πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 456 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7f562b4c-8934-45fd-b9a4-eeb3a6bcf609 MEDIUM 6.5 The Delete All Comments Easily WordPress plugin through 1.3 is lacking Cross-Site Request Forgery (CSRF) checks, which c… wordfence
7f42730f-f701-4f35-a240-5fa4229dff8b MEDIUM 6.5 The Google Maps Travel Route plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.1… wordfence
7f3b7b5e-486b-447a-af65-b58d680b9870
< 3.10.0
MEDIUM 6.5 The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable t… wordfence
7ecbf3cb-6b4b-4e49-b301-53eb3965aec3
< 4.19.0
MEDIUM 6.5 The Pinterest Automatic Pin plugin for WordPress is vulnerable to SQL Injection in versions up to 4.19.0 due to insuffic… wordfence
7ea10a95-c24b-49ae-8a70-317fe04590bf MEDIUM 6.5 The Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to S… wordfence
7e82e1c5-0ed4-4dee-9990-976591693eb5
< 3.4.4
MEDIUM 6.5 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripti… wordfence
7e15f804-f5a9-4e29-8aeb-4ba2b116dc46
< 1.1.6
MEDIUM 6.5 The Product Size Chart For WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
7df39a64-76c5-4ebe-a271-44bd147a3a86
< 1.0.229
MEDIUM 6.5 The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modificat… wordfence
7da1d7cf-e8b5-4b7c-bdc1-13ef8c11b663 MEDIUM 6.5 The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.4.2 via th… wordfence
7d7f2cb6-5c19-4126-9f39-439cf6057c5b
< 5.3.8
MEDIUM 6.5 The Tour Master - Tour Booking, Travel, Hotel plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜… wordfence
7d33594b-e7b7-4685-97c1-37a2fecc1b8a
< 1.4.7
MEDIUM 6.5 The Yoast SEO plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the reset … wordfence
7d02bed5-c45b-46db-a2c2-9c741f8b1dc5
< 1.1.1
MEDIUM 6.5 class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has a… wordfence
7cbe9175-4a6f-4eb6-8d31-9a9fda9b4f40
< 5.1.5
MEDIUM 6.5 The UserPro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '… wordfence
7c6be7f2-5526-4fba-9fe0-003b8460c926 MEDIUM 6.5 The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check … wordfence
7c6aef41-e4f9-4494-a5fd-47f55973d1d9
< 2.11.0
MEDIUM 6.5 The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing a… wordfence
7c5d7818-e548-4d8f-b847-396d528b58cd
< 1.3
MEDIUM 6.5 The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th… wordfence
7c32d967-85b9-4c93-a948-0126efb78f39
< 4.0.3
MEDIUM 6.5 The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to … wordfence
7c312478-0d6e-400b-81c2-172c2c5798ff MEDIUM 6.5 The jQuery HTML5 File Upload plugin for WordPress is vulnerable to unauthenticated settings update in versions up to, an… wordfence
7bd3c653-249c-42b1-8af7-beac4ac3dd30
< 3.7.30
MEDIUM 6.5 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to SQL Inje… wordfence
7bc875b3-8250-4447-b921-243926849fa2 MEDIUM 6.5 The Attorney theme for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the hd_… wordfence
7bb6caf6-5676-49cd-8577-5a41b44b00c0
< 5.12.7
MEDIUM 6.5 The Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and includi… wordfence
7b498c5a-9fd1-43b8-b456-f6cec65d5077
< 4.1.1
MEDIUM 6.5 The WP Shamsi plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the deacti… wordfence
7af56157-7b69-4bbd-8f22-4963d0cdf9eb MEDIUM 6.5 The Userpro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.9 due to insuffici… wordfence
7af13d87-c36b-4a75-8364-f151571f52b2 MEDIUM 6.5 The WP EIS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.3 due to insufficie… wordfence
7ad9e7e0-f673-455b-8e99-a12cf3bf161d MEDIUM 6.5 The CoSchool LMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.3 due to insu… wordfence
← Prev 453 454 455 456 457 458 459 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top