🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 461 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
66b669ce-142a-48b8-9adf-620657c2db74
< 5.16.7.2
MEDIUM 6.5 The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode… wordfence
668a77e4-9d0a-4835-be5c-4c1acfe7ba43
< 3.43
MEDIUM 6.5 The WP Tools plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wptools… wordfence
667547a9-0dc5-4810-aba9-025f0c222d24 MEDIUM 6.5 The Account Manager for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capabili… wordfence
65b54e53-ec14-4dae-bcc1-1ca9b4128324
< 4.0.2
MEDIUM 6.5 The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to SQL Injectio… wordfence
65b48fc0-27fd-4a37-afb8-2213ca0d4746
< 8.4.5
MEDIUM 6.5 The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the ‘prgSo… wordfence
65a9e877-e870-4e36-985d-c0629abe3f78
< 9.660
MEDIUM 6.5 The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the… wordfence
658ff7da-6496-4cca-8b1c-76b794c20aad
< 1.2.0
MEDIUM 6.5 The Quantity Plus Minus Button for WooCommerce by CodeAstrology plugin for WordPress is vulnerable to Cross-Site Request… wordfence
657e2a4d-7e10-495d-8352-1adc0cb89e83
< 1.0.32
MEDIUM 6.5 The Simple Page Access Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t… wordfence
655e3795-44c8-498c-a8cd-9985abc9664c
< 5.9.5.1
MEDIUM 6.5 The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.0 due to in… wordfence
65585b03-5a53-454a-b6f9-1d124a622f5e MEDIUM 6.5 The Docxpresso plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6. This… wordfence
6535f932-3aa4-4686-adf6-4e7a1f494e02
< 2.5.0
MEDIUM 6.5 The REST API endpoint get_users in the User Profile Picture WordPress plugin before 2.5.0 returned more information than… wordfence
64f43aee-01ee-4fbb-a174-966ed3c06b21
< 1.1.25
MEDIUM 6.5 The RSFirewall! plugin for WordPress is vulnerable to IP Address Spoofing in versions less than and equal to 1.1.24 due … wordfence
64e4d51a-7b65-4fba-9742-bc7d23f46f8d
< 2.4.6
MEDIUM 6.5 The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in a… wordfence
64ce00e9-1ef6-4155-9d0d-69a130bddba6
< 1.8.0
MEDIUM 6.5 The Behance Portfolio Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.… wordfence
647b0d58-1397-47ad-b001-6d5085fb4c4f
< 7.4.1
MEDIUM 6.5 The Events Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4.0 due to in… wordfence
64599caf-d79f-425a-b0b0-b97665130144
< 3.11.2.2
MEDIUM 6.5 The The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to arbitrary shortcode exe… wordfence
641e52d1-d046-4c15-9624-3b1919cd674f
< 1.3.4
MEDIUM 6.5 The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure tha… wordfence
63fec549-09e0-4d4e-ae41-128ce0669501
< 11.2.1
MEDIUM 6.5 The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, an… wordfence
63dc0acf-cec6-402b-aad3-21135354e488 MEDIUM 6.5 The Attention Bar plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and … wordfence
63567094-9fb1-44b2-a3e6-99194389c4b6
< 1.80
MEDIUM 6.5 The 1003 Mortgage Application plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.75… wordfence
634bec5f-e511-4047-9a46-09147ccc3a25
< 2.0.0
MEDIUM 6.5 The Download Plugin plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 1.6.2 … wordfence
6335cc7b-7282-4f54-9d8e-09a98ac3c3e5 MEDIUM 6.5 The iFrame Images Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0 due … wordfence
630cc68e-102e-4e05-98ff-94de434a10ae
< 3.2.1
MEDIUM 6.5 The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'stan… wordfence
6300c8c2-f539-46b2-9ee0-80bebbe4cad3
< 5.9.6
MEDIUM 6.5 WordPress Core processes shortcodes in user-generated content on block themes in versions up to, and including, 6.2. Thi… wordfence
62e75bb6-83d9-43db-8c89-0995698ca0ca
< 27.1.2
MEDIUM 6.5 The Betheme theme for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the '_to… wordfence
← Prev 458 459 460 461 462 463 464 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top