πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 451 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
991ab188-869c-4875-80f3-940000a1717b
< 1.2.11
MEDIUM 6.5 The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode executio… wordfence
98ab4a17-c350-49a9-921d-7ef04e923110 MEDIUM 6.5 The Pixelating image slideshow gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
984ca0d3-26c3-40cf-8e77-2ec1e3b89ce2
< 2.8.7
MEDIUM 6.5 The Cost of Goods for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
97fbbf5b-d3c7-47ce-b251-ce1fe38af152
< 2.6.3
MEDIUM 6.5 The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and inclu… wordfence
97c07a3e-4538-4e0f-a597-6b843ff7feb5
< 1.2.5
MEDIUM 6.5 Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allo… wordfence
97a6da6b-ed85-4bf4-8ae7-5cd831d022a7
< 1.2.42
MEDIUM 6.5 The Form Builder CP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.41 due to … wordfence
97845a09-d7ae-42bc-b59b-e93f76289b09 MEDIUM 6.5 The CWS SVGicons plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.5 due to insu… wordfence
97827e26-d418-4c96-b0d0-10b92a4513bd
< 1.0.9
MEDIUM 6.5 The Responsive Filterable Portfolio plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all ve… wordfence
96a80b89-94e0-4bbd-88cf-5eb5349c320b
< 1.13.20
MEDIUM 6.5 The Geo Mashup plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geo_mashup_null_fields' par… wordfence
9638fb98-045b-44ec-8b53-15cfa3693ee7
< 0.21.13
MEDIUM 6.5 The Tainacan plugin for WordPress is vulnerable to SQL Injection via the 'collection_id' parameter in all versions up to… wordfence
962f31e6-7863-45e1-835e-c679046deeea MEDIUM 6.5 The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check authorization or that the option me… wordfence
96112707-04ca-4647-9008-31954764486f
< 1.4.7
MEDIUM 6.5 The Gallery Portfolio plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to mi… wordfence
95dc0d79-b65a-4bfb-89c0-569bf26232df
< 6.8.2
MEDIUM 6.5 A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress a… wordfence
95ce3773-a676-4aa6-9314-6adccf44d070
< 11.5.0
MEDIUM 6.5 The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injec… wordfence
951b8cbd-0509-4548-ae69-6cfd67e83b1a
< 1.43
MEDIUM 6.5 The External Links in New Window / New Tab WordPress plugin before 1.43 does not ensure window.opener is set to "null" w… wordfence
950bed9d-8698-4aa0-86a4-fac9e07bb42b
< 1.8.10.5
MEDIUM 6.5 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is… wordfence
94f7f2d2-e90b-4978-bab8-eee160949567
< 4.0.7
MEDIUM 6.5 The MainWP UpdraftPlus Extension for WordPress is vulnerable to authorization bypass due to a missing capability check w… wordfence
94c98edf-6f4a-4c23-afa7-d5caaa22397f
< 1.2.3
MEDIUM 6.5 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… wordfence
9479c9ff-6da3-4391-802d-9e3eb14eff77
< 4.20
MEDIUM 6.5 The Anti Hacker plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the anti… wordfence
94392c66-6e50-48bb-93cb-9aa9d0229761
< 3.11.13
MEDIUM 6.5 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'que… wordfence
940aabdc-e98e-45be-87dd-cafae45f2474
< 2.3.3
MEDIUM 6.5 The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers… wordfence
93f9862f-745f-44d5-ac49-f8d2d19b35ed
< 3.3.7
MEDIUM 6.5 WordPress plugin Wordfence versions 3.3.6 and older were vulnerable to Cross-Site Scripting via the unlockEmail function… wordfence
93d8ed64-0b3e-4410-9166-6e7861d885ca
< 3.7.26
MEDIUM 6.5 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to SQL Inje… wordfence
938e5d6b-1ad6-4021-a148-1d1c9e8a0a83
< 6.1.2
MEDIUM 6.5 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vul… wordfence
930e7fd6-ae0b-465a-aa93-04ef80011d32
< 8.7.5
MEDIUM 6.5 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d… wordfence
← Prev 448 449 450 451 452 453 454 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top