πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 455 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
83ec5fa5-2fd9-4c7d-a2f1-de885746d2d3
< 2.0.5
MEDIUM 6.5 Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenti… wordfence
836af607-a9cb-4ea2-b3e8-0cd42a04254b MEDIUM 6.5 The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection… wordfence
830f53a4-da3b-4a95-99f1-c4a4c8e6944c
< 6.20.02
MEDIUM 6.5 The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data… wordfence
830a5784-5ebb-4a32-b214-a601bb41062c MEDIUM 6.5 The All In Menu plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.5 due to insuf… wordfence
8298f1fb-3165-40e3-9192-805a07c14cae
< 2.0.7
MEDIUM 6.5 The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch… wordfence
826a3fa2-ee41-4960-becb-0df8813a964a
< 1.2.6
MEDIUM 6.5 Multiple Plugins By ThemeHunk are vulnerable to unauthorized plugin setting modification due to a missing capability che… wordfence
82299c65-2d27-472f-85c8-9e8b3d8ff02b
< 8.14.1
MEDIUM 6.5 The MapSVG plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.14.0 due to insuffici… wordfence
81fc41a4-9206-404c-bd5b-821c77ff3593
< 3.3.2
MEDIUM 6.5 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_thankyou' s… wordfence
81bf9a8d-fc70-45d9-a352-4a5bfb2c43f4
< 2.8.5
MEDIUM 6.5 Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a de… wordfence
81b49050-84e4-4fb4-b8ed-baf21c8bb5a3
< 1.7.2
MEDIUM 6.5 The Logo Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜wp-admin/edit.php?post_ty… wordfence
815ce00b-3753-4c38-8a30-5242a5841734
< 1.23
MEDIUM 6.5 The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val… wordfence
8156d204-f48a-43aa-af2f-86d4aaf4f50e
< 3.28.8
MEDIUM 6.5 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file … wordfence
814fd060-8781-46ad-86e6-e2b75a7fffc0
< 2.29.2
MEDIUM 6.5 The Download IP2Location Country Blocker plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, an… wordfence
814b1d7c-0601-4afb-b84c-7aa8ffadd57c
< 6.1.16
MEDIUM 6.5 The Simple File List plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.15. … wordfence
8118e676-6506-42ae-9f30-536cc1243dbf
< 4.7.2
MEDIUM 6.5 The APIExperts Square for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
8113fd51-9e2b-45c4-a17b-b38072da0de9
< 3.6.0.1
MEDIUM 6.5 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' par… wordfence
80de464f-a4b0-4aaf-8869-f8d29a422bdb
< 1.0.2
MEDIUM 6.5 The Gutenberg Thim Blocks – Page Builder, Gutenberg Blocks for the Block Editor plugin for WordPress is vulnerable to … wordfence
8019da67-fd2c-48f8-8983-6fb8fb30510b
< 1.0.31
MEDIUM 6.5 The BookingPress plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including… wordfence
80128b8c-a2ae-410f-ad82-64e204f62585
< 1.3.5
MEDIUM 6.5 The xPromoter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4 due to insuffi… wordfence
7fe3d251-4edf-4d94-a946-0aa918135784
< 4.5.3
MEDIUM 6.5 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Obje… wordfence
7fdf428d-b57a-4f2d-acfd-24a3a059e5c1
< 5.3.2
MEDIUM 6.5 The SlimStat Analytics plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜args’ parameter in al… wordfence
7fd7a515-6389-4152-8dac-d5497dd94f6d
< 10.4.3
MEDIUM 6.5 The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerabl… wordfence
7fa986aa-e899-42e1-9b86-8b205e247cbf MEDIUM 6.5 The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted reque… wordfence
7f800bc0-5b1b-43fa-a267-d8db444d0c2c
< 1.7.2
MEDIUM 6.5 The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to HTML Injection in … wordfence
7f7dca64-4965-4b19-96a1-8c24c49468fb
< 13.8
MEDIUM 6.5 The The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to arbitrary shortcode execu… wordfence
← Prev 452 453 454 455 456 457 458 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top