🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 468 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
46b7820c-f36d-4c7d-b326-07259786fc6a
< 1.8.8.5
MEDIUM 6.5 The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is… wordfence
466a5315-fc05-4b96-9dfd-17862fc406c5
< 2.7.3
MEDIUM 6.5 The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi… wordfence
4648a390-bd89-4493-8daa-cd069b5dafff
< 2.3.4.3
MEDIUM 6.5 The Vimeotheque plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.3.4.2 due to ins… wordfence
462da6ba-c558-4ce8-b26c-df69d086d592 MEDIUM 6.5 The Image Uploader for Welcart plugin for WordPress is vulnerable to generic SQL Injection via the 'post_title' paramete… wordfence
46258dc2-3e05-4050-baad-3b3ded912bfe
< 5.2.5
MEDIUM 6.5 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, … wordfence
461cf8ba-a0d1-4de8-983d-170305e14f97
< 1.3.02
MEDIUM 6.5 The 5 Stars Rating Funnel plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on… wordfence
45d04643-e43a-4732-91bf-e4af7b622e33
< 2.7.1
MEDIUM 6.5 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refe… wordfence
458b58d1-81eb-4934-84ae-55ac66a71df7 MEDIUM 6.5 The Dokan Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.2 due to insuffi… wordfence
457865ca-cbf8-42ee-928d-2c894d9d62de
< 2.5.4
MEDIUM 6.5 The Loco Translate WordPress plugin before 2.5.4 mishandles data inputs which get saved to a file, which can be renamed … wordfence
44f2a414-245b-4c2d-a7ef-ca33b399f6b6
< 1.7.6
MEDIUM 6.5 The Convert Pro plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions … wordfence
44e9e7b5-6d60-4c2b-b29b-1a856dc86b41
< 10.3.2
MEDIUM 6.5 The Quiz And Survey Master plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.3.1 … wordfence
44e112a7-8f51-4d2a-a4b3-74a47ef3aec7
< 1.7
MEDIUM 6.5 The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on th… wordfence
44ace7aa-eacd-4de5-af0b-48b1608c3299
< 3.3.7
MEDIUM 6.5 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to SQL Injection in versions … wordfence
44a98565-7861-4489-9009-43292b6e46df
< 3.9.34
MEDIUM 6.5 The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in al… wordfence
4495e352-758b-4331-a617-033ff348c07d
< 4.5.2
MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection vi… wordfence
44579fe8-4004-4608-b2fd-3531b14e6e69
< 1.3.91
MEDIUM 6.5 The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… wordfence
43f2c4e5-c19d-4b7c-849b-47052bb62cb5
< 6.7.38
MEDIUM 6.5 The Slider Revolution plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missin… wordfence
43d31d1e-0f4f-4f51-8274-650151642d03
< 9.2.2
MEDIUM 6.5 The LifterLMS plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up to, and i… wordfence
4389ddc9-de69-4316-9bfa-ff3bd3346c69
< 2.28.1
MEDIUM 6.5 The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or… wordfence
436d77d9-242a-452b-93d4-707881f59034
< 4.1.5
MEDIUM 6.5 The WP Easy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘custom_style’ paramet… wordfence
436ab843-7729-4d57-9c9e-2ede2f101ddb
< 1.6.11
MEDIUM 6.5 The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in versions up to and inclu… wordfence
4349f322-41ee-43d2-b0a9-567b89aa5d76
< 2.46
MEDIUM 6.5 The Memory Usage plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wpm… wordfence
42f5f29b-2d83-4b15-82aa-0598f8a2317b
< 4.0.6
MEDIUM 6.5 The ARMember plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.5. T… wordfence
42eba5fe-aafa-4cdd-9243-a50df56014fb
< 1.76.0
MEDIUM 6.5 The Memberful plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function … wordfence
42cd1d08-4d5a-466b-930c-f4e28ae4d52c
< 4.2.1
MEDIUM 6.5 The Nelio Content plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.2.0 due to ins… wordfence
← Prev 465 466 467 468 469 470 471 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top