🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 428 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
13cfa202-ab90-46c0-ab53-00995bfdcaa3
< 1.28.0
MEDIUM 6.6 The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'for… wordfence
1388873f-8053-4ba9-8707-093bc0e8f2f5
< 2.1.79
MEDIUM 6.6 The WooCommerce Product Vendors plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions… wordfence
102e32d5-5ccc-43f8-adef-f0e2b145bf53
< 5.9.14
MEDIUM 6.6 The Icegram Express Pro plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5.9… wordfence
0e55c464-1ece-4dc2-b814-3a94ca90ae79
< 3.4.4
MEDIUM 6.6 The eCommerce Product Catalog plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and includin… wordfence
0d423c90-89ca-4295-92eb-d26acd445db0
< 3.1.16
MEDIUM 6.6 The Real Testimonials – Testimonial Slider, Collect Customer Reviews and Video Testimonials plugin for WordPress is vu… wordfence
0d3f7676-5ab0-4fe0-a0be-786f4cf84056
< 2.2.6
MEDIUM 6.6 The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to SQL Injection vi… wordfence
0c7beb26-a4ac-47a3-9ee1-64f399e3218b
< 1.0.4
MEDIUM 6.6 The User Rights Access Manager plugin for WordPress is vulnerable to unauthorized access in versions up to, and includin… wordfence
0c458644-a799-4bea-abcb-06a946dc19df
< 2.1.66
MEDIUM 6.6 The wpDataTables - Tables & Table Charts plugin for WordPress is vulnerable to PHP Object Injection in versions up to, a… wordfence
0a86f6ed-9755-4265-bc0d-2d0e18e9982f
< 2.1.5
MEDIUM 6.6 The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file up… wordfence
0a6707ef-aab7-449c-8160-034bc188a998
< 4.1.40
MEDIUM 6.6 In all current versions of WordPress Core before 6.4.3, plugins uploaded via the admin area are not verified as being ZI… wordfence
08fb51d6-30c1-4a48-b626-a8c6f203ac83 MEDIUM 6.6 The Clockwork SMS Notfications plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versi… wordfence
06863974-e428-418b-891a-ade59ee46c4f
< 6.5.0.3
MEDIUM 6.6 The SEOPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.0.2 via de… wordfence
03b1376e-8ef3-4bd2-904b-6819aa21d144
< 2.0
MEDIUM 6.6 The Computer Repair Shop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in ver… wordfence
fffd7d50-6563-4652-8fae-3fe698125c59
< 7.3.1
MEDIUM 6.5 The WooCommerce Checkout Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… wordfence
fff419fc-e617-4f7f-92c1-6b58108a993e
< 3.0.12
MEDIUM 6.5 The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 du… wordfence
fff1cff1-6745-4124-ba93-8b0749eae61a
< 1.7.1
MEDIUM 6.5 The tagDiv Opt-In Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘subscriptionCouponId… wordfence
ffe1eca0-eba0-4b4c-afe5-9bff4aa2f3f1
< 5.0.26
MEDIUM 6.5 The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX act… wordfence
ffb8c561-ce2a-447c-add6-d7e01c8c9435 MEDIUM 6.5 The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.12.7 due to … wordfence
ffb70e82-355b-48f3-92d0-19659ed2550e
< 1.0.93.2
MEDIUM 6.5 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a mis… wordfence
ff6e6101-8ba5-4cc7-9b02-67a0d9a978b6 MEDIUM 6.5 The Browser and Operating System Finder plugin for WordPress is missing authorization checks on functionality that reset… wordfence
ff5d8f5f-c7af-4789-9920-a09d2733b8ee
< 4.2.3
MEDIUM 6.5 The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option c… wordfence
ff449224-d405-453f-8c45-5c6f79bc76d6
< 1.13.13
MEDIUM 6.5 The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1… wordfence
ff294b0f-97fe-4d27-bf93-f5bbb57ac1f6
< 6.7.1
MEDIUM 6.5 The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vu… wordfence
feb0e1f0-5c0e-4a02-986b-3fbfa1b8ec1b
< 1.4.3
MEDIUM 6.5 The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… wordfence
fdc806de-9d93-4e89-a708-d4c142dd14af MEDIUM 6.5 The Easy Post Duplicator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.1 due… wordfence
← Prev 425 426 427 428 429 430 431 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top