πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 442 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
c2e770e0-1a39-4946-838b-4fd1f1dea1c8
< 1.3.8
MEDIUM 6.5 The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to unauthorized site option deletion du… wordfence
c2a166de-3bdf-4883-91ba-655f2757c53b
< 5.4.0
MEDIUM 6.5 Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various vers… wordfence
c250bc90-130a-489a-b0da-6996073f44b5 MEDIUM 6.5 The Blrt WP Embed plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.9 due to ins… wordfence
c1b81a26-c12c-4b57-9ef1-c53e0b87ad9a
< 1.7.7
MEDIUM 6.5 The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugi… wordfence
c19fde88-236d-4c27-a97c-e2fef49b7862
< 1.6.8
MEDIUM 6.5 The The Doctreat - Hospitals and Doctors Directory WordPress Listing Theme theme for WordPress is vulnerable to arbitrar… wordfence
c19dd824-eefb-4bf9-94a8-ce4be637fbac
< 1.1.11
MEDIUM 6.5 The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.10 due to in… wordfence
c19d9288-39b2-4db1-abc6-ba87f98fecad MEDIUM 6.5 Open redirect vulnerability in track-click.php in the Ad-Manager plugin 1.1.2 for WordPress allows remote attackers to r… wordfence
c15e111f-7e37-4ff5-bf1e-e472a05990a9
< 2.2.0
MEDIUM 6.5 The WP Roadmap plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insuff… wordfence
c0da4d55-5025-47cf-9f45-377d8943fc94
< 5.0.10
MEDIUM 6.5 The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… wordfence
c0b3662d-e369-4978-aa7a-debbb3ee37e4
< 3.5.1
MEDIUM 6.5 The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address values in all vers… wordfence
c093ed6a-0f3d-4ad9-a57c-cec1c2e7bd8e
< 3.0.0
MEDIUM 6.5 The WP Project Manager plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in the '/pm/v2/ac… wordfence
c0248af2-f9f3-4652-bf6d-b46aa91b66f3
< 2.2.15
MEDIUM 6.5 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' paramet… wordfence
c0179947-9346-4411-a946-09d58b556b9c MEDIUM 6.5 The Limb Gallery | Create Beautiful Image & Video Galleries plugin for WordPress is vulnerable to Directory Traversal in… wordfence
bf88b1db-ca99-4bca-857d-fdc39aa81758
< 5.4.5
MEDIUM 6.5 The LBG Zoominoutslider plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.4 due … wordfence
bf297cd8-3d67-4750-b856-38ded4daf4ad
< 3.2.20
MEDIUM 6.5 The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the β€œw… wordfence
bedfb712-faf6-4131-b254-e6d7c367f49f
< 4.7.1
MEDIUM 6.5 The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca… wordfence
be700f83-248f-4d22-b53d-7cc61e1f7d7d
< 5.2.4
MEDIUM 6.5 The Wordfence Plugin is vulnerable to multiple protection mechanism bypasses in version up to, and including, 5.2.3. The… wordfence
be5d86ad-f94b-4fcb-9b74-ecddde2bf29d
< 4.17.5
MEDIUM 6.5 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege… wordfence
be4515d8-0d5d-4925-a9a4-64ba9d51fe02
< 2.0.5
MEDIUM 6.5 WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, whic… wordfence
be39e24f-d7d7-44db-9ffd-a4605de8e577
< 2.9.6
MEDIUM 6.5 The AI Engine plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability che… wordfence
be0ef9d4-abb0-4801-b847-b84912bc6677
< 1.5.8
MEDIUM 6.5 The BCS BatchLine Book Importer plugin for WordPress is vulnerable to Unauthenticated Product Import/Update in versions … wordfence
bdf8d5c2-dbb1-47d5-b858-da6f6e1989f4
< 2.8.8
MEDIUM 6.5 The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vu… wordfence
bdf63cff-a159-42a3-a5b5-24a3623bfc1e MEDIUM 6.5 The Short URL plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.6.8 due to ins… wordfence
bdb8cb7f-38fc-41d7-aa78-abe11c6402b6
< 1.9.10
MEDIUM 6.5 The Public Post Preview plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … wordfence
bd54a50b-13ce-43ce-bce1-8fe132abc07e
< 2.6.18
MEDIUM 6.5 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for … wordfence
← Prev 439 440 441 442 443 444 445 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top