πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 450 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9fdf6c97-6fc4-4840-b96d-e194149861e4 MEDIUM 6.5 The Rolo Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
9f9e5bf6-c988-4bd5-9328-69a2034ab1c4
< 3.0.2
MEDIUM 6.5 The JS Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.1 due to insu… wordfence
9f70377f-5b9d-4595-b22c-88aa30900a6f
< 3.33
MEDIUM 6.5 The Media LIbrary Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.32 d… wordfence
9f6a358a-333c-4eb7-9149-348bf3713943
< 3.2.17
MEDIUM 6.5 The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.… wordfence
9f51ea60-7bda-4627-9b65-d1ff402dfc88 MEDIUM 6.5 The Better Anchor Links plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
9efac984-21ef-4e02-8ead-bf4205ddb38d
< 3.2.4
MEDIUM 6.5 The Insert Pages plugin for WordPress is vulnerable to directory traversal via custom template paths in versions before … wordfence
9eb7fc3a-6575-42ed-9304-d8ce02a849c2
< 2.2.2
MEDIUM 6.5 The Publitio plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.1. This make… wordfence
9e6837ad-576f-4c25-9540-6144ddc8630e
< 3.20.6
MEDIUM 6.5 The The Germanized for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution via 'account_hold… wordfence
9e37c664-76ed-4ede-88fd-e41b9969685f
< 0.5.0
MEDIUM 6.5 The Custom Query Shortcode plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.… wordfence
9e1fa691-3934-4e15-b339-e679976d6d5c
< 2.2.7
MEDIUM 6.5 The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could all… wordfence
9e052577-185b-485e-8b7c-a4e7802025c5
< 2.0.9
MEDIUM 6.5 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
9dfca4cb-71dc-4b2d-bcf3-0ca9f88f88df
< 10.0.1
MEDIUM 6.5 The Jetpack plugin for WordPress is vulnerable to arbitrary file manipulation in versions up to, and including, 12.1. Th… wordfence
9de09daa-a3e0-4563-bdc9-79cb5e4b039b
< 7.9
MEDIUM 6.5 The SEO Redirection Plugin – 301 Redirect Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in … wordfence
9c819a98-033e-4ef8-a295-bf1a3518f63a
< 7.8.8
MEDIUM 6.5 The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress i… wordfence
9bf5b60b-5a4f-4227-97ac-a952019f46d9
< 5.2.1
MEDIUM 6.5 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
9bc6d516-7636-45b2-ade1-c8f2297f0ea1
< 7.0.5
MEDIUM 6.5 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via … wordfence
9b5618b1-99fe-422a-9485-d51342e178b3
< 1.16.11
MEDIUM 6.5 The ERP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.16.10 due to insufficien… wordfence
9b2f01fe-ea54-4b64-9e48-ccf4681c42f8
< 4.19
MEDIUM 6.5 The Accessibility Suite by Online ADA plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
9a866dfd-2374-4a66-9dee-b8bda47d1cc7
< 2.2.0
MEDIUM 6.5 The StoreEngine β€” Complete eCommerce Solution with Memberships, Licensing, Affiliates & More plugin for WordPress is v… wordfence
9a812aad-d769-4c28-8035-471bd3a50faa
< 3.6.9.1
MEDIUM 6.5 The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to arbi… wordfence
9a6b05b1-c649-4b72-b884-11fb83ec77f2
< 1.5.7
MEDIUM 6.5 The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capab… wordfence
9a57bd92-c819-436f-b7ea-727c9b9f45e5
< 2.6.5
MEDIUM 6.5 The The Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More plugin f… wordfence
9a552f81-b222-46f0-b318-702e09d249c1 MEDIUM 6.5 The Demo Awesome plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che… wordfence
996cb291-692d-4892-a3ab-ffad960ba732 MEDIUM 6.5 The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Inj… wordfence
99277269-e7e7-4445-a901-fc4f1bec778d MEDIUM 6.5 The Mediabay - WordPress Media Library Folders plugin for WordPress is vulnerable to SQL Injection in versions up to, an… wordfence
← Prev 447 448 449 450 451 452 453 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top