ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 427 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
47aed582-efb6-4caf-a65b-57995907ecaa
< 2.1.4
MEDIUM 6.6 The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all… wordfence
477d3d7a-6028-4dd3-b713-6098bfe32832
< 2.35.0
MEDIUM 6.6 The 404 Solution plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 2.35… wordfence
43b72542-623f-4ecf-892b-273cb6a8d6cf
< 2.1.12
MEDIUM 6.6 The LTL Freight Quotes – Day & Ross Edition plugin for WordPress is vulnerable to PHP Object Injection in versions up … wordfence
433ab82d-31ce-4386-ab1b-6d3498d7722a
< 4.1.20
MEDIUM 6.6 The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.1.19. This ma… wordfence
4284c31c-fa58-49fe-89ed-35d7b1bd6ec8
< 19.1.5
MEDIUM 6.6 The Contest Gallery Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 d… wordfence
3f0ed355-b5c8-4143-b391-7436d67ba0de
< 1.20.24
MEDIUM 6.6 The E2Pdf – Export To Pdf Tool for WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parame… wordfence
3bc8e26f-0a35-4223-b69a-e9f0b4f13cc8 MEDIUM 6.6 The Aitasi Coming Soon plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … wordfence
39ec49b4-f0f3-4ec7-b11b-ce808c025577
< 1.1.8
MEDIUM 6.6 The Simple User Import Export plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, … wordfence
391f76a1-098b-4b88-be71-4270d9942c66
< 269.2
MEDIUM 6.6 The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to PHP Object Injection in… wordfence
37426991-7778-4dc4-8cae-2725584fb8b8
< 1.1.5
MEDIUM 6.6 The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation i… wordfence
360a022d-8530-48af-be34-77d6b4b5c19d
< 2.2.0
MEDIUM 6.6 The All In One Redirection plugin for WordPress is vulnerable to SQL Injection via the request URI in versions up to, an… wordfence
3498c871-9404-4d12-9609-16fecf218b30
< 2.0.14
MEDIUM 6.6 The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Obj… wordfence
34267e02-4270-4656-a946-e4895f796786
< 2.1.0
MEDIUM 6.6 The HT Contact Form 7 plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0… wordfence
32b2b8e9-aa49-4cc3-97b7-249695969461
< 5.7.8
MEDIUM 6.6 The Media File Renamer: Rename Files (Manual, Auto & AI) plugin for WordPress is vulnerable to Remote Code Execution in … wordfence
304765f9-772c-4d47-b929-08fd708736ab MEDIUM 6.6 The eDS Responsive Menu plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2… wordfence
2f796373-7116-4fd3-9d53-5f520e6e1a0c
< 4.1.5
MEDIUM 6.6 The LearnPress – Backup & Migration Tool plugin for WordPress is vulnerable to PHP Object Injection in all versions up… wordfence
2b821728-eb16-4157-906f-96f6420fa850
< 2.1.5
MEDIUM 6.6 The Easy Invoice plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.4. Thi… wordfence
2a69576e-4796-421a-b6ee-08a3b40d4805
< 9.4.3.1
MEDIUM 6.6 The Booking Calendar plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and… wordfence
2881e144-a109-4034-afe8-2f72efd70360
< 1.0.13
MEDIUM 6.6 The History Log by click5 plugin for WordPress is vulnerable to time-based SQL Injection via the mail log functionality … wordfence
27a36e90-9678-4832-9f37-b54fe75f5571
< 20.9.0
MEDIUM 6.6 The Popup Box Business and Developer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin setting… wordfence
1a1fc6c9-50cd-40fd-a777-9eed98aab797
< 4.3.4
MEDIUM 6.6 The NinjaFirewall plugin for WordPress is vulnerable to Authenticated PHAR Deserialization in versions up to, and includ… wordfence
17b16fa4-9ea7-4bc5-accb-8249ed7280aa
< 1.3.10
MEDIUM 6.6 The Small Package Quotes – USPS Edition plugin for WordPress is vulnerable to PHP Object Injection in versions up to, … wordfence
17a787da-5630-42ec-b5b0-47435db765a7
< 1.6.3
MEDIUM 6.6 The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the ‘txtsearch’ parameter in v… wordfence
15f38932-2687-4d71-8793-843058a657d1
< 6.9
MEDIUM 6.6 Authenticated Stored Cross-Site Scripting (XSS) vulnerability in WordPress Absolutely Glamorous Custom Admin plugin (ver… wordfence
1597859c-2808-4e0f-aa8d-4e2727728e22
< 3.7.20
MEDIUM 6.6 The Dokan plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.7.19 via deseri… wordfence
← Prev 424 425 426 427 428 429 430 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top