ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 440 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
cb5cb94b-1f4c-4e93-9764-c50e8449acfb
< 2.4.1
MEDIUM 6.5 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versi… wordfence
cb51383f-03c8-4e81-bfed-40fd9f5c4d20
< 5.7.6
MEDIUM 6.5 The AutomateWoo plugin for WordPress is vulnerable to unauthorized functionality access due to a missing capability chec… wordfence
cb453fe3-ba89-437c-b3fb-9ec207eaa9f0
< 9.0.8
MEDIUM 6.5 The teachPress plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tpsearch' shortcode… wordfence
cb371826-3fbd-4884-945f-cc040512dc95 MEDIUM 6.5 The LambertGroup - AllInOne - Banner with Playlist plugin for WordPress is vulnerable to SQL Injection in versions up to… wordfence
cae7dabd-ce43-43e3-9f67-b2de55bd720b
< 1.8.42
MEDIUM 6.5 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Inject… wordfence
ca989077-60c8-4bd9-a91b-fbefd2ccc49b
< 5.6.3
MEDIUM 6.5 The Client Portal Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.… wordfence
ca729178-8df0-437e-82cc-70c4975f7b47
< 2.7.3
MEDIUM 6.5 The MailPoet Newsletters plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 2… wordfence
ca6aa922-9c58-445c-b88a-3d1d1c95102c
< 4.5.4
MEDIUM 6.5 The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Authorization Bypass Through … wordfence
ca5cb925-6f95-4f81-92d0-5f3c8e5f7d59
< 3.10.0
MEDIUM 6.5 The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable t… wordfence
ca481a37-8c45-499c-bf68-3af6795af827
< 1.2.3
MEDIUM 6.5 The Predictive Search plugin for WordPress is vulnerable to unauthorized disclosure of data due to a missing capability … wordfence
c9ebc817-ccae-4ad2-8eea-eade1c2a1a0c
< 3.1.73
MEDIUM 6.5 The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ pa… wordfence
c9d07faf-cc88-4233-a552-55e3376a2fc4
< 3.11.0
MEDIUM 6.5 The FunnelKit Checkout plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check… wordfence
c9694f9b-beaa-44c9-b577-aae4fd14936b
< 1.0.23
MEDIUM 6.5 The Booktics plugin for WordPress is vulnerable to SQL Injection in versions up to 1.0.22 due to insufficient escaping o… wordfence
c940719c-f233-41bb-8866-2487ba0719e2
< 3.16.3.3
MEDIUM 6.5 The BM Content Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and excluding, 3.16.3… wordfence
c8f3c96b-9a78-47cb-9266-ff87d9409160
< 1.17.5
MEDIUM 6.5 The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje… wordfence
c8e9a333-a6b7-4b5e-93c1-b95566e5d6fb
< 2.2.8
MEDIUM 6.5 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
c8c95e9a-9d4d-4a94-bd71-d5d53085df90
< 2.48.2
MEDIUM 6.5 The Simple Giveaways plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.48.1 due to… wordfence
c8bd778b-1d56-4544-b2c3-a77a7ec05aa4
< 2.4.2
MEDIUM 6.5 The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due… wordfence
c8a14993-6faa-47fd-a066-d827ab143d9b
< 5.19
MEDIUM 6.5 The WP Tools plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.18. Th… wordfence
c87adbd9-3b09-403e-921a-31b3f58962e9
< 1.7.3
MEDIUM 6.5 The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to,… wordfence
c873c76a-144e-4945-8fa2-c9ffe0e3c061
< 3.16.5
MEDIUM 6.5 The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil… wordfence
c86f157e-e7f2-4b00-977c-c4cc7c2b3b0b
< 1.6.30
MEDIUM 6.5 The SalesKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
c84e274e-292f-4d0f-b847-4a786b4cb15a
< 2.1
MEDIUM 6.5 WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain f… wordfence
c7f041a7-f5cc-463c-97b0-d4ecb3edb77a
< 2.2.0
MEDIUM 6.5 The PopupKit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.5 due to insuffic… wordfence
c76da3a4-ec6f-4aa3-8f13-4daa212441f2 MEDIUM 6.5 The iNET Webkit plugin for WordPress is vulnerable to SQL Injection in versions up to 1.2.4 due to insufficient escaping… wordfence
← Prev 437 438 439 440 441 442 443 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top