πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 438 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d21c7537-8437-43aa-ab52-9e14d27a6e7f
< 3.1.7
MEDIUM 6.5 The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
d2137662-d328-4da7-986a-341ff1bdca63
< 3.4.4
MEDIUM 6.5 The iThemes Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in version… wordfence
d1a78208-0909-4134-bc78-19e395fe7e24
< 5.0.9
MEDIUM 6.5 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to ge… wordfence
d18684e3-0745-4415-a765-8c99af33aba6
< 1.3.1
MEDIUM 6.5 The Skimlinks Affiliate Marketing Tool plugin for WordPress is vulnerable to unauthorized access due to a missing capabi… wordfence
d13ccd77-a39a-4779-86e6-9cd9484ff82a MEDIUM 6.5 The Wishlist plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.44 due to insuffi… wordfence
d117d930-d210-44bf-ac49-19c003ca5a24 MEDIUM 6.5 The Gestion de tarifs plugin for WordPress is vulnerable to SQL Injection via the 'tarif' and 'intitule' shortcodes in a… wordfence
d0fd1c19-b752-4562-9365-165d709b91b2
< 2.9.9
MEDIUM 6.5 The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
d0eafb20-4ef2-448b-9da7-ad8aa9e45215
< 2.1
MEDIUM 6.5 The Simple Download Counter plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includi… wordfence
d0b4a357-fddd-4b42-8834-3a294e0d150c
< 1.8.5
MEDIUM 6.5 Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before … wordfence
d01a8636-3796-4fb3-b603-d1ef42bc3e72
< 3.7.1
MEDIUM 6.5 The GD Rating System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7 due to in… wordfence
CVE-2026-6262 MEDIUM 6.5 The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is… nvd
CVE-2026-2899 MEDIUM 6.5 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and … nvd
CVE-2026-2426 MEDIUM 6.5 The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… nvd
CVE-2026-2363 MEDIUM 6.5 The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the… nvd
CVE-2026-1793 MEDIUM 6.5 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, … nvd
CVE-2026-1651 MEDIUM 6.5 The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the 'workflow_ids' para… nvd
CVE-2026-1461
< 4.7.1
MEDIUM 6.5 The Simple Membership plugin for WordPress is vulnerable to Improper Handling of Missing Values in all versions up to, a… nvd
CVE-2026-0722 MEDIUM 6.5 The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin… nvd
CVE-2025-15470 MEDIUM 6.5 The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th… nvd
CVE-2025-11725
< 3.0.3
MEDIUM 6.5 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… nvd
CVE-2024-10938 MEDIUM 6.5 The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives … nvd
cffb26bc-3d3f-4593-bb36-d2abcd67861e
< 4.5.2
MEDIUM 6.5 The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and i… wordfence
cfd1e59a-a76d-4f6d-9d22-021afd45d9af
< 5.10.4
MEDIUM 6.5 The Better Click To Tweet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check o… wordfence
cfbbb8cf-ea03-4a99-92a2-6d0672c82190
< 4.0.0
MEDIUM 6.5 The KiviCare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.16 due to insuffi… wordfence
cfb09dcd-f8ec-4b0a-ae77-4b4b7b54c93b MEDIUM 6.5 The ElementCamp plugin for WordPress is vulnerable to time-based SQL Injection via the 'meta_query[compare]' parameter i… wordfence
← Prev 435 436 437 438 439 440 441 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top