πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 434 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e7f17136-d285-4ecf-990f-66af04b5bcf9
< 2.22.6
MEDIUM 6.5 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerabl… wordfence
e7c936b8-3132-45e1-92ed-32ecdc9cbb1e MEDIUM 6.5 The Omnishop plugin for WordPress is vulnerable to Cross-Site Request Forgery on its /users/delete REST route in all ver… wordfence
e7a0b40b-560a-4f2a-ad6d-6b2284fd5f25
< 1.2.0
MEDIUM 6.5 The "Duplicate Post" WordPress plugin up to and including version 1.1.9 is vulnerable to SQL Injection. SQL injection vu… wordfence
e766f735-f5b2-4189-b4b1-40161c5aba8b MEDIUM 6.5 Cross-site request forgery (CSRF) vulnerability in inc/AdminPage.php in the WP HTML Sitemap plugin 1.2 for WordPress all… wordfence
e7506429-7f8a-45b5-b1b0-6fdb39599ee5
< 1.5.6
MEDIUM 6.5 The Adning Advertising plugin for WordPress is vulnerable to file deletion via path traversal in versions up to, and inc… wordfence
e6de7a25-3079-4023-9faa-7a63952afe25
< 2.7.0
MEDIUM 6.5 The Crayon Syntax Highlighter plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including… wordfence
e69c7363-2649-45ce-8515-7a7d0c2e28ef MEDIUM 6.5 The Shuffle plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.5 due to insufficien… wordfence
e6524e66-5bd1-4616-8185-c0501a09893e
< 10.3.2
MEDIUM 6.5 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to time-based SQL Inj… wordfence
e61faffc-1b4a-4f53-93c1-03dae5fba2e7 MEDIUM 6.5 The Reviewer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.14.2 due to insuffi… wordfence
e585998a-d78f-4923-865c-c3a9820b583f
< 2.5.3
MEDIUM 6.5 The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL In… wordfence
e53a2b7a-7005-451a-88f2-c23d420b4aad MEDIUM 6.5 The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via th… wordfence
e4dd0c6a-75af-4b53-ac13-fc4ef0e9001d
< 0.21.8
MEDIUM 6.5 The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the … wordfence
e4d9c659-ec6a-43ca-b484-02afd06f3c13
< 2.24.18
MEDIUM 6.5 The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to una… wordfence
e4ca7dad-bfe2-443e-b575-362d8ff93242
< 5.1.7
MEDIUM 6.5 The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t… wordfence
e4c1d21f-424c-49c7-850b-15441cd8ee56
< 2.0.7
MEDIUM 6.5 The Listeo-Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 2.0.7 due to insuf… wordfence
e46bd083-ed21-4e2a-b79d-62d9b3c7f1d0
< 5.9.5.3
MEDIUM 6.5 The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.2 due to in… wordfence
e46a18b8-f624-4d31-ad99-c543c6a31390
< 3.3
MEDIUM 6.5 The Woocommerce Partial Shipment plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3… wordfence
e4595a79-c7d0-4e37-b19b-9ae985c9d713 MEDIUM 6.5 The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… wordfence
e458b2d6-ce72-41f8-9fc9-50156bb72895 MEDIUM 6.5 The WPGYM plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 65.0 due to insufficient… wordfence
e45207af-3886-4d95-9cd8-5ecdc683dc58
< 2.0
MEDIUM 6.5 The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to… wordfence
e3d9b2d2-d8eb-42c2-a807-ccee30798581 MEDIUM 6.5 The Sticky HTML5 Music Player plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.… wordfence
e3d4a52d-edc1-4ac7-bfe3-89d5e09ff5f4
< 2.5.7
MEDIUM 6.5 The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
e3a902a6-c16f-4e0a-a13a-defb93754c92 MEDIUM 6.5 The Task Manager plugin for WordPress is vulnerable to arbitrary shortcode execution via the 'search' AJAX action in all… wordfence
e3820f80-9b80-4672-b2ff-3864793d2de2
< 2.0.6.2
MEDIUM 6.5 The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is … wordfence
e36a09c6-158f-464a-9eb9-b47c3672c883 MEDIUM 6.5 The DELUCKS SEO plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.5.8. T… wordfence
← Prev 431 432 433 434 435 436 437 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top