πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 469 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
425b4f6d-9f13-4aa7-bc97-d6c221d234ca
< 2.29.0
MEDIUM 6.5 The Relevanssi Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to 4.26.0 (Free) & 2.29.0 … wordfence
4235f279-0975-4814-b156-b45b011e3ce6
< 2.1
MEDIUM 6.5 The Prevent Landscape Rotation plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
422bb9a5-c848-4492-add7-bc65b1111565 MEDIUM 6.5 The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss … wordfence
420bcda3-e275-4811-ae37-df69d4d60cee
< 3.6.9
MEDIUM 6.5 The Import any XML or CSV File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing … wordfence
418e1f3b-ca99-4576-add9-d6134ba3869d
< 4.3.25
MEDIUM 6.5 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF check in place when delet… wordfence
4165cff7-457d-4790-8678-84c4365a191a
< 1.4.9.1
MEDIUM 6.5 The Beaver Themer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ… wordfence
4120c8e6-e162-4adf-890c-8070e5009748 MEDIUM 6.5 The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜meta_key’ parame… wordfence
4101c35e-5af9-4372-9ed1-fb6a15d8500f
< 3.2.1
MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Cross-Site Request Forge… wordfence
408312d3-9a9e-4b6b-9991-aee6b77745b2
< 2.7.12
MEDIUM 6.5 The Jobs for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2… wordfence
407a5c69-cce0-4868-aef0-ffc88981e256
< 7.6.1
MEDIUM 6.5 The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in … wordfence
4072ba5f-6385-4fa3-85b6-89dac7b60a92
< 5.1.2
MEDIUM 6.5 The UserPro plugin for WordPress is vulnerable to sensitive information disclosure via the 'userpro' shortcode in versio… wordfence
40595943-121d-4492-a0ed-f2de1bd99fda
< 3.22.1
MEDIUM 6.5 The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of dat… wordfence
402f32fa-466b-4d9e-948f-3b7dc4507105
< 3.2.1
MEDIUM 6.5 The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is… wordfence
400fe58b-8203-4fd5-a3d3-d30eb1b8cd85
< 3.4.2
MEDIUM 6.5 The Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
3fb59a19-3d04-4605-a98a-bcff51359708
< 1.3.62
MEDIUM 6.5 The CP Contact Form with Paypal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… wordfence
3fb25dd5-4191-46ec-8b36-5bb389a7ebfc
< 1.5.5
MEDIUM 6.5 The Directory Kit plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.5.4 due to ins… wordfence
3f8f8319-d75f-4e71-90d4-1c60b5a8df90
< 2.11.14
MEDIUM 6.5 The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path valid… wordfence
3f8f083e-0de2-42a5-b289-101ec53aa44c
< 4.16.12
MEDIUM 6.5 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePr… wordfence
3f7f7cb3-e153-4315-991c-80e8c9be7764
< 11.11
MEDIUM 6.5 The Visitor Traffic Real Time Statistics pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
3f753961-3eeb-402d-876f-4a4dea41a96a
< 1.1.4
MEDIUM 6.5 The Duplicator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.3.… wordfence
3f596af2-ff83-4c67-a8f0-e4df4a0adbd2
< 1.1
MEDIUM 6.5 An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPres… wordfence
3f58ed72-5a0b-4b43-ad76-7730c79741da
< 5.9.8.5
MEDIUM 6.5 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind SQL Injection via … wordfence
3f159aac-092b-4655-9d97-a496ac01738c MEDIUM 6.5 The WP Blockade plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 0.9.14. … wordfence
3f070125-faee-46fe-aa6e-a51772868192
< 5.0.53.decaf
MEDIUM 6.5 The Event Espresso – Event Registration & Ticketing Sales plugin for WordPress is vulnerable to unauthorized access du… wordfence
3ec00aaa-a236-4b99-8104-5062ed440920 MEDIUM 6.5 The Apollo plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.3 due to insufficie… wordfence
← Prev 466 467 468 469 470 471 472 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top