πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 472 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
334839c2-6844-4531-ab16-26f32ddcaba1 MEDIUM 6.5 The BeePress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.9.8. T… wordfence
32db57ec-47f8-4b33-b22c-6d8c079412a8 MEDIUM 6.5 The Photospace Gallery plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on i… wordfence
326c16af-a2d3-431b-9735-a5dbd9a68ae0
< 5.5.7
MEDIUM 6.5 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to unauthorized access … wordfence
321bfc32-a08d-46ea-98c8-c7be10905307 MEDIUM 6.5 The Web en Mantenimiento plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
32192878-930a-4947-a38f-ec395c17e515
< 2.1.3
MEDIUM 6.5 The Ocean Extra for WordPress is vulnerable to disclosure of potentially sensitive data in versions up to, and including… wordfence
31e7c09e-dc81-410c-bc7a-971190245ff1
< 1.13.20
MEDIUM 6.5 The Geo Mashup plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.13.19 due to insu… wordfence
317e17ac-74bd-44cd-8bae-aa893c588a46 MEDIUM 6.5 The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all ver… wordfence
316e98ba-c497-416e-9286-1d67daeb3fd4
< 11.2.1
MEDIUM 6.5 The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to SQL Injection in ve… wordfence
3137a85e-82e3-4111-ae60-1bcf1abd0c0b
< 3.8.4.9
MEDIUM 6.5 The Pie Register – User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorize… wordfence
312bb534-2a40-42f1-9a3e-8b1395e1e199
< 1.24
MEDIUM 6.5 WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows … wordfence
30f2a3ee-7f95-478c-b3d7-c254b9472d42
< 3.6.5
MEDIUM 6.5 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 's… wordfence
30eab93e-0196-4f2e-9e63-a2c293819850
< 1.6.4
MEDIUM 6.5 The Ovic Importer plugin for WordPress is vulnerable to Arbitrary File Download Traversal in all versions up to, and inc… wordfence
30b5ea7f-f731-41c8-bb82-fc59637cb12b
< 2.2.2
MEDIUM 6.5 The WP Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a f… wordfence
30a79974-ee61-4764-8864-89659b1848a4
< 2.3.9
MEDIUM 6.5 The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient … wordfence
309ea238-44a7-4640-88a0-501f74db50ac
< 11.15.11
MEDIUM 6.5 The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to SQL Injection in versions up to, and i… wordfence
3053fa8f-f63e-4f28-a286-9a15e662c645
< 2.2.8
MEDIUM 6.5 The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to SQ… wordfence
303bdead-96e4-45f4-8b57-f1cb703bbe16 MEDIUM 6.5 The WP-Pro-Quiz WordPress plugin through 0.37 does not have CSRF check in place when deleting a quiz, which could allow … wordfence
2fea26e3-365d-4f3b-8d38-fc315befbbac MEDIUM 6.5 The School Management plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 93.2.0 due t… wordfence
2f975d32-a008-46a9-bc00-420610464ecb MEDIUM 6.5 The uninstall plugin before 1.2 for WordPress has CSRF to delete all tables via the wp-admin/admin-ajax.php?action=unins… wordfence
2f58df1f-66f7-4e3d-af6d-08174653a2ad
< 2.2.0
MEDIUM 6.5 The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1… wordfence
2efe885d-7e17-4057-abde-37482047facb
< 4.7
MEDIUM 6.5 The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and … wordfence
2ef5a8f1-ed3c-48bb-9554-b42e9e8d645d
< 1.0.2
MEDIUM 6.5 The Curtain plugin for WordPress is vulnerable to authorization bypass in versions up to, and including 1.0.1 due to ins… wordfence
2ef2ded1-dd56-4c33-98dc-d4c69e66568f
< 2.3.7
MEDIUM 6.5 The Code Embed plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 2.3.6. This… wordfence
2ee6ffb3-9a4a-4564-bfef-116a12268c3c
< 2.3.4
MEDIUM 6.5 In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the… wordfence
2e6d30c9-a759-41b3-8509-f49b89f8d802
< 3.7.3
MEDIUM 6.5 The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to SQL Injection in … wordfence
← Prev 469 470 471 472 473 474 475 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top