πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 471 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
39192c3f-0021-4094-81c7-e74de1900d4f MEDIUM 6.5 The Error Log Viewer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.5 due to … wordfence
39005c38-f60d-44fa-9121-a77039dc34de
< 1.0.99
MEDIUM 6.5 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access du… wordfence
38f84f31-5aeb-4f6f-9e10-33e365f6f2c8
< 8.3.8
MEDIUM 6.5 The The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including… wordfence
37f6993a-2812-4007-b649-833a32163c75 MEDIUM 6.5 The imEvent theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in … wordfence
37a9b2d0-e27d-4a2c-945a-a06a9b9bd2ea
< 6.9.1
MEDIUM 6.5 The Stylish Price List WordPress plugin before 6.9.1 does not perform capability checks in its spl_upload_ser_img AJAX a… wordfence
379aa658-ebc4-4000-913e-5f95a4783233
< 3.0.8
MEDIUM 6.5 The Rearrange Woocommerce Products WordPress plugin before 3.0.8 does not have proper access controls in the save_all_or… wordfence
377b8532-61b8-45be-ad7c-c9ff60a7100a
< 1.4.0
MEDIUM 6.5 The Caldera Forms – More Than Contact Forms plugin for WordPress is vulnerable to Sensitive Information Disclosure due… wordfence
36d92fc7-8383-4dca-b672-db3b1916c07d MEDIUM 6.5 The Corpkit - Business Consulting WordPress Theme theme for WordPress is vulnerable to Sensitive Information Exposure in… wordfence
368bc607-42b4-49fc-90b1-0ca427cdda4a MEDIUM 6.5 The WooCommerce Point Of Sale (POS) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… wordfence
365fce53-223b-48d3-bfb6-151b74218875 MEDIUM 6.5 The Doctor Appointment Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0… wordfence
3610644e-3481-4fed-a83c-cd9ce09775d2 MEDIUM 6.5 The Traffic Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an u… wordfence
36051ae9-80ae-4abe-8bc7-9a9ec78ee7aa
< 2.6
MEDIUM 6.5 The UberSlider plugin for WordPress is vulnerable to SQL Injection in versions up to, and excluding, 2.6 due to insuffic… wordfence
35eebcc8-a6bf-4cbb-9cc6-f49bd1625d6b
< 2.15.4
MEDIUM 6.5 The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin… wordfence
35be104a-15bc-489b-9806-9abe4ea2388a MEDIUM 6.5 The Rename wp-login.php plugin for WordPress is vulnerable to Cross-Site Request Forgery as well as an authorization byp… wordfence
351926d4-a9be-4fbd-bdf2-8bbff41d97ef
< 3.4.3
MEDIUM 6.5 The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification… wordfence
3511e110-d091-447d-87c0-25d33900bc30
< 2.20
MEDIUM 6.5 The Export All Posts, Products, Orders, Refunds & Users plugin for WordPress is vulnerable to Cross-Site Request Forgery… wordfence
34e89c4d-de55-40bd-8b78-c2ec544c2f60
< 4.9.5
MEDIUM 6.5 The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
34e7688d-af94-4ba4-96a5-8b1ebbde8214
< 3.1.0
MEDIUM 6.5 The wpForo Forum plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 due to insu… wordfence
34d5dbd4-5546-439e-a47a-4f9385116adc
< 1.53
MEDIUM 6.5 The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor. wordfence
34a6d349-dfdc-4301-9380-7fc64c25f043
< 2.6.71
MEDIUM 6.5 The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX a… wordfence
3486f114-5625-4751-a25e-2c5ab7b15b38
< 28.4.1
MEDIUM 6.5 The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is… wordfence
34817e32-d5a3-403a-85f0-1d60af8945de
< 1.2.4
MEDIUM 6.5 The YourChannel plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check when … wordfence
340e98bf-6484-4634-b2f8-e02f14de67de
< 1.2.3
MEDIUM 6.5 The Predictive Search plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to miss… wordfence
33cdd58b-9e5e-492e-a211-78de592f0663
< 2.4.7
MEDIUM 6.5 The easy.jobs- Best Recruitment Plugin for Job Board Listing, Manager, Career Page for Elementor & Gutenberg plugin for … wordfence
33823749-e977-4c91-b8c4-d9774ba46dd9
< 6.3.14
MEDIUM 6.5 The eshop plugin through 6.3.13 for WordPress has CSRF with resultant XSS via the wp-admin/admin.php?page=eshop-download… wordfence
← Prev 468 469 470 471 472 473 474 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top