🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 462 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
621e3b3f-9647-41ec-aa06-e961e3525fea
< 3.05
MEDIUM 6.5 The Car Dealer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the carde… wordfence
61fdc6e9-75ea-4226-9527-a5fd02efde70
< 1.8.2
MEDIUM 6.5 The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthenticated settings reset in versions… wordfence
61e107e8-405a-4f14-b0ff-b9a66b7ccf8b MEDIUM 6.5 The Team Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
61b07604-b206-4f13-b25f-7a6d54236eb1
< 1.7.7
MEDIUM 6.5 The Slideshow Gallery LITE plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in versions up … wordfence
615f9068-2a42-40c2-aff9-4807b2bd7550
< 7.0.2
MEDIUM 6.5 The WPJAM Basic plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.0.1 due to insuf… wordfence
6101c3a2-4284-4b14-995d-06855a8e551d MEDIUM 6.5 The JSP Store Locator plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.0 due … wordfence
60ee9cfc-016d-45ee-b3f4-da999d093776 MEDIUM 6.5 The Booster Elementor Addons plugin for WordPress is vulnerable to unauthorized access and modification of data due to m… wordfence
60e642f9-74ff-47f1-a49d-99c8fdb26f4a MEDIUM 6.5 The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data d… wordfence
60496696-7cb9-44b1-a622-7ee427530c9d
< 5.1.9
MEDIUM 6.5 The Download Monitor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.1.8 due to … wordfence
603734a3-f471-4a40-9253-92e0d1ef5ac2 MEDIUM 6.5 The Infility Global plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.14.7. T… wordfence
601ad4f3-2160-4af6-b3d5-c2af52746aab
< 2.2
MEDIUM 6.5 An issue was discovered in the MULTIDOTS WooCommerce Checkout for Digital Goods plugin 2.1 for WordPress. If an admin us… wordfence
6015e204-1e07-4c75-ad22-969045934468
< 1.8.5
MEDIUM 6.5 The Coupon Referral Program plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … wordfence
5fe7668b-9d70-44b7-a347-3922c0b8684c
< 2.1.10
MEDIUM 6.5 The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized a… wordfence
5f1ba1c7-de88-4070-a4ec-fbe4a0c30920
< 2.1.2
MEDIUM 6.5 The GenerateBlocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check o… wordfence
5ee7f904-d150-4da1-a79c-502fe2ca3b37
< 1.1.5
MEDIUM 6.5 Server-side request forgery (SSRF) in the Podcast Importer SecondLine (podcast-importer-secondline) plugin 1.1.4 and bel… wordfence
5ee333a6-6b4b-4abb-9fc9-1afd9598b321
< 2.0.7
MEDIUM 6.5 A CSRF vulnerability in Settings form in the Custom Simple Rss plugin 2.0.6 for WordPress allows attackers to change the… wordfence
5ec1fd03-f865-4f58-b63b-e70c0c7e701d
< 4.7.15
MEDIUM 6.5 The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to … wordfence
5e91f4af-7ac6-4c85-bbf4-ac06d516a570
< 1.9.27
MEDIUM 6.5 The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthent… wordfence
5e8933b8-1e09-4cd7-8206-711cc0716dba
< 1.6.8
MEDIUM 6.5 The Masteriyo - LMS for WordPress plugin is vulnerable to Sensitive Information Exposure in versions up to, and includin… wordfence
5e640767-7998-4404-a894-0b1794464c66 MEDIUM 6.5 The Legoeso PDF Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘checkedVals’ paramet… wordfence
5e408c1b-6789-4e9c-95c2-89e0a033e6b8
< 1.4.1
MEDIUM 6.5 The DynamicTags plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.0 due to insuf… wordfence
5dbe5094-d255-46b1-9e8e-9c48cd74e8a2
< 1.6.12.11
MEDIUM 6.5 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to I… wordfence
5db00eb6-3e05-42fa-bb84-2df4bcae3955
< 3.3.2
MEDIUM 6.5 The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to unauthorized permalink structure update… wordfence
5dad7348-39ba-4163-a5eb-939601645edb
< 5.12.7
MEDIUM 6.5 The Shortcodes Ultimate plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 5.12… wordfence
5d9736e0-1a10-4ea0-a514-62ff49e36c43
< 1.5.4
MEDIUM 6.5 Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remot… wordfence
← Prev 459 460 461 462 463 464 465 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top