πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 437 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d75cce66-35b5-4915-b29b-9a1ef648ec16 MEDIUM 6.5 The WordPress Custom Sidebar plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3 d… wordfence
d7324a4e-ff45-4908-bcaa-379b130f73c0 MEDIUM 6.5 The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜tab’ paramet… wordfence
d6fa45e2-d082-472f-920d-35cb26d7261b MEDIUM 6.5 The BWL Pro Voting Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.9 d… wordfence
d6d0651a-c2e2-4985-927c-b60e80475450
< 3.6.28
MEDIUM 6.5 The MasterStudy LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.27 due to … wordfence
d662846b-c694-4030-ade1-f0d5bc811e12
< 5.4.5
MEDIUM 6.5 The Meow Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due to insu… wordfence
d592141d-191b-4739-bc0a-07549ef2f31b
< 2.9.1.7
MEDIUM 6.5 The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_… wordfence
d57e6739-2cae-4755-8fdf-25b74dac6792
< 3.0.4
MEDIUM 6.5 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection in versio… wordfence
d56ce525-c6af-42ac-9c74-ffce65dda2ae
< 3.6.14
MEDIUM 6.5 The KiviCare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.13 due to insuffi… wordfence
d52332cc-ba8d-4e7f-981a-c829fd45b5c4 MEDIUM 6.5 The Sticky Radio Player plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4 due to… wordfence
d4db7f56-41c7-497a-8e83-460450644d5b MEDIUM 6.5 The The Uminex - Multipurpose WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in al… wordfence
d4b17cce-bb52-4125-8c85-6da15517275f
< 5.78
MEDIUM 6.5 The Ebook Store plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on t… wordfence
d4a7c647-4c57-499a-8e46-ca273985bd6d
< 1.1.7
MEDIUM 6.5 The Contact Form to Any API plugin for WordPress is vulnerable to unauthorized modification/loss of data due to a missin… wordfence
d466b837-e5be-4e0b-9d92-483f2f5fecef MEDIUM 6.5 The Plugin A/B Image Optimizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl… wordfence
d45eb4e4-b59b-479a-a49b-2ca6d254aa01
< 2.8
MEDIUM 6.5 The Custom Field Template plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7.8 du… wordfence
d3cda8d0-321c-4b15-980e-5ebf49fac367
< 3.14.0
MEDIUM 6.5 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification … wordfence
d3bc5ef7-6825-463f-a3ce-d6ab1fc0e030
< 4.8.8
MEDIUM 6.5 The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7… wordfence
d3aa8d64-a0d1-49ad-ad92-e2a2bf066fe1
< 3.4.1.3
MEDIUM 6.5 The Watu Quiz plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.4.1.2 due to insuf… wordfence
d396ed2e-ae33-4cc8-a943-df33d9f1aeb4 MEDIUM 6.5 The Ohio Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,… wordfence
d396e90b-c113-4534-8ce3-27bea3bd7296
< 1.2.3
MEDIUM 6.5 The Predictive Search plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to miss… wordfence
d386f842-24f6-4b09-a2eb-cbf7712f7123
< 4.2
MEDIUM 6.5 The ARPrice plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1.3 due to insuffici… wordfence
d352e4d1-92ab-482b-8fce-90ee3e22ba3c
< 3.9.2
MEDIUM 6.5 The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, El… wordfence
d2ead824-2722-4b09-8387-e064dee371c1
< 1.3.3.6
MEDIUM 6.5 The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute… wordfence
d2a63b8e-e16e-4702-be1b-acc5c3e74b22 MEDIUM 6.5 The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing … wordfence
d2365e92-d70d-47fa-9abe-7cbdd6336f39
< 4.2.9.4
MEDIUM 6.5 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to… wordfence
d2266254-9281-4859-8630-f7bb5c0ead19
< 8.2.3
MEDIUM 6.5 The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter… wordfence
← Prev 434 435 436 437 438 439 440 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top