ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 457 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7aab1307-7fb5-46fb-ae12-087dce3086fc
< 1.5.1
MEDIUM 6.5 The ilGhera Carta Docente for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an… wordfence
7aa6da4d-7221-4878-8532-5372227f906a
< 4.1.0
MEDIUM 6.5 The Simple Membership WordPress plugin before 4.1.0 does not have Cross-Site Request Forgery (CSRF) protections in place… wordfence
7a747542-0601-4fa5-a97c-c72d1347013b
< 3.9.7
MEDIUM 6.5 The MStore API plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks … wordfence
7a7157c0-8378-4aa0-bc47-635be4ba2f8f
< 3.2.68
MEDIUM 6.5 The Cost Calculator Builder plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_ids’ param… wordfence
7a51fe96-f3d3-46fe-9e3a-fb7c1bd17b05
< 3.7.26
MEDIUM 6.5 The MasterStudy LMS WordPress Plugin for Online Courses and Education plugin for WordPress is vulnerable to Time-based B… wordfence
7a275fd7-e1c9-462a-8fe5-2c05e171f235
< 1.6.002
MEDIUM 6.5 The Premium SEO Pack plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.001 due t… wordfence
7a2420ca-e079-429b-b1f1-47bf1d0a9f71
< 4.6.19
MEDIUM 6.5 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based SQL Injection via the… wordfence
79f9632e-cfaf-48bd-aeed-919fc729f2b4
< 1.8.3
MEDIUM 6.5 The tutor_quiz_builder_get_question_form AJAX action from the Tutor LMS – eLearning and online course solution WordPre… wordfence
79e786ce-a3eb-40df-8dad-4c9c75243bec
< 1.8
MEDIUM 6.5 The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capabi… wordfence
79da7239-0343-465e-8dda-44ff440939c4
< 1.13.2
MEDIUM 6.5 The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is… wordfence
798d120a-edec-4af9-b574-46f9beabc491
< 2.6.17
MEDIUM 6.5 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for … wordfence
796c0ded-3a23-4dd6-968a-a8e60bd8ea0e
< 8.5.3
MEDIUM 6.5 The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to… wordfence
79545b24-b325-486b-b34f-87bba14b8cd4
< 3.9.5
MEDIUM 6.5 The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any… wordfence
7951c8e4-b610-4cc4-ab27-4cfa78d72302
< 5.0
MEDIUM 6.5 The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and includ… wordfence
79125ac2-f3ed-40c9-a81b-340195fc8da5
< 2.6
MEDIUM 6.5 The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin … wordfence
790514c4-47f2-4c8f-a0c0-cd0b761dd5fc
< 1.1.11
MEDIUM 6.5 The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.10 due to in… wordfence
78ac100e-ba2f-4ba6-9125-9cc2d531cc0e
< 2.1.2
MEDIUM 6.5 The Miraculous Core plugin for WordPress is vulnerable to SQL Injection in versions up to 2.1.2 due to insufficient esca… wordfence
78ab6263-7762-4fd2-af42-2224efa9509e
< 5.0.9
MEDIUM 6.5 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to ge… wordfence
78823184-e90a-4f5c-9f08-5ffc22787f16 MEDIUM 6.5 The avenirsoft-directdownload plugin 1.0 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=avenir_pl… wordfence
786ef53a-0fcd-4226-b469-52b72cd6890c
< 3.6.0.2
MEDIUM 6.5 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_eve… wordfence
7863c5fb-1eda-41a3-b8ec-054784ab2438
< 1.3.2
MEDIUM 6.5 The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers… wordfence
781b00cd-3af9-432a-876b-bff482106ab0
< 4.9.6
MEDIUM 6.5 The WPML Multilingual CMS plugin for WordPress is vulnerable to SQL Injection via the 'sorting' parameter in all version… wordfence
7801d3e1-90aa-434d-ae3d-9f19670280c0
< 5.2.0
MEDIUM 6.5 The LayerSlider plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 4.6.1 via the Lay… wordfence
77ebd648-3851-47ea-a5eb-86af4899727c
< 3.3.13
MEDIUM 6.5 The Tatsu WordPress plugin before 3.3.13 add_custom_font action can be used without prior authentication to upload a rog… wordfence
77e5155d-5279-4609-93de-18fa54702c3e MEDIUM 6.5 The Duplicate Page and Post plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.5 … wordfence
← Prev 454 455 456 457 458 459 460 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top