πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 435 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e3691e6e-bc80-492c-8cbc-cb5d0cc3a689 MEDIUM 6.5 The Javo Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
e2e4b83a-34d5-4a8a-b694-a887a46fe6bf
< 1.5.0
MEDIUM 6.5 The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio… wordfence
e2ce9caf-2ca2-401c-acc7-76be2fd72f36
< 3.5.1.34
MEDIUM 6.5 The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1… wordfence
e2c8838c-d29a-4df8-85b3-6e440ba7f962
< 4.23.83
MEDIUM 6.5 The Anti-Malware Security and Brute-Force Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all vers… wordfence
e2886f2e-9cf1-4cb4-a0df-197cf65800dd
< 3.3.3
MEDIUM 6.5 The Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend plugin for WordPress is vulnerabl… wordfence
e2857fd0-2401-4e38-aa8a-3f0a89e14b78
< 4.5.1
MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection vi… wordfence
e2318ae9-4115-442e-9293-a9251787c5f3
< 2.1.18
MEDIUM 6.5 The WooCommerce Multi Currency plugin for WordPress is vulnerable to authorization bypass due to a missing capability ch… wordfence
e229ab5e-c9e3-4a7c-ac28-ba35b6abf85e
< 3.0.9
MEDIUM 6.5 The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place w… wordfence
e20deec4-f40c-4bd3-91f7-6a9d643a5520
< 3.1.4
MEDIUM 6.5 The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deleti… wordfence
e1ebbb18-0266-49e8-ada3-b63905021846
< 2.7.1
MEDIUM 6.5 The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and… wordfence
e1bbd339-5eb7-4a62-9c68-bcd76507425c
< 5.2.8
MEDIUM 6.5 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to SQL Injectio… wordfence
e1686441-3860-4b36-a3d7-b17a1d6f9686 MEDIUM 6.5 The YDS Support Ticket System plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, … wordfence
e1167864-1d46-40cb-bd75-e0d921e173c9
< 0.6.3
MEDIUM 6.5 The Attendance Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.6.2 due t… wordfence
e0b87bee-3cf0-4ab3-8fb7-4fc228eae8d0
< 1.1
MEDIUM 6.5 The Porsline plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due to insuffic… wordfence
e0891211-e4b3-4dcf-8ee0-e20abeb91640
< 2.2.1
MEDIUM 6.5 The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks… wordfence
e0365efc-f443-40a6-a365-fd36c1818242
< 3.4.8
MEDIUM 6.5 The User Meta Manager for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 3.4.7 via… wordfence
e024d5c7-d650-4303-8bf2-2958d5f9d960 MEDIUM 6.5 The Starter Templates by FancyWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,… wordfence
e014d8b6-9ce3-40ec-862e-ab5f220f1b6d
< 4.4.2
MEDIUM 6.5 The Defender Security – Malware Scanner, Login Security & Firewall plugin for WordPress is vulnerable to IP Address Sp… wordfence
dfd3e6e9-e939-4f98-8560-4dcac330ccb3 MEDIUM 6.5 The Revy plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1 due to insufficient e… wordfence
df5ddcc0-7bc2-4895-a07f-0b373802bf36
< 1.2.45
MEDIUM 6.5 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin fo… wordfence
df4f4358-af6a-4a1a-bb83-afe31b3cdb9f
< 3.14.2
MEDIUM 6.5 The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Informati… wordfence
df268fbf-c784-429e-a77a-967aac529cbd
< 2.3.1
MEDIUM 6.5 The The Sign-up Sheets plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and in… wordfence
ded1944f-662d-4d25-8277-4b1dc63b2144
< 20240511
MEDIUM 6.5 The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all v… wordfence
dec2e656-8936-43e2-b156-e96718fd7ef4 MEDIUM 6.5 The WPB Show Core plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including… wordfence
de9b0eba-5d2b-427c-a199-88bf96c26f5e
< 1.5.3
MEDIUM 6.5 Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the file… wordfence
← Prev 432 433 434 435 436 437 438 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top