🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 432 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f07c1aac-28c1-47fc-a2e5-fbe48a90f051
< 1.0.36
MEDIUM 6.5 The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options v… wordfence
f00015e7-f669-451e-a614-17aa12843bf3
< 4.0.2
MEDIUM 6.5 The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0.1 due to insuf… wordfence
ef9ee3e3-f6b7-400f-a977-2a3230c3b080 MEDIUM 6.5 The Database Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
ef9ad9c6-268c-4abc-8fa0-535b3612d259 MEDIUM 6.5 The 5 Stars Rating Funnel plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.01 d… wordfence
ef60c109-30e2-48e9-8599-6f226e74b6bc MEDIUM 6.5 The WP Limit Login Attempts plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, … wordfence
ef4c6f76-4d3e-4ab0-9e12-1df55a8edae5
< 1.4
MEDIUM 6.5 The Browser Theme Color plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
eecd1497-c94e-4f67-8cc5-72afffe9fae2
< 1.3.0
MEDIUM 6.5 The Be POPIA Compliant plugin for WordPress is vulnerable to SQL Injection via the 'check_id' parameter in versions up t… wordfence
eec9afef-2d71-4aa6-9b51-5be1ba51b8a5 MEDIUM 6.5 The NC Wishlist for Woocommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… wordfence
ee5e1262-193c-480b-bc27-481c961c7c47
< 2.8.2
MEDIUM 6.5 The Quick Adsense plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the se… wordfence
ee5cddbc-9162-4397-8e7a-0ec5552cc367
< 1.5.2
MEDIUM 6.5 The Xpro Elementor Addons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.1 du… wordfence
ee50731f-696f-4e9f-a930-05b2b23752de
< 2.8.7
MEDIUM 6.5 The Cost of Goods for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
edc0d90f-41a7-430a-a994-57be7fba8753
< 2.6.2
MEDIUM 6.5 The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows… wordfence
ed99a056-42c6-4540-950e-12f8b547b64d
< 2.8.5
MEDIUM 6.5 The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2… wordfence
ed2290ea-b567-487f-92b0-3a718e1ce496
< 3.4.7
MEDIUM 6.5 The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to SQL… wordfence
ecd9800e-ce0f-45f3-bb66-3690c51d885b
< 2.4.6
MEDIUM 6.5 The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PH… wordfence
ecd383f1-0546-4ff2-9f93-ee9d48ac3053 MEDIUM 6.5 The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore… wordfence
ecb40bc2-aff5-4ced-8ded-1505d7b9db45
< 2.8.28
MEDIUM 6.5 Cross-site scripting (XSS) vulnerability in the Contact Form DB (aka CFDB and contact-form-7-to-database-extension) plug… wordfence
ebcbf872-1420-4a57-a4b4-8a52ba74e0a1
< 3.4
MEDIUM 6.5 The Funnelforms Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission answers in ve… wordfence
ebbc420d-43fd-48c4-8507-6d94b9fed565
< 1.5.0
MEDIUM 6.5 The Media Sync plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.9 via the … wordfence
ebb9e37c-9e8b-429b-b4ef-cd875351852c MEDIUM 6.5 The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7… wordfence
eb6b0c35-b478-4616-a708-1fd243c95c14
< 3.6.8
MEDIUM 6.5 wordfence
ead76977-d0dc-4385-8666-c8a4694c3bbe
< 6.4.0
MEDIUM 6.5 The Site Reviews plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.2.0. This allow… wordfence
eab85a0a-f328-4cb6-b01f-d7e57540969d
< 3.6.9
MEDIUM 6.5 The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to improper… wordfence
ea49df40-e58f-4e20-8e48-ed0f9a1b94ca
< 6.7.37
MEDIUM 6.5 The Slider Revolution plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.7.36 … wordfence
ea2b5dca-42a5-49d4-800d-b268572968a9
< 9.96.0.0
MEDIUM 6.5 The VK All in One Expansion Unit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
← Prev 429 430 431 432 433 434 435 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top