🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 447 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ab890935-d59a-4d4e-9c02-c4eceea270a9 MEDIUM 6.5 The Duplicate Page and Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 du… wordfence
ab870fc4-1651-414e-8702-cbe9829a4e75
< 6.10.2
MEDIUM 6.5 Vulnerable versions of the Jupiter Theme allow arbitrary plugin deletion by any authenticated user, including users with… wordfence
ab3b52f7-e2c3-44f7-8e19-b6c51ccd50e0
< 10.8.0
MEDIUM 6.5 The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a … wordfence
ab15fa8b-4072-435a-8a1c-ca6fd964a260
< 1.8.1
MEDIUM 6.5 The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of … wordfence
ab07e612-b561-41fc-8195-22d22fe06acd MEDIUM 6.5 The Editor Wysiwyg Background Color plugin for WordPress is vulnerable to unauthorized access due to a missing capabilit… wordfence
aa7be3a9-8a11-46c7-9fa0-7c5bda7a9846 MEDIUM 6.5 The AllInOne - Banner Rotator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8 … wordfence
aa7b7474-c170-42a2-be88-0fe410a2e71b
< 6.8.4
MEDIUM 6.5 WordPress core is vulnerable to XML External Entity (XXE) Injection via the bundled getID3 library in all versions up to… wordfence
aa698e7e-b1c7-4ead-aa2e-7fbfc9dfac80
< 2.0.7
MEDIUM 6.5 The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and includin… wordfence
aa30b959-cdf2-4b3b-9c65-d52e1d839a79
< 9.6.5
MEDIUM 6.5 The The XStore theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, … wordfence
aa1eaac2-a23b-4ef6-803a-15f7ec7e5728
< 2.4.10
MEDIUM 6.5 The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to… wordfence
aa174135-d7aa-44f1-8924-44313fc70a75
< 2.5.7
MEDIUM 6.5 The WooCommerce GoCardless Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up… wordfence
a9e4e989-8e55-4ea7-8f42-9f67cfab1168
< 1.3.2
MEDIUM 6.5 The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Acti… wordfence
a973dd0a-1a36-4ea2-a300-0f8bb277dfaa
< 3.7.2
MEDIUM 6.5 The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does … wordfence
a9576cee-2375-437e-9dc8-713209a96a73
< 3.7.8
MEDIUM 6.5 The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all version… wordfence
a920a77a-681a-4309-bce2-1f77c11c8b29
< 1.3.0
MEDIUM 6.5 The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' at… wordfence
a8ecc765-ae00-4091-81dc-e93f91bbd86e MEDIUM 6.5 The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google… wordfence
a8a31080-c124-49be-b9d1-7bc5abe7cbda
< 2.84
MEDIUM 6.5 The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions … wordfence
a8839665-8f98-4c81-b234-9201236e0194
< 2.0.5
MEDIUM 6.5 The CBX Bookmark & Favorite plugin for WordPress is vulnerable to generic SQL Injection via the ‘orderby’ parameter … wordfence
a8790df5-7228-4854-870c-1e6d3d0cfbaa
< 93.0.0
MEDIUM 6.5 The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance'… wordfence
a8360ce3-6885-418c-9950-4a5f888c703b
< 1.2.2
MEDIUM 6.5 The Client Portal – Private user pages and login plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
a83061c0-d8d3-4dbe-bf2a-65350d17094b MEDIUM 6.5 The Short URL plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data … wordfence
a82bffab-77c3-48e8-af84-39709bf0353b
< 4.4.4
MEDIUM 6.5 The LiteSpeed Cache WordPress plugin before 4.4.4 does not properly verify that requests are coming from QUIC.cloud serv… wordfence
a8208866-2bac-41e4-8a88-ae32520ff208 MEDIUM 6.5 The Flickr set slideshows plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.9 due … wordfence
a809de9f-e552-4ed0-914a-a37992dcab4b MEDIUM 6.5 The Ultra Portfolio plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.7 due to ins… wordfence
a8077d07-acaf-40f2-bc0f-e28a44ead94c
< 5.5.3
MEDIUM 6.5 The Icegram Express plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 5.5.2. This al… wordfence
← Prev 444 445 446 447 448 449 450 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top