πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 449 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a3b1b581-eb22-4a45-9f3d-55f0b1d3b5d8
< 3.8.6.4
MEDIUM 6.5 The Brands for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.8.6.3… wordfence
a3aa680f-4ce2-43b2-81fb-c664e398c868
< 5.7.10
MEDIUM 6.5 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQ… wordfence
a388b406-1640-443d-9656-6a87588ce201
< 3.10.1
MEDIUM 6.5 The Profile Builder Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
a3647a25-999f-44c0-9eeb-54f143e77b0c MEDIUM 6.5 The WP Google Calendar Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1… wordfence
a35aa722-041f-4126-b742-bcf5219424ed MEDIUM 6.5 The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1… wordfence
a2e05094-8344-4388-a703-518daf3d2948
< 1.1.30
MEDIUM 6.5 The Materialis theme for WordPress is vulnerable to limited arbitrary options updates in versions up to, and including, … wordfence
a27c6935-adad-47c7-a387-9a4d297c383f MEDIUM 6.5 The WC Wallet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
a26da53c-4be0-4c9f-9caf-05f054a6d5e7 MEDIUM 6.5 The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a de… wordfence
a21b7c40-2090-4262-9105-346db2325612
< 2.6.16
MEDIUM 6.5 The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i… wordfence
a1dbc2ca-eb3f-4c0f-a5c0-28579f694237 MEDIUM 6.5 The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field vi… wordfence
a1cbe205-1858-4561-a87a-c3908c91370f
< 1.0.6.4
MEDIUM 6.5 The Fox LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.6.3 due to insuffi… wordfence
a1c6ad5a-bc76-4012-acc6-35f742e0869e
< 1.0.0
MEDIUM 6.5 The ActivityPub plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including,… wordfence
a195dc44-4047-4c80-817a-cd5e267c0b55 MEDIUM 6.5 The The RS WP Book Showcase – A Complete Book Catalogue & Library System plugin for WordPress is vulnerable to arbitra… wordfence
a1887469-f362-405b-b171-1900c0846aa0
< 5.0
MEDIUM 6.5 The WP Links Page plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.9.6 due to ins… wordfence
a15e917f-f46a-4006-a4cb-3d55331ccb5b
< 3.39
MEDIUM 6.5 The NextGEN Gallery plugin for WordPress is vulnerable to Arbitrary File Read and Deletion in versions up to, and includ… wordfence
a155c289-558c-4209-8d9a-bf085fecaf8a
< 4.10.35
MEDIUM 6.5 The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to… wordfence
a10cb85d-65f1-4e34-8614-f161d4746797 MEDIUM 6.5 The DriCub theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in v… wordfence
a0f2e2f4-6575-4f00-9417-3b5a19c3de40
< 6.0.0
MEDIUM 6.5 The Highcompress Image Compressor plugin for WordPress is vulnerable to unauthorized modification of datadue to a missin… wordfence
a0e5fcfa-ebc9-45f6-9cbc-c9e3540baa6f
< 5.9.3.7
MEDIUM 6.5 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modificatio… wordfence
a09d45fd-13e7-4180-bb3b-bd5ede21324b
< 2.1.3
MEDIUM 6.5 The Organici Library plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.2 due to … wordfence
a089026a-5da9-467c-a1e4-622bb74363e2
< 2.0.3
MEDIUM 6.5 The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on … wordfence
a057ad05-0ed7-48c4-9dc1-0e7b1d3cb270
< 1.3.2
MEDIUM 6.5 The Headline Analyzer plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability … wordfence
a04e6a18-c1ce-4204-b9ca-31ea4106bd7c MEDIUM 6.5 The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.4.0 due… wordfence
a0299b95-abbf-43c4-81d0-7c383d92cffe
< 1.9.8
MEDIUM 6.5 The ActiveCampaign plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
a018fcb1-b7a6-456f-ab0b-59ccc1fd5b67
< 1.2.42
MEDIUM 6.5 The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL… wordfence
← Prev 446 447 448 449 450 451 452 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top