πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 430 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f8befbf2-0d9d-4d0e-87de-0f1b26c0acd0 MEDIUM 6.5 The Sales Report Email for WooCommerce plugin for WordPress is missing a capability and nonce check in several functions… wordfence
f89737cf-90f0-4d85-a7b3-f633047eb93c
< 10.2.5
MEDIUM 6.5 The Quiz And Survey Master plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.2.4 … wordfence
f8945eed-eee4-4043-b6ab-d1ea553a4a23 MEDIUM 6.5 The WP-Addpub plugin for WordPress is vulnerable to SQL Injection via the 'wp-addpub' shortcode in all versions up to, a… wordfence
f883823f-c225-4cd2-a0f6-39013476ed83
< 9.7.3.1
MEDIUM 6.5 The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the booking form fields in ve… wordfence
f88286b9-16b2-42a9-b8c6-0a6fe6c136ef
< 1.6
MEDIUM 6.5 The "Forminator Contact Form, Poll & Quiz Builder" plugin before 1.6 for WordPress has SQL Injection via the wp-admin/ad… wordfence
f87df7cc-54bb-454c-94be-c8c4768cbe44
< 2.8.5
MEDIUM 6.5 The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file read due to missing restrictions to proper f… wordfence
f8544784-1994-47e2-be39-568d0ab9ee00
< 0.9.2.4
MEDIUM 6.5 The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all vers… wordfence
f7e2246d-704c-40df-ab82-ffdb85e78cd3 MEDIUM 6.5 The Ray Enterprise Translation plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
f7d2a830-4b66-4875-98b1-4730c3b6ae4b MEDIUM 6.5 The Duplicate Title Checker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 du… wordfence
f7c39d66-f1e1-4d41-a9e4-984aec3f37dc
< 1.22.27
MEDIUM 6.5 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
f77e2d1e-7925-4343-9c22-5b77ea0d439b
< 3.4.8
MEDIUM 6.5 The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to SQL Injection in versions up to, and in… wordfence
f76a757b-8eac-4e54-ae0e-3f0a491ff582
< 3.4.3
MEDIUM 6.5 The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up t… wordfence
f72ad187-9745-4d0b-8cb0-5bf07ab1e2ac MEDIUM 6.5 The Distance Rate Shipping For WooCommerce plugin for WordPress is vulnerable to SQL Injection in all versions up to, an… wordfence
f719d624-d6f9-4095-abaf-f2ba9e448710 MEDIUM 6.5 The Workreap (theme's plugin) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.3.… wordfence
f68ac2b8-33dc-4cc2-b0f3-8777450e39f9
< 2.0.0
MEDIUM 6.5 The Pro Mime Types plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
f673e463-5ef0-4704-91a1-76e375df9d1c
< 2.9.9.5.2
MEDIUM 6.5 The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.9.… wordfence
f6043cff-f2b7-46bb-b00d-96bfcd69e54e
< 4.9.1.1
MEDIUM 6.5 The All In One SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.1 due … wordfence
f5e92e16-606e-4540-9116-26fe77fe4142 MEDIUM 6.5 The Review Stars Count For WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
f5da4cdd-15c7-41a6-be2f-e31bd407ae05
< 3.0.5
MEDIUM 6.5 The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized… wordfence
f53d9579-56e9-41aa-b6b7-2472734ee719
< 21.0.10
MEDIUM 6.5 The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… wordfence
f5266ae5-1e38-4f76-9137-1fcf94ed59b8 MEDIUM 6.5 The Simple Personal Message plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.3 … wordfence
f4fcc6e5-1f90-41e7-8d5a-2bfe8cbf46fa MEDIUM 6.5 The Flashcard plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.9 via the 'so… wordfence
f47d50dc-ec14-40c8-95a2-f393986ed71b
< 2.6
MEDIUM 6.5 There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settin… wordfence
f46b01e4-1022-45aa-8511-6d2519e4e562
< 1.0.8.2
MEDIUM 6.5 The WP Setup Wizard plugin for WordPress is vulnerable to unauthorized access of datadue to a missing capability check i… wordfence
f4618bfd-77d9-4396-b041-d7ba0f6ec75a
< 3.6.3
MEDIUM 6.5 The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri… wordfence
← Prev 427 428 429 430 431 432 433 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top