πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 439 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cf1ca22a-7fb6-457c-bde0-83f6744185be
< 1.8.10
MEDIUM 6.5 The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks… wordfence
cf0fb349-4cb8-4cf3-ae7c-5c4dcc6fd4f7
< 2.6
MEDIUM 6.5 The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access o… wordfence
cec13225-baa3-4f26-b2d2-af6106888c74
< 10.6.0
MEDIUM 6.5 The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
ce88f1e7-969b-4d43-a12c-da2812d3bfec MEDIUM 6.5 The Image&Video FullScreen Background plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
ce8474eb-a521-4739-bc3f-3782deb3bc9f
< 4.7.5
MEDIUM 6.5 The WC Shop Sync – Square Payment Gateway and Product Synchronization for WooCommerce plugin for WordPress is vulnerab… wordfence
ce8397d5-6637-4faa-be1f-9cf52c25be9b
< 1.5.1
MEDIUM 6.5 The Passwords Manager plugin for WordPress is vulnerable to SQL Injection via the $wpdb->prefix value in several AJAX ac… wordfence
ce70da8e-7273-4eca-b187-2db7c36f1a50
< 6.4.9
MEDIUM 6.5 The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via … wordfence
ce6b9b0a-e82e-459a-bddf-1c9354bcec00
< 1.2.5
MEDIUM 6.5 The GTG Product Feed for Shopping plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
ce3cb2e9-6491-4b93-bd98-1ece39171b0c
< 3.20.6
MEDIUM 6.5 The Happy Addons for Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.2… wordfence
ce2d582e-4f50-4b55-9f3b-3c46d96c0927
< 1.2.4
MEDIUM 6.5 The Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links plugin for WordPress is vulnerable … wordfence
cdf3b629-c1a2-4fdd-b7fc-d3550bd30857
< 1.2.1
MEDIUM 6.5 The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to unautho… wordfence
cdaa7450-3b51-470d-8903-52fd1d4215a2
< 3.6.4.4
MEDIUM 6.5 The Uncanny Toolkit for LearnDash plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
cd9e0044-263e-453a-b9e5-b3c6b98e90be
< 7.3.2
MEDIUM 6.5 The Restricted Site Access plugin for WordPress is vulnerable to IP Spoofing in versions up to, and including, 7.3.1 du… wordfence
cd959968-d3f0-4546-8fc6-eb451b417f0d MEDIUM 6.5 The Task Manager plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.0.2 v… wordfence
cd85da97-f62c-4c4e-ae29-dea5aa529f54
< 1.9.2
MEDIUM 6.5 The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain… wordfence
cd6ce97c-fd80-4c43-a4d2-02aa91d11fac MEDIUM 6.5 The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check… wordfence
cd64b4cb-955a-4942-9837-bdf0e6a1b48a
< 3.1.3
MEDIUM 6.5 The Pricing Tables WordPress Plugin WordPress plugin before 3.1.3 does not verify the CSRF nonce when removing posts, al… wordfence
cd2951c4-6450-48a3-bcfb-5c74dc778ee7 MEDIUM 6.5 The CSV Product Import Export for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and… wordfence
cd224169-ae51-4af8-b6de-706ed580ff8d
< 7.11.6
MEDIUM 6.5 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to Sensitive Information Expos… wordfence
ccd73030-7185-4302-b3fd-29cbbe716e3e
< 3.1
MEDIUM 6.5 The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and i… wordfence
cc938f6b-29fd-4f4f-b569-8b81a607ad47
< 2.11.0
MEDIUM 6.5 The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
cc465757-4295-4a75-90f6-92c4be4e8944
< 1.6.8
MEDIUM 6.5 The ReviewX plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.6.7. This allows una… wordfence
cc0b766a-b7fd-4950-9868-de3308123229
< 2.0.16
MEDIUM 6.5 The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of … wordfence
cc06a6d7-4fd9-450d-99f2-3f40343a9555
< 2.3.5
MEDIUM 6.5 The iubenda-cookie-law-solution plugin before 2.3.5 for WordPress does not restrict URL sanitization to http protocols. wordfence
cb753b29-ca8c-4044-97ff-3b7e57d5de61
< 5.0
MEDIUM 6.5 The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and … wordfence
← Prev 436 437 438 439 440 441 442 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top