πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 458 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
7783f6fd-02c9-4ff0-ba36-77a0ad5a4bb6
< 0.21.9
MEDIUM 6.5 The Tainacan plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.21.8 due to insuffi… wordfence
776fc47e-a86c-43dc-8d5e-50273c4411b2
< 3.1.25
MEDIUM 6.5 Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to o… wordfence
7740fdfb-65b2-4d27-935f-b0e73487f0c4
< 3.9.0
MEDIUM 6.5 The ElementsKit Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
76cd5762-1ad4-4b76-8161-5a4ce4fc8118
< 5.12.1
MEDIUM 6.5 The Advanced Custom Fields plugin for WordPress is vulnerable to authorization bypass due to a missing capability check … wordfence
769c8483-2975-44d3-9a2b-e015a5d00708
< 1.9.2
MEDIUM 6.5 The TextMe SMS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tetxme… wordfence
767b1234-5b4a-4baa-9048-7b2e413cdba5
< 1.6.7
MEDIUM 6.5 The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and … wordfence
76664f7a-b27d-4f2c-9314-92f4515c359f
< 7.3.2
MEDIUM 6.5 The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_priv… wordfence
76421c8e-de5f-4469-9a32-09976de873b4
< 1.2.10
MEDIUM 6.5 The Spam Protect for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fi… wordfence
7638c454-2941-4a86-bb49-c3647b131fac MEDIUM 6.5 The WP Contest plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.0 due to insuff… wordfence
760cea25-0d1f-4dd7-a85a-6f41173e8c15
< 3.4.0
MEDIUM 6.5 The WordPress CRM Plugin – WP-CRM System plugin for WordPress is vulnerable to unauthorized access due to a missing ca… wordfence
760012c0-d871-41fa-a026-d831d5148744
< 12.40
MEDIUM 6.5 The DZS Video Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 12.39 due to… wordfence
75bc2295-bf9a-430f-92b7-d380eed6df11
< 1.1.3
MEDIUM 6.5 The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to unauthorized modification of dat… wordfence
759f5687-4ff1-4b8d-a5e7-3fb409fc2ba0
< 7.24
MEDIUM 6.5 The StopBadBots plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the stop… wordfence
756b5e3e-46fa-483e-945a-86166e79d989
< 2.9.32
MEDIUM 6.5 The Affiliates Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
75685f2f-b1d0-4f38-a2b4-1cc0259aedc7
< 1.9.1
MEDIUM 6.5 The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to authorization bypass due to a m… wordfence
7520010f-c402-4fe9-82dc-a973ce446765 MEDIUM 6.5 The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which… wordfence
750d0925-aecb-4360-869d-765d7e46541a
< 2.5.3
MEDIUM 6.5 The WP Job Portal – AI-Powered Recruitment System for Company or Job Board website plugin for WordPress is vulnerable … wordfence
74bbd842-833b-4c3d-9829-72469591bcaa
< 1.2.5
MEDIUM 6.5 The Easy Quotes plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
74984cc6-06b1-4c3a-a3e6-9e104c71e9c5
< 2.6.27
MEDIUM 6.5 The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plu… wordfence
748220a6-9882-458c-8f80-a928f449c400
< 1.5.2
MEDIUM 6.5 The Easy WP SMTP plugin for WordPress is vulnerable to Arbitrary File Deletion versions up to, and including, 1.5.1. Thi… wordfence
746eec41-e8d2-4c51-b63e-726eeadbb2ab
< 6.0.0
MEDIUM 6.5 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQ… wordfence
745c1501-a148-47ff-adb3-a6af06357bf4 MEDIUM 6.5 The Easy Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4 due to insuff… wordfence
74428e76-1946-408f-8adc-24ab4b7e46c5
< 2.4.7
MEDIUM 6.5 The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… wordfence
73e51f52-70e9-4620-8c87-2a3982b98681
< 3.1
MEDIUM 6.5 The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to SQL Injection in versions up to, and includin… wordfence
73897594-d25c-410e-81b1-70b6a8136aee
< 9.6
MEDIUM 6.5 The The XStore theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and excluding, … wordfence
← Prev 455 456 457 458 459 460 461 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top