πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 463 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
5d78ea71-5886-488e-a660-0dc25129a8b6 MEDIUM 6.5 The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitr… wordfence
5d27cead-d234-4bea-ad2b-a748840aa31d
< 1.1.4
MEDIUM 6.5 The WPGuppy plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.3 due to insuffici… wordfence
5d0b26b6-61e3-4fa2-9cde-6e49bb7e1d7f
< 8.14.1
MEDIUM 6.5 The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to SQL Injection in versions up t… wordfence
5cec4c17-24c1-4ed3-a3d3-9404ad7af420
< 1.2.9
MEDIUM 6.5 The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi… wordfence
5ccfafaf-902f-4142-90b3-9f70800eb377
< 3.2.25
MEDIUM 6.5 The Front End Users plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing ca… wordfence
5cbbfe66-09fe-48c9-9af1-0b7b90ac222a
< 2.2.1
MEDIUM 6.5 The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up… wordfence
5c28577f-d405-4120-808e-62d0bd9398ac
< 5.9.9.8
MEDIUM 6.5 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Registration Bypass in a… wordfence
5bf95020-ac4f-4fb2-8fb4-a9998005991c
< 5.0.5
MEDIUM 6.5 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all vers… wordfence
5bdf04e6-6d9d-41a3-ac54-1a95f4617ea4 MEDIUM 6.5 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection via several fu… wordfence
5bcdeeff-19cb-403a-8b69-420198a44f25
< 1.3.5
MEDIUM 6.5 The Ultimate WP Mail plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4 due to … wordfence
5b4f563c-a17b-4d69-9e94-7287da976e85
< 1.0.2
MEDIUM 6.5 The FluentAuth plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This i… wordfence
5af7055d-832e-430c-b9d9-bcfc9cf1d10f MEDIUM 6.5 The CountDown Pro WP Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.7 du… wordfence
5af46aef-9c1d-46f2-987d-62c2d668bdad
< 5.4.5
MEDIUM 6.5 The The tagDiv Composer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i… wordfence
5ada82fe-79a5-4763-a22f-13d010d0be39 MEDIUM 6.5 The Do Lasso plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 358 due to insufficie… wordfence
5ac8e551-7995-4201-b711-87773da1be9e
< 4.3
MEDIUM 6.5 The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attac… wordfence
5a109434-4e52-4823-8c5b-d755cb7cbdf9 MEDIUM 6.5 The eDoc Easy Tables plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.29 due to i… wordfence
5a0211d1-45e8-4b20-beb7-0a74d21aa0b5
< 1.8.1
MEDIUM 6.5 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to SQL Injection in versions u… wordfence
59cba7f0-cb06-4408-abba-49552dddd04c
< 2.9.9.6.0
MEDIUM 6.5 The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the … wordfence
599da697-6b24-47b0-aa12-8a8397213316
< 9.7.0
MEDIUM 6.5 The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to unauthori… wordfence
59880d92-5d75-432f-9fb5-d74b13d101ff MEDIUM 6.5 The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do… wordfence
5987ef13-15d6-4ecf-894c-f22c8726402b
< 2.7.17
MEDIUM 6.5 The Brizy – Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a… wordfence
5964dd2a-e388-4454-89f6-aa71e1734d35
< 2.2.9
MEDIUM 6.5 The Gutenberg Forms plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and includ… wordfence
5954bdc0-09e9-4691-95ff-02f7304514c9
< 3.2.3
MEDIUM 6.5 The plugin ACF Quick Edit Fields for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and … wordfence
593eb5bc-59f9-4944-b147-4ba66d49abe6
< 3.0.9
MEDIUM 6.5 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure … wordfence
593cf634-edf2-4c8d-8f24-35bb6e6ff7e4 MEDIUM 6.5 The PGS Core plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.0 due to insuffic… wordfence
← Prev 460 461 462 463 464 465 466 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top