πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 465 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
53889ac8-a101-4aae-a1d2-f25cbf6f58e2 MEDIUM 6.5 The WP Video Gallery WordPress plugin through 1.7.1 does not sanitise and escape a parameter before using it in a SQL st… wordfence
5349096b-4897-4019-9eba-a959a42f03f0
< 1.1.2
MEDIUM 6.5 The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and… wordfence
53157142-f14b-4e95-bea2-77de9b657274 MEDIUM 6.5 The AHAthat Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 1.6 due to … wordfence
52fc484a-973f-44e6-a767-7e27f51c5a0f MEDIUM 6.5 The AnyComment plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.3.6 due to insuff… wordfence
52fb128f-d846-478e-bf9a-cbc3fe8ce89d
< 1.2.15
MEDIUM 6.5 The Reviews Plus plugin for WordPress is vulnerable to Denial of Service in versions before 1.2.14. This is due to an un… wordfence
52105225-1b22-42b9-97b4-a521ced36b01
< 3.0.9
MEDIUM 6.5 The Newspack Blocks plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati… wordfence
51cd51a3-0b8b-4dbb-b384-20076d18cca9
< 1.5
MEDIUM 6.5 The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up … wordfence
51c98a2c-639e-410b-8665-95ba057167bc MEDIUM 6.5 The TSB Occasion Editor plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.1 due … wordfence
518be2c6-36ca-4015-8b7f-451a806c7b1d
< 2.8.6
MEDIUM 6.5 The Welcart e-Commerce plugin for WordPress is vulnerable to Information Disclosure due to missing capability checks on … wordfence
5189c1c0-2d4c-47f5-b8d9-3192a670e586
< 2.0.6.2
MEDIUM 6.5 The Authors List plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi… wordfence
513274bc-3016-4adb-be78-b13c5fae9c03
< 2.9.5
MEDIUM 6.5 The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,… wordfence
51262d25-f7cf-4069-84fb-f283a3f07410
< 5.7.3
MEDIUM 6.5 The BookingPress Appointment Booking Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capa… wordfence
50cc1a15-bb73-4c60-b610-e0c3bf1ef841
< 1.2.3
MEDIUM 6.5 The JobBoardWP plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the ac… wordfence
50c5154c-1573-4c2b-85a1-a89bdb22dc7d
< 1.2.4
MEDIUM 6.5 The WP Directory Kit plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a m… wordfence
505edcf7-7015-453e-abd2-e2cd68a3a9f6
< 1.9
MEDIUM 6.5 The WP Super Cache plugin for WordPress is vulnerable to Unauthenticated Cache Poisoning in versions up to, and includin… wordfence
505d7072-8fca-4b86-9b9c-3f39bc4dcfaf
< 2.2.12
MEDIUM 6.5 The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin f… wordfence
50589b41-cc2b-4ffa-ab63-509fb9d61be2
< 2.1.9
MEDIUM 6.5 The NextGen Gallery plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 2.1.7 via the… wordfence
50421e90-ccd6-4896-8041-b99279314301 MEDIUM 6.5 The LOGIN AND REGISTRATION ATTEMPTS LIMIT plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, a… wordfence
502577dd-49e3-419d-8b37-591be69ad131
< 1.2.0
MEDIUM 6.5 The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to gene… wordfence
50251b17-58d7-4870-b825-a194312fb3e7
< 1.48
MEDIUM 6.5 The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log … wordfence
4ffd74de-6629-4088-ba5c-ac9dd5c6322c
< 4.15.0
MEDIUM 6.5 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
4ff9abb4-2b25-4bbb-86b4-fb1ba37e122f
< 1.0.2
MEDIUM 6.5 The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0… wordfence
4fed59bf-885b-4a06-aff2-8e5ab5f83ba7
< 5.1.4
MEDIUM 6.5 The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version… wordfence
4fe758c4-027f-4667-a22a-9e859894a40f
< 2.45
MEDIUM 6.5 The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater ac… wordfence
4fdfbc46-3e8e-4db1-8778-d46121168d93 MEDIUM 6.5 The WPListCal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.5 due to insuffi… wordfence
← Prev 462 463 464 465 466 467 468 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top