πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 452 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9309b8bf-f581-4a56-a1ed-3941ebb36127
< 4.16.5
MEDIUM 6.5 The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profi… wordfence
92e444db-72d5-444f-811e-ade0bc097769
< 3.0.7
MEDIUM 6.5 The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing c… wordfence
92c37a5e-7896-44f6-807d-61e06bfbda99 MEDIUM 6.5 The AppExperts plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.5 due to insuff… wordfence
92b8829e-a8eb-4fdb-a772-9efbb5aaeb6c
< 1.6.1
MEDIUM 6.5 The BetterLinks plugin for WordPress is vulnerable to unauthorized access and modification due to insufficient capabilit… wordfence
9283f6ea-8bc4-4fdd-a0b9-05de127f34e4
< 4.0.3
MEDIUM 6.5 The WebPurify Profanity Filter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing … wordfence
927076bc-bafa-43d6-bf3b-5861844c932a
< 3.8.3
MEDIUM 6.5 The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_po… wordfence
926e7bbf-7e19-4bc3-b976-5003399cdcdc
< 1.3
MEDIUM 6.5 The Accordion Slider PRO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due t… wordfence
926b0a28-17b8-4d28-b911-03c75c2e64c9
< 4.5.2
MEDIUM 6.5 The KiviCare plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.5.1 due to insuffic… wordfence
9242cebe-3394-4df9-9c60-8d8d6297d791
< 2.2.4.2
MEDIUM 6.5 The Open Graph and Twitter Card Tags plugin for WordPress is vulnerable to Cross-Site Scripting via the β€˜img’ parame… wordfence
921c2486-42cb-42f2-a326-e951c20bd7ea MEDIUM 6.5 The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it pre… wordfence
91f9235e-f578-475f-92c3-34062d6d1e3d MEDIUM 6.5 The Subscribe To Comments Reloaded plugin for WordPress is vulnerable to unauthorized modification of data due to a leak… wordfence
91ebe8cb-99ec-4380-a77e-17e17144a17e
< 1.6.2
MEDIUM 6.5 The EmailKit plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and inc… wordfence
91ebde99-3383-4179-a72b-2709c1db9e53
< 11.8.2
MEDIUM 6.5 CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin wordfence
91c9fb05-e853-4d59-95ec-a0c2ff06565b MEDIUM 6.5 The Envato Sales By Item plugin for WordPress fails to sanitize user input that is subsequently used in an SQL. It also … wordfence
915cce97-8305-4249-b2d3-c4da2f59a95a MEDIUM 6.5 The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
912523ae-f619-46af-83b9-e9fca81bd5b0
< 1.22.22
MEDIUM 6.5 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to SQL Injection in versions up to, and inc… wordfence
9118acb5-65d7-4058-82f0-0989d33ea44c
< 5.9.4.9
MEDIUM 6.5 The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.4.8 due to in… wordfence
9102fe7e-7baa-4bc0-879f-cc7df1ea13d2
< 2.4.0
MEDIUM 6.5 The MediaCommander – Bring Folders to Media, Posts, and Pages plugin for WordPress is vulnerable to unauthorized data … wordfence
900d09e8-ded5-49b9-81bf-ddfc85d3cf2b MEDIUM 6.5 The WP01 plugin for WordPress is vulnerable to Arbitrary File Download in all versions up to, and including, 2.6.2 due t… wordfence
900cfb6d-61c8-4696-9a5d-1ff03cd76a22
< 1.8.17.0
MEDIUM 6.5 The WP Mailster plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
8ff1ca68-7c71-4442-b27f-12743fc39b37
< 4.0
MEDIUM 6.5 The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other p… wordfence
8fcc8b94-6ed3-4784-93f3-ec1654d197bd MEDIUM 6.5 The Author Discussion plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.2.2 due to… wordfence
8f9863b2-177d-4b72-8337-90fbedfd5b54
< 2.11.2
MEDIUM 6.5 An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that … wordfence
8f7b0a1c-16d7-45db-b419-569ed5c4a5e4
< 1.5.3
MEDIUM 6.5 The Make plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce verifica… wordfence
8f411d17-5b0d-4a4a-afa8-7efebf6965f2
< 1.4.8
MEDIUM 6.5 The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to … wordfence
← Prev 449 450 451 452 453 454 455 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top