🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 467 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
4bc10693-6d7c-4293-8848-02181ceb0d25
< 1.6.1
MEDIUM 6.5 The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPres… wordfence
4bbff678-db55-4058-9f54-9220321616b0
< 1.2.3
MEDIUM 6.5 The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and i… wordfence
4b796697-5f4b-435f-a63f-1f20afc4182b
< 1.1.3
MEDIUM 6.5 The Hive Support – WordPress Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and incl… wordfence
4b68e8d4-58d4-4753-bda3-60c0d874f822
< 2.2.1
MEDIUM 6.5 The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS … wordfence
4a86d15a-0abf-464c-a998-c1fc96edc964 MEDIUM 6.5 The Gboy Custom Google Map plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due… wordfence
4a82c911-71aa-4f6c-8088-7b839e027a6a
< 1.8.42
MEDIUM 6.5 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to SQL Injection in vers… wordfence
4a7c9797-918b-4cde-9815-9d796fb09d45 MEDIUM 6.5 The Quran Shortcode plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5 due to ins… wordfence
4a7a15ab-4f13-4eb1-aeb5-143230308871
< 1.3.7
MEDIUM 6.5 The All Bootstrap Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
4a0c04fe-7a9f-4a3f-ba2c-3bdcb5dec060
< 4.5.6
MEDIUM 6.5 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… wordfence
49f5bb21-d18f-453b-bef4-e3b234d162c8
< 1.4.3
MEDIUM 6.5 The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofi… wordfence
497b51f5-fb0a-4fd4-a545-cece9ec80a94 MEDIUM 6.5 The Pakke Envíos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due to ins… wordfence
495183b6-dc7c-4ff7-bc99-fc05a10d1269
< 1.3.53
MEDIUM 6.5 The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
490061dc-11f7-48f2-bc9a-974bedf16621
< 2.3.3
MEDIUM 6.5 The Stamped.io Product Reviews & UGC for WooCommerce plugin for WordPress is vulnerable to unauthorized access and modif… wordfence
48d6cd72-6a38-403b-9a8f-960e99d8801f
< 1.6.13
MEDIUM 6.5 The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content… wordfence
48ba0558-41ad-46f5-971d-3da9311b262b
< 1.8.2
MEDIUM 6.5 The Rankie - Wordpress Rank Tracker Plugin plugin for WordPress is vulnerable to SQL Injection in all versions up to 1.8… wordfence
48a59d72-16f2-498e-b042-ce79b55605dc
< 0.3.5
MEDIUM 6.5 The Cecabank WooCommerce Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability ch… wordfence
487d94e8-e4f1-4da8-914c-96157f8ae14d
< 5.7
MEDIUM 6.5 The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which c… wordfence
48784892-443f-452c-9fe9-12e73af1cf7f
< 5.6.1
MEDIUM 6.5 The Booster for WooCommerce plugin for WordPress is vulnerable to order modification due to a missing capability/authori… wordfence
4838c2ad-87e0-4140-81bb-7d39d7a704dc
< 6.2.9
MEDIUM 6.5 The eshop plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘eshoptemplate’ GET parameter… wordfence
4822f1c7-3f83-416c-8957-17e4b53d7e69
< 2.1
MEDIUM 6.5 The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all… wordfence
4783eff5-b7cf-4342-b762-85f745c38ec8
< 4.0.0-rc17
MEDIUM 6.5 The Font Awesome plugin for WordPress versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable to API Token Exposure. The vulne… wordfence
4772b482-f5e5-4707-b012-aca70fc89e49 MEDIUM 6.5 The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.… wordfence
475ca301-32f2-4913-925c-369a9a4c83c1 MEDIUM 6.5 The Table Generator plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
47243ee1-42da-480c-94b8-bdebd8f9eac6
< 3.0.7
MEDIUM 6.5 The Taskbuilder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.6 due to insuf… wordfence
46c61f38-553e-43b2-a666-b160db40e66d
< 3.4.9
MEDIUM 6.5 The WP-Members Membership Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up… wordfence
← Prev 464 465 466 467 468 469 470 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top