πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 445 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b4f4fcaa-4c66-49f6-b13f-da112ae26e21
< 1.9.5
MEDIUM 6.5 A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to u… wordfence
b4b4ca5b-c806-4b68-acb8-6b63d6ca5728
< 1.2.0
MEDIUM 6.5 The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
b4b33226-59b8-4445-9f7f-ba788e8f6dbe
< 4.9.0
MEDIUM 6.5 The Daisycon prijsvergelijkers plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.8… wordfence
b4a63360-01eb-491e-b25d-501adb83f57f
< 1.7.10
MEDIUM 6.5 The wp-social-bookmarking-light plugin before 1.7.10 for WordPress has CSRF with resultant XSS via configuration paramet… wordfence
b495914d-d8f2-4592-8461-1ae1056a0855
< 2.0.8
MEDIUM 6.5 The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' p… wordfence
b47edd57-cac7-463f-88cc-8922f1b34612
< 7.5.5
MEDIUM 6.5 The Directorist plugin for WordPress is vulnerable to an Insecure Direct Object Reference in versions up to, and includi… wordfence
b4334a69-5e50-4efe-8386-f61b5f2af4b6
< 2.5.5
MEDIUM 6.5 The Job Portal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.4 due to insuff… wordfence
b409ef44-18fa-4ea0-90a4-69e03fa0116e MEDIUM 6.5 The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'ima… wordfence
b3f2c4c3-73d6-4b3b-8eb3-c494f52dc183
< 4.6.20
MEDIUM 6.5 The B2BKing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… wordfence
b3e149dd-636e-47ce-9ade-e1ae337612da
< 1.4.7
MEDIUM 6.5 The Event Calendar plugin for WordPress lacks authorization and capability checks on several of its functions reachable … wordfence
b36e94e4-b1e8-4803-9377-c4d710b029de
< 5.4.9
MEDIUM 6.5 The WP EasyCart plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.4.8… wordfence
b3365102-20f1-46e4-960f-d5986af9014d MEDIUM 6.5 The Download-Mirror-Counter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 du… wordfence
b32bf1cb-3722-41fc-be51-dabe80416b14
< 11.0.0
MEDIUM 6.5 The Quiz and Survey Master (QSM) plugin for WordPress is vulnerable to SQL Injection via the 'merged_question' parameter… wordfence
b328d8e0-46ad-4f05-8e26-21313fc7b1dd
< 2.0.15
MEDIUM 6.5 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, an… wordfence
b323d910-23f6-41e2-9d64-d60398994996
< 2.4.10
MEDIUM 6.5 The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10 performs incorrect checks before allowing an… wordfence
b308bddf-a153-4d5b-936f-2170a1a494a5
< 4.15.8
MEDIUM 6.5 The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via… wordfence
b2d26156-b88c-4cae-a830-be765e1f1473
< 4.2.8
MEDIUM 6.5 WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files be… wordfence
b2bb2d4c-eaba-45be-a86f-8acde02c946b
< 3.1.13
MEDIUM 6.5 The Actionwear products sync plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 3.1.1… wordfence
b1de31ae-4095-4863-9971-9de45c36f5a0
< 11.2.2
MEDIUM 6.5 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Inject… wordfence
b194b241-d8f4-430c-b00c-d84190026bad
< 1.6.0
MEDIUM 6.5 The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and includ… wordfence
b1938ba4-ced7-455b-8772-a192d9cb0897
< 14.16.5
MEDIUM 6.5 The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.1… wordfence
b14af68e-960f-4817-bab4-881f2720cb82
< 2.4.0
MEDIUM 6.5 The Timetable and Event Schedule WordPress plugin before 2.4.0 outputs the Hashed Password, Username and Email Address (… wordfence
b0eba1e2-d34e-4164-a7cb-55148d308439
< 2.0.6
MEDIUM 6.5 Cross-Site Request Forgery (CSRF) vulnerability in WordPress uListing plugin (versions <= 2.0.5) makes it possible for a… wordfence
b0eb165f-c979-4318-8362-ca47500ed845
< 7.2.0
MEDIUM 6.5 The Image Regenerate & Select Crop plugin for WordPress is vulnerable to unauthorized modification and deletion of data … wordfence
b0c232b2-f7c8-4a8d-b282-72f61ecfc5da
< 1.1
MEDIUM 6.5 The Page Expire Popup/Redirection for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the '… wordfence
← Prev 442 443 444 445 446 447 448 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top