🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 446 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b0aec8f4-9c22-4e44-989b-359442c1e6c7
< 3.28.5
MEDIUM 6.5 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3… wordfence
b052b334-751e-4d70-9713-0c214cf932c2
< 2.1.5
MEDIUM 6.5 The Bug Library plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.4 due to insuf… wordfence
b0382227-48eb-4a97-8f3c-5c8fc4bcc0b6
< 3.7.4
MEDIUM 6.5 The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, doe… wordfence
affb5746-0af7-488e-872d-5c78e517897b MEDIUM 6.5 The Gallery Widget plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.1 due to in… wordfence
aff636ac-5bb5-4804-adf4-358ef3158d2d
< 2.7.3
MEDIUM 6.5 The MailPoet Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'encodedForm' para… wordfence
af93f4f5-4c6d-4178-b7f7-c66c341bde87
< 3.8
MEDIUM 6.5 The DoLogin Security plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
af7adacf-7189-401f-b7c9-845eb328ca76
< 0.9.77
MEDIUM 6.5 The WPvivid Backup plugin for WordPress is vulnerable to Path Traversal in version 0.9.76 due to a newly introduced dele… wordfence
af4bd5f6-4f0e-4035-8544-48154a05cef1 MEDIUM 6.5 The Plugin: CMS für Motorrad Werkstätten plugin for WordPress is vulnerable to SQL Injection via the 'arttype' paramet… wordfence
af455697-59da-488e-82fe-bb0fad65a810
< 0.3.5
MEDIUM 6.5 The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on … wordfence
af3c8ea5-0af8-492b-920d-858bf23ca6f0
< 6.2.7.1
MEDIUM 6.5 The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable t… wordfence
aec4d370-58c0-466f-b3bb-9676fc744d96
< 2.3.29
MEDIUM 6.5 The Contact Form builder with drag & drop - Kali Forms plugin for WordPress is vulnerable to unauthorized access due to … wordfence
aea5f970-243f-4642-83e1-34db11c4ca63
< 3.9.8
MEDIUM 6.5 The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via th… wordfence
ae58e5b0-b587-4503-8519-c5a50245891a
< 1.6.6
MEDIUM 6.5 The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to and including 1.6.5. This i… wordfence
ae0abace-9bf6-4ef9-a9b8-7efffbf25628 MEDIUM 6.5 The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in… wordfence
ada2e0f5-1214-4356-944c-655c5561e97e MEDIUM 6.5 The Interview plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.01 due to insuffic… wordfence
ad943111-24c1-4ff9-b34a-aa4e1ee8ee75
< 3.7.4
MEDIUM 6.5 wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and ui… wordfence
ace46bae-5dfb-4cdf-bd9e-d68282be16d0 MEDIUM 6.5 The Footer Putter plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including… wordfence
ac97c729-4c75-429b-bbf2-27ca322be1cf
< 2.7.1
MEDIUM 6.5 The FastDup – Fastest WordPress Migration & Duplicator plugin for WordPress is vulnerable to Path Traversal in all ver… wordfence
ac805f12-a7fc-4a04-8779-09e6096f4400
< 1.15.45
MEDIUM 6.5 The Form Maker by 10Web plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.15.44 du… wordfence
ac5549ec-f931-4b13-b5f9-0d6f3e53aae4
< 5.1
MEDIUM 6.5 The demon image annotation plugin for WordPress is vulnerable to improper input validation in versions up to, and includ… wordfence
ac4ebdd1-f28a-4b88-bd92-5d0e9cce6790
< 1.1
MEDIUM 6.5 The Geo to Lat plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.19 due to insuf… wordfence
abcbb84c-6c2d-40c1-8c64-7d4866fa9503 MEDIUM 6.5 The Twitter posts to Blog plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab… wordfence
abc13da0-8d1e-4ecd-80c8-d7fe5fb31a6d
< 3.2.6
MEDIUM 6.5 The Traveler theme for WordPress is vulnerable to SQL Injection in versions up to 3.2.6 due to insufficient escaping on … wordfence
abb1a758-5c16-4841-b1c7-0705ab16b328
< 1.2.3
MEDIUM 6.5 The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m… wordfence
ab9d3fa4-f2b1-4f38-b928-a1220cfeca75 MEDIUM 6.5 The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in place when deleting publi… wordfence
← Prev 443 444 445 446 447 448 449 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top