πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 459 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
73323c62-c23f-4bf2-b266-df63db63d4d3
< 2.3.2
MEDIUM 6.5 The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to HTML injection via Email in versions up… wordfence
73017e92-d95e-4b9c-a44a-779b498f58b7
< 7.1.2
MEDIUM 6.5 The WoodMart theme for WordPress is vulnerable to unauthorized shortcode injection in versions up to, and including, 7.1… wordfence
72f3541e-e589-4f21-ab51-89dba704b271
< 1.2.4
MEDIUM 6.5 The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be de… wordfence
72e4428b-d2cd-471f-9821-947f4601fd64
< 3.4.2
MEDIUM 6.5 The Funnelforms Free plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
724a1790-811a-4ec5-a664-a22e6b72fba1
< 2.0.6
MEDIUM 6.5 The WP-FormAssembly plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.0.5. T… wordfence
721f8943-5d59-41ee-935e-999dff2e590d
< 2.46.1
MEDIUM 6.5 The Simple Giveaways plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on sev… wordfence
71fb90b6-a484-4a70-a9dc-795cbf2e275e MEDIUM 6.5 The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ava… wordfence
71e587ec-ceb6-48ca-9a1a-599d9d988b4d
< 2.13.4
MEDIUM 6.5 The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up… wordfence
71b05a05-9fbb-4444-a731-6d070cd56cbd MEDIUM 6.5 The WPAMS plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 44.0 (17-08-2023) due to… wordfence
70f464ca-ff6c-4c2e-8b56-bf5e4bc6bd1f MEDIUM 6.5 The WP Online Contract plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on th… wordfence
70effa22-fbf6-44cb-9d1b-8625969c10ac
< 1.2.4
MEDIUM 6.5 The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all ver… wordfence
70ce4450-e38b-422e-a171-09f428dfe0d8
< 1.2.8
MEDIUM 6.5 The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification vi… wordfence
70bac5e0-8182-426c-94da-e6832af8c487 MEDIUM 6.5 The MkRapel Regiones y Ciudades de Chile para WC plugin for WordPress is vulnerable to Cross-Site Request Forgery in ver… wordfence
708e3851-a4fe-41bd-8a6c-9e1674f3b62d
< 5.0.8
MEDIUM 6.5 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to SQ… wordfence
70083f93-f110-4029-a3d3-ce8a77799a31
< 2.6.18
MEDIUM 6.5 The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for … wordfence
6ffb078c-2a92-4682-aaa9-c519e28e7e18
< 1.6.3
MEDIUM 6.5 The Zippy plugin for WordPress is vulnerable to unauthorized archiving and unarchiving of pages due to a missing capabil… wordfence
6ff5cda2-edcd-4fa5-9c8e-427a43802ed1
< 1.6.3
MEDIUM 6.5 The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to SQL Injection via the 'id' pa… wordfence
6fcc3a82-f116-446e-9e5f-4f074e20403b
< 2.2.9
MEDIUM 6.5 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery i… wordfence
6f998b76-9fa8-47c4-a95b-bdb5db5893e4
< 2.0.4
MEDIUM 6.5 Directory traversal vulnerability in wp-db-backup.php in WordPress 2.0.3 and earlier allows remote attackers to read arb… wordfence
6f917973-e207-4ba3-b61b-e562e884fe0f
< 2.4.4
MEDIUM 6.5 The Booked plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and excluding, 2.4.4… wordfence
6f6ea94a-c8c7-4ff9-9fdd-a40acd6ec4f9
< 6.7.2
MEDIUM 6.5 The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. wordfence
6f5f6931-aeda-4499-a1a4-9e80f730dad4
< 1.1.35.2
MEDIUM 6.5 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… wordfence
6ee04e4d-4385-4854-9bfe-1b957ca13963
< 7.6.2
MEDIUM 6.5 The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ver… wordfence
6ed99dfd-6ca6-41e7-a844-d53eec7068c1
< 0.5.6
MEDIUM 6.5 The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable… wordfence
6e9eec61-bf51-4cf7-b567-58ee2ccd91c5 MEDIUM 6.5 The Restrict File Access plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,… wordfence
← Prev 456 457 458 459 460 461 462 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top