πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 448 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a7f0afe8-234a-4c3f-87c8-f3f23ac94fe3
< 3.0.3
MEDIUM 6.5 The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
a7e3818c-883f-4633-a460-a8c0446edffc
< 1.1.3.2
MEDIUM 6.5 The BEAR plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.1. Thi… wordfence
a7af6721-4886-4bec-8931-992881310f26
< 1.8.4
MEDIUM 6.5 The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX action… wordfence
a7856d0f-bc7d-436c-968c-631fd6a686ab
< 3.4.5
MEDIUM 6.5 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via t… wordfence
a7764ea4-6c4b-47cf-a711-b92e56e03d3a
< 2.1.2
MEDIUM 6.5 The Amelia plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 due to insufficie… wordfence
a6bb97fa-c8cd-44bc-90ba-dd3b6a3a78da MEDIUM 6.5 The L Squared Hub WP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to in… wordfence
a697aef0-5236-464f-aea3-40d93efaba82
< 4.5
MEDIUM 6.5 The Content Views plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.4 due to insuf… wordfence
a692d9c4-66e0-4461-ad13-65e1446106c5 MEDIUM 6.5 The Hero Slider - WordPress Slider Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in … wordfence
a65e820d-afb7-4e1c-b690-5948447af59a
< 4.5.0
MEDIUM 6.5 The Nelio AB Testing plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.4.4 v… wordfence
a65a1f25-04e5-4ca3-9b2d-1b78254a8871
< 1.5.9
MEDIUM 6.5 The WordPress CTA plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
a63a41d1-b9b0-43a9-a6e0-761f3b8d9d4a
< 2.9.5
MEDIUM 6.5 The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in … wordfence
a616cee1-2aee-40bb-ab79-3bebb3438582
< 1.20.5
MEDIUM 6.5 The FooEvents for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.20… wordfence
a6072f47-91b3-4c5d-b16e-61bcd7760604
< 1.7.7
MEDIUM 6.5 The tutor_place_rating AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1… wordfence
a601d0de-2f09-4f5c-8937-dfa20f1c64ec
< 2.2.57
MEDIUM 6.5 The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin… wordfence
a5f3fbd2-6152-4a89-8fe9-982120d1a640
< 1.6.9.6
MEDIUM 6.5 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
a5c8d361-698b-4abd-bcdd-0361d3fd10c5
< 2.8.10
MEDIUM 6.5 The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8… wordfence
a5a8e4ca-c16b-4e9d-8ad2-5a671fdbc49a
< 6.3.7
MEDIUM 6.5 The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to mis… wordfence
a57426d2-0ca4-405b-bfbf-0685e2c744a0
< 4.7.20
MEDIUM 6.5 Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes passwo… wordfence
a55cfeb3-7632-4a88-ac71-8e119b060721
< 5.7.3
MEDIUM 6.5 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
a4806327-46f9-4e84-8886-c9065e1a0ceb MEDIUM 6.5 The WP Sitemap plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to insuffic… wordfence
a4647620-e06a-49d5-8f9d-a59cb5a999b1
< 1.1.31
MEDIUM 6.5 The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi… wordfence
a46364f4-9258-4f5e-9d53-dcbaf726f2f0
< 4.6.4
MEDIUM 6.5 The WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More plugin for WordPress is vulnerable to a… wordfence
a45a6b3d-49e1-4e25-aa66-15b396da8986
< 5.1.3
MEDIUM 6.5 The WooCommerce Subscriptions plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c… wordfence
a3f791dd-7c24-45e3-b4f6-b8d7e594c568
< 1.69.1
MEDIUM 6.5 The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 v… wordfence
a3d14d8f-61f4-4942-9eff-42264bb036bb
< 1.1.3
MEDIUM 6.5 The WP Mail Log plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.1.2 vi… wordfence
← Prev 445 446 447 448 449 450 451 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top