πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 454 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8a711984-4eb2-4d96-b2b9-0ecd840679b1
< 1.5.4
MEDIUM 6.5 The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_sav… wordfence
89de168e-1bce-4e11-a765-afc1d7dce8fe
< 4.0.3
MEDIUM 6.5 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing… wordfence
89a02485-a2a5-467d-ad19-6b267059389d
< 2.69.0
MEDIUM 6.5 The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMO… wordfence
898ba68f-2b0c-462a-87ee-272ee624396e
< 5.6.2
MEDIUM 6.5 The Jock on air now plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5… wordfence
8972b507-4aae-40cc-a79e-2603dbdc70c0
< 3.6.0.2
MEDIUM 6.5 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_ord… wordfence
88a9abf4-62a9-4695-87e7-18ff0b0075e9
< 10.3.2
MEDIUM 6.5 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to unauthorized acces… wordfence
88241855-075b-4608-aa04-ceb96d062033 MEDIUM 6.5 The RSVP ME plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9.9 due to insuffici… wordfence
8808e4bd-76ea-4e31-8a2c-92c5b7dd3c68
< 2.7.8
MEDIUM 6.5 The Schema Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.7.… wordfence
87adbc9d-cb7b-4e3b-be43-73663d549d20
< 1.5
MEDIUM 6.5 The GymBase Theme Classes plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due … wordfence
8794854d-e931-4a85-b767-2ab81bfcb780 MEDIUM 6.5 The CataBlog plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.0. … wordfence
873e8f12-19a8-43b4-8da0-8b740853b658 MEDIUM 6.5 The Lodgix.com Vacation Rental Website Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, an… wordfence
87099513-d8e2-45e5-b7e6-b46558a10d3b
< 1.0.20
MEDIUM 6.5 The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on… wordfence
86f15e94-6ca7-4eb2-8a38-b4add9251dab
< 2.0.9.3
MEDIUM 6.5 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a… wordfence
86e990ae-6bfe-4f2b-8c37-b0675430a638
< 3.1.26
MEDIUM 6.5 The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.… wordfence
867c9de4-b547-4bf2-8ff1-897c49077f76 MEDIUM 6.5 The Find Me On plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.9.1 due to … wordfence
86632212-37b5-4280-8a2a-163957ad9787
< 3.6.5
MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 's… wordfence
864a3444-0479-4b9f-beca-584a4a9b8682
< 3.2.0
MEDIUM 6.5 The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… wordfence
86346be9-7ca6-49b7-83b2-01a335d48c94
< 3.15.3
MEDIUM 6.5 The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2… wordfence
8584e86d-bafe-4032-9483-c92ecb28ab9c MEDIUM 6.5 The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in… wordfence
85674d8a-96b3-4fae-8bff-900ca78073a4
< 6.4
MEDIUM 6.5 The Page and Post Clone plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' parameter in the content_… wordfence
84c61d00-20c1-4176-a74d-ea6ff6220f26
< 18.3
MEDIUM 6.5 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up t… wordfence
843b569d-d70e-46ae-b8f1-65579f0af333
< 1.2.4
MEDIUM 6.5 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… wordfence
840fefde-8c9d-413f-a6a6-1e796fb9e910 MEDIUM 6.5 The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions … wordfence
840f54c4-898d-40f3-ad0b-fb1a359165e5
< 2.1.7
MEDIUM 6.5 The uListing plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.6 due to insuffic… wordfence
83f8adea-4735-4c72-b274-58e813cab6ab
< 4.6
MEDIUM 6.5 Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre… wordfence
← Prev 451 452 453 454 455 456 457 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top