to … wordfence
8ea6b79c-2a09-4a6e-9b4b-a81f96e3bc12
< 1.18.9
MEDIUM 6.6 The HTTP Headers plugin for WordPress is vulnerable to SQL Injection via the 'http_headers_post_import' and 'http_header… wordfence
← Prev 422 423 424 425 426 427 428 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top