🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,836
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 17, 2026
Last Updated

39,836 vulnerabilities found (page 433 of 1594)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ea233fd1-d64e-48a4-8209-b6ce7703d1c6 MEDIUM 6.5 The Woocommerce Book Price plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.… wordfence
ea183ae3-683f-4eec-b583-feefc8c62382 MEDIUM 6.5 The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all … wordfence
e9e43c5b-a094-44ab-a8a3-52d437f0e00d
< 2.8.6
MEDIUM 6.5 The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Sensitive Information Exposu… wordfence
e9c7a759-e256-4bd5-970a-1e62d188f7c5 MEDIUM 6.5 The Horsemanager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3 due to insuff… wordfence
e982d457-29db-468f-88c3-5afe04002dcf
< 3.1.3
MEDIUM 6.5 The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_ac… wordfence
e97479b1-06a0-4e24-9d2b-005bdfec9eaf
< 3.6.25
MEDIUM 6.5 The Ninja Forms plugin for WordPress is vulnerable to arbitrary file deletions in versions up to, and including, 3.6.24.… wordfence
e9160c10-8e10-44b2-b08a-612856869689
< 6.2.0
MEDIUM 6.5 The PlugNedit Adaptive Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 6.2.0.… wordfence
e897a83b-d746-427d-8c31-64d4eab5848e
< 1.5
MEDIUM 6.5 The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to … wordfence
e8596412-53d5-45ed-998a-49799bd269d0
< 7.2.0
MEDIUM 6.5 The Image Regenerate & Select Crop plugin for WordPress is vulnerable to cross-site request forgery due to missing nonce… wordfence
e7fd090d-255b-4a67-9010-9261dd79816a
< 2.7.2
MEDIUM 6.5 The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ paramete… wordfence
e7f17136-d285-4ecf-990f-66af04b5bcf9
< 2.22.6
MEDIUM 6.5 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerabl… wordfence
e7c936b8-3132-45e1-92ed-32ecdc9cbb1e MEDIUM 6.5 The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver… wordfence
e7a0b40b-560a-4f2a-ad6d-6b2284fd5f25
< 1.2.0
MEDIUM 6.5 The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vu… wordfence
e766f735-f5b2-4189-b4b1-40161c5aba8b MEDIUM 6.5 Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress all… wordfence
e7506429-7f8a-45b5-b1b0-6fdb39599ee5
< 1.5.6
MEDIUM 6.5 The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and inc… wordfence
e6de7a25-3079-4023-9faa-7a63952afe25
< 2.7.0
MEDIUM 6.5 The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including… wordfence
e69c7363-2649-45ce-8515-7a7d0c2e28ef MEDIUM 6.5 The Shuffle plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.5 due to insufficien… wordfence
e6524e66-5bd1-4616-8185-c0501a09893e
< 10.3.2
MEDIUM 6.5 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Inj… wordfence
e61faffc-1b4a-4f53-93c1-03dae5fba2e7 MEDIUM 6.5 The Reviewer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.14.2 due to insuffi… wordfence
e585998a-d78f-4923-865c-c3a9820b583f
< 2.5.3
MEDIUM 6.5 The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL In… wordfence
e53a2b7a-7005-451a-88f2-c23d420b4aad MEDIUM 6.5 The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via th… wordfence
e4dd0c6a-75af-4b53-ac13-fc4ef0e9001d
< 0.21.8
MEDIUM 6.5 The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the … wordfence
e4d9c659-ec6a-43ca-b484-02afd06f3c13
< 2.24.18
MEDIUM 6.5 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to una… wordfence
e4ca7dad-bfe2-443e-b575-362d8ff93242
< 5.1.7
MEDIUM 6.5 The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… wordfence
e4c1d21f-424c-49c7-850b-15441cd8ee56
< 2.0.7
MEDIUM 6.5 The Listeo-Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 2.0.7 due to insuf… wordfence
← Prev 430 431 432 433 434 435 436 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top