πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 429 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fd8f3eb7-ac60-46c4-b41f-5d89e3133042
< 1.5.7
MEDIUM 6.5 The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versi… wordfence
fd80133d-03c7-4ecb-ad2c-98950f788ca6
< 7.38
MEDIUM 6.5 The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to SQL Injection in all ver… wordfence
fd7916f3-7844-4f3f-87ae-a8a66a9f3dec
< 3.1.7
MEDIUM 6.5 The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies. wordfence
fd28c405-ed2f-435a-806c-1fc43cac0f80
< 4.0.2
MEDIUM 6.5 The Sreamit theme for WordPress is vulnerable to arbitrary file downloads in all versions up to, and including, 4.0.1. T… wordfence
fd063077-7fda-4c64-abc8-c7456c3dc2b8
< 2.6.9
MEDIUM 6.5 The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable … wordfence
fc56aeb0-eba1-4196-aac9-e5723674cd1a
< 3.2.8
MEDIUM 6.5 The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.8 due to insufficient escaping on … wordfence
fc48f75d-a2e8-49ea-9bfa-a27a61ff8a84
< 1.6.3
MEDIUM 6.5 The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability … wordfence
fba36ebc-a396-4eb8-8cb6-afc50b9c974e MEDIUM 6.5 The Bucketlister plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode `category` and `id` attr… wordfence
fb7fd98d-de1d-4b06-b769-92df40bc1873
< 4.5.9
MEDIUM 6.5 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… wordfence
fb77413e-3e7a-4315-8dde-59ac4e2534ae
< 2.4.11
MEDIUM 6.5 The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
fb291c79-8b8e-476b-b6e4-e8428bf60d6e MEDIUM 6.5 The Filter Portfolio Gallery WordPress plugin through 1.5 is lacking Cross-Site Request Forgery (CSRF) check when deleti… wordfence
faffd8e3-b110-4ba3-98c1-22aee7f19586 MEDIUM 6.5 The Commenter Emails plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.6.1. This a… wordfence
fab4db72-e8d6-4417-ba40-a55f395beb35
< 1.0.2
MEDIUM 6.5 The Category Icon plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.1. This… wordfence
fa48aeb9-5d20-43c4-8177-30730852eeb0 MEDIUM 6.5 The WooMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
fa2bb0c0-e412-4e78-a7b5-4517f1c15481
< 1.0.1
MEDIUM 6.5 The Mail Subscribe List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bwsmn_form_email' par… wordfence
fa15939c-44eb-45e5-95d7-49307912f21c
< 2.0.0
MEDIUM 6.5 The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in a… wordfence
f9fcd12b-bcc8-48cb-a077-ccf1bc4ff276
< 3.1.3
MEDIUM 6.5 The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/options-general.php CSRF. wordfence
f9989f22-d5a0-453a-86e8-dc45c7cdd5dd
< 1.1.5
MEDIUM 6.5 The TH Advance Product Search plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
f99192a3-7ca1-4a19-aa9c-f2fc04fd2d1f MEDIUM 6.5 The AI Quiz plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check… wordfence
f98acfe6-b012-47c6-b47e-66a4304d3501
< 1.5.6
MEDIUM 6.5 The Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.5 due to ins… wordfence
f979e58a-9520-4b6b-82ee-421380552593 MEDIUM 6.5 The LambertGroup - AllInOne - Content Slider plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
f9661fa8-1c69-433b-8e18-039000e7d6e7
< 6.5.0
MEDIUM 6.5 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulne… wordfence
f94eabc5-6e3b-46df-9e36-d7d0fad833de
< 2.7.0
MEDIUM 6.5 The Kraken.io Image Optimizer plugin for WordPress is vulnerable to authorization bypass due to a missing capability che… wordfence
f8ed68ab-1f25-4683-b4a3-60de785681b1 MEDIUM 6.5 The AI Hub - Startup & Technology WordPress Theme theme for WordPress is vulnerable to Path Traversal in all versions up… wordfence
f8d4029e-07b0-4ceb-ae6e-11a3f7416ebc
< 2.7.0
MEDIUM 6.5 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized modification o… wordfence
← Prev 426 427 428 429 430 431 432 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top