ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 470 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
3e815531-f966-44a1-a037-8077a40c83b0
< 3.7.4.1
MEDIUM 6.5 The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including,… wordfence
3e5ad3a7-03c5-4085-b330-bc77e7e46cea MEDIUM 6.5 The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in… wordfence
3db1375b-169a-450d-86b5-2db99f916034 MEDIUM 6.5 The Wp cycle text announcement plugin for WordPress is vulnerable to SQL Injection via the 'cycle-text' shortcode in all… wordfence
3d8f722f-79be-4df2-9f91-e759b8a73277 MEDIUM 6.5 The AIO Contact plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
3d757d89-1079-42d1-94a3-d863bbfa9ad4 MEDIUM 6.5 The Hospital Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 47.… wordfence
3d6b95ee-0a0d-49f7-83b1-4716eec3b863
< 8.7.00.004
MEDIUM 6.5 The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i… wordfence
3d492fcd-5138-44e8-816b-295ec219fd0d
< 1.4.1
MEDIUM 6.5 The Download Attachments plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… wordfence
3d365284-73ac-4730-a83d-9202677cf161
< 4.52
MEDIUM 6.5 The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v… wordfence
3d18fa5a-100f-4dcf-8571-d826c94d173a MEDIUM 6.5 The The Nyla - A Fresh & Modern WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in … wordfence
3c3192ee-f241-47b2-b10f-fc38f394012a
< 2.7.2
MEDIUM 6.5 The "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attacke… wordfence
3c2e41ba-e37d-47c7-bdcb-f9a3801c045a MEDIUM 6.5 The The CURCY - WooCommerce Multi Currency - Currency Switcher plugin for WordPress is vulnerable to arbitrary shortcode… wordfence
3c107916-1de8-46e3-80bf-3e1529533907
< 1.9.11
MEDIUM 6.5 The My Tickets plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.10… wordfence
3bf68449-487d-4ef1-86be-c51dc7d79054
< 4.2.5
MEDIUM 6.5 The WP OAuth Server plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4… wordfence
3bea473d-f97b-4646-9221-deb63e0efe98
< 2024.10.21
MEDIUM 6.5 The Administrator Z plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2024.10.14 due… wordfence
3b9891d4-b9c7-49c7-b40c-3d6525a8ba99
< 1.8
MEDIUM 6.5 The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to una… wordfence
3ad03e3f-fb3e-4a80-9eea-d24459ed62b8
< 11.53
MEDIUM 6.5 The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode ex… wordfence
3a70b64b-a0e8-4b5c-af05-cf8f1d611dec MEDIUM 6.5 The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter hand… wordfence
39dc1ba3-5afe-4ab0-86b8-4a651ba73735
< 1.7.0
MEDIUM 6.5 The Media Library Tools plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.15 due… wordfence
39972b06-920f-48b0-aa36-bb5caab87cb6
< 2.5.5
MEDIUM 6.5 The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i… wordfence
397dabc3-5dcf-4d1f-9e24-28af889cb76f
< 2.8.4
MEDIUM 6.5 The plugin Wbcom Designs – BuddyPress Group Reviews for WordPress is vulnerable to unauthorized settings changes and r… wordfence
397555cf-0b0c-4ce5-97ad-59f135f9d195
< 4.9.9.9
MEDIUM 6.5 The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby' parameter in all vers… wordfence
39404341-8a27-4770-b6a6-d33e899b6bd8
< 3.2.1
MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Sensitive Information Ex… wordfence
393bf415-f4fb-43c4-86b9-f066457e3526
< 2.5.4
MEDIUM 6.5 The Create plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.3 due to insufficie… wordfence
393811e4-71dd-4359-80fa-5a3d146439bb
< 4.2.8
MEDIUM 6.5 The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due t… wordfence
39336115-5993-49e1-b810-80a712e8e42b
< 1.4.1
MEDIUM 6.5 The Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label sw… wordfence
← Prev 467 468 469 470 471 472 473 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top