πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 431 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f4425296-5519-4c90-9bdd-00be5811b3dd MEDIUM 6.5 The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 92.0.0 due t… wordfence
f440a5c5-2a48-4beb-849f-3f7cde5a8653
< 2.0.0
MEDIUM 6.5 The Gerencianet Oficial plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … wordfence
f431ce10-dfb2-4dc5-9865-3f29cdcba156 MEDIUM 6.5 The AmaDiscount plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insuffi… wordfence
f426c32e-a376-4447-b83f-409a8eb0c499 MEDIUM 6.5 The IMPress Listings plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in vers… wordfence
f40cc632-c6af-4c8b-a455-76319f7fe151
< 3.41.0
MEDIUM 6.5 The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to time-based b… wordfence
f3bbc23b-94af-4f4f-8b5f-6af41108fd93
< 0.48
MEDIUM 6.5 The Google Authenticator plugin for WordPress is vulnerable to authentication bypass due to a missing capability check o… wordfence
f38c28f4-e73a-4eb2-8bbd-73c849385c4e
< 2.2.17
MEDIUM 6.5 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' paramet… wordfence
f35b6b83-93e7-464e-baaf-4be12e694510
< 2.4.2
MEDIUM 6.5 The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress … wordfence
f2ba40d9-2d37-453a-a731-078f1de1fc69
< 4.5.5
MEDIUM 6.5 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… wordfence
f2b7258e-c594-415a-a872-d5b28397e40d
< 1.6.19
MEDIUM 6.5 The weForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '… wordfence
f29f9290-1f98-4019-997b-e33f2c151a5d
< 3.3.3
MEDIUM 6.5 Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote atta… wordfence
f29e5b19-2505-4b02-92c7-071833de6bc2
< 3.3.1
MEDIUM 6.5 The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type… wordfence
f24749a8-e01d-436a-9ec8-3745a6b5eecf
< 4.8.21
MEDIUM 6.5 The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in … wordfence
f24003da-2d30-427c-b3f7-bbce4649c34d
< 3.6.21
MEDIUM 6.5 The My auctions allegro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.20 due… wordfence
f23dd2d7-3b21-47d6-b6da-24c20c36ee7c MEDIUM 6.5 The The TechOne - Electronics Multipurpose WooCommerce Theme ( RTL Supported ) theme for WordPress is vulnerable to arbi… wordfence
f234d676-86ac-47ab-b8b3-b0459cbb4538
< 1.3.4
MEDIUM 6.5 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… wordfence
f21e48b7-7dc7-4fd2-802c-da3c01cd5268
< 3.15.1
MEDIUM 6.5 The AppMySite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
f1ed51a3-c049-4816-ada1-49f7edcb9a6f
< 6.3.8
MEDIUM 6.5 The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c… wordfence
f1eb0852-00ef-489a-aa39-7d8603249deb
< 5.11
MEDIUM 6.5 Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au… wordfence
f13a7eab-9c15-4829-9756-c5d4961a618c MEDIUM 6.5 The include-file plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1. This make… wordfence
f119c6c2-cd4e-415a-b717-2bfc90ed729e
< 1.0.30
MEDIUM 6.5 The Piotnet Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a mi… wordfence
f1152a9d-7bc4-4fc9-a25f-cd94496b2306 MEDIUM 6.5 The The deepdigital theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ… wordfence
f10ae2b6-1580-418c-9cf7-e75ed71bb309
< 2.1.2
MEDIUM 6.5 The Product Recommendation Quiz for eCommerce plugin for WordPress is vulnerable to unauthorized modification of data du… wordfence
f105c62b-4b70-4514-a63d-6b6b78085c90
< 1.10.0.1
MEDIUM 6.5 The If-So Dynamic Content – Elementor & All Page Builders Personalization plugin for WordPress is vulnerable to SQL In… wordfence
f0c5d1f4-6c6d-413b-8f0d-a6d36556dc4a
< 4.7.9
MEDIUM 6.5 The Gallery by BestWebSoft – Customizable Image and Photo Galleries for WordPress plugin for WordPress is vulnerable t… wordfence
← Prev 428 429 430 431 432 433 434 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top