πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 460 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
6e834db1-0859-4e58-a11c-96e8f201b097
< 2.4.1
MEDIUM 6.5 Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b… wordfence
6dfcd264-39e3-44af-8e0e-5c35734524d0
< 2.4.1
MEDIUM 6.5 The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 … wordfence
6dd041ff-a0a3-4d1f-83e0-6ec2a978e9cf
< 3.9.9
MEDIUM 6.5 The Tutor LMS plugin for WordPress is vulnerable to SQL Injection in versions up to and including 3.9.8. This is due to … wordfence
6d8f7252-5e91-4e42-a6a5-056da491b4f1
< 5.6.5
MEDIUM 6.5 The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file downloads due to missing sanitization a… wordfence
6d7c8f79-4dfd-4d6f-b533-dc7a5998dfc1
< 1.1.4
MEDIUM 6.5 The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up t… wordfence
6d1ad409-d5d3-4231-9a7c-de881c7b9de2
< 0.8.9.1
MEDIUM 6.5 The WP Fastest Cache plugin through 0.8.9.0 for WordPress allows remote attackers to delete arbitrary files because wp_p… wordfence
6d081b89-1b98-4f4f-8728-d1ea676d7afd
< 1.1.22
MEDIUM 6.5 The Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to SQL… wordfence
6ca16602-52e6-4d14-99a5-ca4e26b9f377
< 2.5.7
MEDIUM 6.5 The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
6c563616-e405-4b3e-a70a-543f42118a97
< 4.0.11
MEDIUM 6.5 Several MainWP extensions for WordPress are vulnerable to authorization bypass due to a missing capability check on an u… wordfence
6b749ed7-ca41-4b3d-a30e-e9abdbc98fab
< 4.7.11
MEDIUM 6.5 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to SQL Injection in versions up to,… wordfence
6b5e8cfd-989e-4a64-abb0-9daa22df46a4
< 4.4.0
MEDIUM 6.5 The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Insecur… wordfence
6b50656b-6cb4-4920-aa36-2634d4d41f5c
< 3.7.9
MEDIUM 6.5 WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to by… wordfence
6b04a5e4-f4df-4ac4-a1a0-3e1d18bb9d02 MEDIUM 6.5 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection in versions up… wordfence
6a9397ed-eddf-466b-b810-1e2f45afd291
< 3.1.78
MEDIUM 6.5 The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
6a19972e-6ff9-4d18-a327-5cafef96a637
< 2.6.38
MEDIUM 6.5 The Like Button Rating β™₯ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the… wordfence
69d3d66c-5557-4fb4-8bd7-05d76d6b86ab MEDIUM 6.5 The Page Builder Sandwich – Front End WordPress Page Builder Plugin plugin for WordPress is vulnerable to unauthorized… wordfence
69ab18a4-e3f2-42d4-bb3d-efb792a77c31 MEDIUM 6.5 The Chameleon HTML5 Audio Player With/Without Playlist plugin for WordPress is vulnerable to SQL Injection in versions u… wordfence
6990abdc-232f-4c25-8cba-c2639f315434
< 1.0.4
MEDIUM 6.5 The Cab fare calculator WordPress plugin through 1.0.3 does not validate the controller parameter before using it in req… wordfence
69622613-e636-4c27-8d05-139149889fcb MEDIUM 6.5 The Exertio Framework plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.3 due to… wordfence
67eb77e9-7e0b-4134-9cb6-30ba78f6a686
< 5.10.3
MEDIUM 6.5 The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W… wordfence
67c15451-672d-4297-9d19-090a4458605f
< 3.4.13
MEDIUM 6.5 The Recipe Card Blocks for Gutenberg & Elementor plugin for WordPress is vulnerable to SQL Injection in versions up to 3… wordfence
67abab41-7671-409d-bebc-353456bf65ab
< 5.5.1
MEDIUM 6.5 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to unauthorized access … wordfence
67685b75-1dce-411d-8e18-55b4f4216099
< 11.5.7
MEDIUM 6.5 The RSVPMarker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 11.5.6 due to insu… wordfence
670953e2-46d3-46f9-9922-0a3c9c277968
< 1.117.6
MEDIUM 6.5 The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v… wordfence
67013cc9-c20f-4137-9a4d-e7d700899131
< 7.20.01
MEDIUM 6.5 The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Fo… wordfence
← Prev 457 458 459 460 461 462 463 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top