🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 426 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
775d4ba7-7198-493c-bae0-7f3f78741b90
< 1.6.6.1
MEDIUM 6.6 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
7600e7df-725d-4877-b0bf-5329f814723f
< 0.9.7.1
MEDIUM 6.6 The Customizer Export/Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
75f5f59e-b071-43aa-87a5-d7c31fb35dae
< 5.9.0
MEDIUM 6.6 The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in versions … wordfence
75b84eae-6ff2-49af-a420-2aeef50224e3
< 1.18.11
MEDIUM 6.6 The HTTP Headers plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.18.10 v… wordfence
73ea7672-4e3f-4a26-a59e-043c2cd10a7a
< 1.7.2
MEDIUM 6.6 The Page Generator plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.… wordfence
73a5058c-74e2-419d-8034-d742cb8816ac
< 2.4.3
MEDIUM 6.6 The Clearfy plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.4.2 via deser… wordfence
72eda38d-34e9-4a0e-a760-a9b991e590de
< 1.2.17
MEDIUM 6.6 The Starter Templates by Kadence WP plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and in… wordfence
72b4f6bb-59dd-453c-b089-4777dcefb11f
< 3.9.6
MEDIUM 6.6 The FormCraft Premium plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, an… wordfence
6ee577bb-7a7c-451a-a658-d3520a7475f5
< 2.4.14
MEDIUM 6.6 The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to PHP Object Injection in all versions… wordfence
6e7e6445-c1c5-48a8-a76d-819f2db1efc2
< 4.1.3
MEDIUM 6.6 The Enable Media Replace plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.… wordfence
6d94e180-8f28-453e-a01a-bfd7b6ba1cb5
< 1.4.0
MEDIUM 6.6 The Car Rental Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.… wordfence
6ab26526-9fbb-4c2e-be41-73450225b834
< 3.4.5
MEDIUM 6.6 The WooCommerce plugin for WordPress is vulnerable to PHP Object Injection by users with access to edit attributes in ve… wordfence
689878cd-3e25-49e9-9e85-28ecf5ed2e94
< 4.3.4
MEDIUM 6.6 The YayMail – WooCommerce Email Customizer plugin for WordPress is vulnerable to PHP Object Injection in versions up t… wordfence
67b450fb-eb36-4d46-aea9-a6bf624203c5 MEDIUM 6.6 The GSheets Connector plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.1… wordfence
63b472fb-c853-4e56-b34c-3cf986c4cf80
< 2.7.1
MEDIUM 6.6 The Asgaros Forum plugin for WordPress is vulnerable to unauthorized control of the plugin's settings due to an insuffic… wordfence
6322e9be-ad71-4a91-ab9f-760107d920be
< 9.0.11
MEDIUM 6.6 The Revive Old Posts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 9.0.10… wordfence
60ffe162-5bcd-4ffc-af45-81240751bc62 MEDIUM 6.6 The Responsive CSS EDITOR plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to… wordfence
6036876a-764d-4f08-96dd-b9b31dbd78b9
< 11.1.2
MEDIUM 6.6 The PixelYourSite – Your smart PIXEL (TAG) Manager plugin for WordPress is vulnerable to Local File Inclusion in versi… wordfence
5fdba41f-daa5-44e8-bc47-aa8b7bd31054
< 7.9.9
MEDIUM 6.6 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including… wordfence
5d7fb020-6acb-445e-a46b-bdb5aaf8f2b6
< 5.8.4
MEDIUM 6.6 The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation… wordfence
59e138f8-c043-4b15-a6a5-347c8e72cc99
< 1.2.4
MEDIUM 6.6 The Creta Testimonial Showcase plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… wordfence
5851b3b0-c9da-4bab-8b15-c22563063f86
< 2.0.0
MEDIUM 6.6 The Simple Login Log plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.1.3 … wordfence
555dce5e-9868-464a-9cb4-67644cc6a61c
< 3.1.7
MEDIUM 6.6 The WP Adminify plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 3.1.7… wordfence
504c0132-530b-4184-b19a-97e68df79b48
< 4.0
MEDIUM 6.6 Multiple plugins for WordPress by Trustindex.io are vulnerable to arbitrary file uploads due to missing file type valida… wordfence
4970be62-9aad-4a5f-9dd3-4bf48bded022
< 2.1.4
MEDIUM 6.6 The HollerBox plugin for WordPress is vulnerable to generic SQL Injection via the ‘get_report_data’ function in vers… wordfence
← Prev 423 424 425 426 427 428 429 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top