πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 464 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
58f9bef5-6596-40b2-bcb6-d686e87d8d8f
< 8.3.18
MEDIUM 6.5 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, … wordfence
58e3b7f1-26f4-453a-ae1f-a1e6eed0348c
< 5.0.3
MEDIUM 6.5 WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can … wordfence
58cc0a13-cda1-499b-b29a-e0b358a2e8e5
< 5.3.0
MEDIUM 6.5 The YML for Yandex Market plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path va… wordfence
58a1f3a1-e00c-4b63-83ad-73205c67c0ac MEDIUM 6.5 The eBay Dropshipping and Affiliate by Wooshark plugin for WordPress is vulnerable to authorization bypass due to missin… wordfence
58695d72-d78e-4e5a-8179-a5d12a80b370
< 1.1.5
MEDIUM 6.5 The WP Sessions Time Monitoring Full Automatic plugin for WordPress is vulnerable to SQL Injection in versions up to, an… wordfence
58387a60-ef68-4911-9349-97b0f7e7726f
< 1.8.13
MEDIUM 6.5 The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜al… wordfence
582fa92d-8e52-49a9-94ce-f1b49229f591
< 3.5.6
MEDIUM 6.5 The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and i… wordfence
5808b671-7795-4a1a-8c8c-b64a3d0db378 MEDIUM 6.5 The Simple Job Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1 due to … wordfence
57a12c21-4a5d-4fbd-8720-93e78164f216
< 4.5.8
MEDIUM 6.5 An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not… wordfence
575ec3a9-26f7-415b-9df6-d0401557a578
< 1.6.2
MEDIUM 6.5 The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to… wordfence
570bca1e-78d0-49e8-8919-eba19f9457b9
< 1.4.1
MEDIUM 6.5 includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin … wordfence
564b8271-ba1a-4bf1-b072-7dadadb02ccf
< 1.1.31
MEDIUM 6.5 The CubeWP plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.30 due to insuffici… wordfence
56233337-ddde-4630-99b7-46a8e2be70af MEDIUM 6.5 The smart SEO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0 due to insuffici… wordfence
561479ed-2402-4511-9344-d6b9e28f2f33
< 5.0.7
MEDIUM 6.5 The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to ti… wordfence
5589754a-2234-457e-bfa4-59fb4161d736
< 7.6.1
MEDIUM 6.5 The Product Feed Manager for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and incl… wordfence
55604ee9-7343-472c-9a29-035d18b266ab
< 2.0.1
MEDIUM 6.5 The JS Job Manager plugin for WordPress is vulnerable to unauthorized access to plugin functionality due to missing capa… wordfence
54db1807-69ff-445c-9e02-9abce9fd3940
< 4.10.1
MEDIUM 6.5 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in al… wordfence
54cccd61-35d0-432c-8832-28e7928c464d
< 1.3
MEDIUM 6.5 The Add Multiple Marker plugin for WordPress is vulnerable authorization bypass in versions up to, and including, 1.2. T… wordfence
549cd23f-3b3a-41b7-baa2-cc5c6b826a2e
< 3.5.8
MEDIUM 6.5 The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions funct… wordfence
546f388e-16e2-4c0b-acb0-a462bff4ef77 MEDIUM 6.5 The Webmaster Tools Verification plugin for WordPress is vulnerable to authorization bypass due to a missing capability … wordfence
546bd215-61aa-48bd-915e-7ced0128f53d
< 3.4.2
MEDIUM 6.5 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated us… wordfence
54344300-6288-40bc-b539-3dc9b555ed00
< 2.2.1
MEDIUM 6.5 The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site… wordfence
541d202b-f3ed-44d8-93a6-e158209db885
< 1.2.4
MEDIUM 6.5 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when c… wordfence
54154f34-96be-4b67-bca8-8efc4ab8543e
< 1.3.19
MEDIUM 6.5 The Premmerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.18.… wordfence
53f12e61-fdb0-4838-b733-fc4d7a4ff016
< 1.8.7
MEDIUM 6.5 The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
← Prev 461 462 463 464 465 466 467 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top