πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 473 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2e5602b2-c1ed-40a5-8186-3ab1b5e32f7f
< 6.1.12
MEDIUM 6.5 The The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is… wordfence
2df2312c-56d7-4899-8342-6f6cf62298e0 MEDIUM 6.5 The FormBuilder WordPress plugin through 1.08 does not have CSRF checks in place when creating/updating and deleting for… wordfence
2d1414f5-e705-4fd4-847b-b46d2d20943b MEDIUM 6.5 The Headless CMS plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability che… wordfence
2cfdde5c-f0e3-4597-9789-3ff0347719c6
< 5.0.3
MEDIUM 6.5 The Taskbuilder – WordPress Project Management & Task Management plugin for WordPress is vulnerable to time-based blin… wordfence
2ccadf7c-b628-43b6-a6b0-828ca31ff9cc
< 1.5.2
MEDIUM 6.5 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via … wordfence
2bfe721b-1614-488c-a467-dd205e93047b
< 1.1.14
MEDIUM 6.5 The WPBulky plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.13 due to insuffic… wordfence
2beaf82f-3709-48de-bcc2-535479c4fafe
< 1.1.4
MEDIUM 6.5 The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on… wordfence
2bc07a16-a3c7-4831-a226-355f303f31a7
< 1.2.51
MEDIUM 6.5 The WP Time Slots Booking Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2… wordfence
2bb47ffd-1375-444c-8c55-05b59cb03f63
< 3.35
MEDIUM 6.5 The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.34 d… wordfence
2ba63578-c65e-4050-aa68-1d6351fccd06
< 2.15.19
MEDIUM 6.5 The Infility Global plugin for WordPress is vulnerable to SQL Injection in versions up to 2.15.19 due to insufficient es… wordfence
2b45674c-8446-44eb-a45a-15dab02c89cf MEDIUM 6.5 The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives … wordfence
2b11670a-f6e4-4555-ab76-4223f0194517
< 3.3.8
MEDIUM 6.5 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypa… wordfence
2ae7f5e3-7312-4fee-962b-3aecd8432557
< 3.6.3
MEDIUM 6.5 The WP Register Profile With Shortcode plugin for WordPress is vulnerable to Sensitive Information Exposure in all versi… wordfence
2ac1e3ee-4dcc-4f45-ad07-17af750da3d1
< 7.8
MEDIUM 6.5 The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to una… wordfence
2a965a23-5594-4925-8104-6f387a60ab49
< 1.5.8
MEDIUM 6.5 The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Par… wordfence
2a5ea5b6-4c34-4d77-9a3a-af53b914a72a
< 4.4.4
MEDIUM 6.5 The The WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds plugin for WordPress is vulnerable t… wordfence
2a4e66e0-85a6-4e9f-8ed7-b7ee8e75aae6
< 1.4.6
MEDIUM 6.5 The Portfolio Gallery – Responsive Image Gallery plugin for WordPress is vulnerable to unauthorized modification and l… wordfence
2a47e3cc-9435-4e9c-8d9a-9eb5014d229f
< 3.5.6
MEDIUM 6.5 The WP-Members Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'order_by' attribute of the… wordfence
2a2f4c83-27a6-4c50-b701-8374f21b3799
< 3.2.2
MEDIUM 6.5 The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before us… wordfence
29ea6ec6-3dc8-4bb6-bdec-bc2a24d2478b MEDIUM 6.5 The Solidres – Hotel booking plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
29dff562-e9b0-4cc9-b974-9239fbf0310f
< 5.81
MEDIUM 6.5 The UnderConstructionPage PRO plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and inclu… wordfence
29d6df4e-eaf6-42ec-8cd9-7cf86908f4ef MEDIUM 6.5 The Email download link plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and incl… wordfence
29a560fa-03bf-435c-85da-68397deab2a6
< 5.0.3.1
MEDIUM 6.5 The LearnDash LMS plugin for WordPress is vulnerable to blind time-based SQL Injection via the 'filters[orderby_order]' … wordfence
298e6e77-b4bd-4476-ae8b-39fef045fbdb MEDIUM 6.5 The RJ Quickcharts plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.6.1 due to in… wordfence
294e1822-b92c-48a4-bfc6-5a89cfbe0bc7
< 31.0.0
MEDIUM 6.5 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Sec… wordfence
← Prev 470 471 472 473 474 475 476 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top