πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 474 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
293ad145-dc93-4d7a-83ba-78f8c730ed6d
< 2.7.1
MEDIUM 6.5 The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge… wordfence
292dab09-7090-4ca9-bca2-0d3e6db08818
< 3.11.3
MEDIUM 6.5 The SALESmanago & Leadoo plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.11.2 du… wordfence
28cf0f3f-0048-4da9-aa86-243479f7b974 MEDIUM 6.5 The WP Human Resource Management plugin for WordPress is vulnerable to Arbitrary User Deletion due to a missing authoriz… wordfence
288946ae-6e58-42e6-89d1-8951539728d3 MEDIUM 6.5 The Easy Newsletter Signups plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due t… wordfence
28477bd5-a55f-4763-b7f2-86b0d9c92fd8
< 3.1.2
MEDIUM 6.5 The Traveler Code plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.1.1 due to ins… wordfence
2830c958-13d1-4c69-8dde-7fc091db02eb
< 3.0.3
MEDIUM 6.5 The Aruba HiSpeed Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabil… wordfence
28246279-ecd8-4731-a4cc-64a3a4167323
< 2.0.4
MEDIUM 6.5 The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization … wordfence
2804c88e-895c-427a-8372-2ef794d9d136 MEDIUM 6.5 The nicen-localize-image plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.9 due… wordfence
27d25885-1a85-40a0-9759-3ae0c8d73d11
< 1.5
MEDIUM 6.5 The WP FullCalendar plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on seve… wordfence
2799ede9-1905-44b9-b731-ce5398d561b1 MEDIUM 6.5 The Batch Cat WordPress plugin through 0.3 defines 3 custom AJAX actions, which both require authentication but are avai… wordfence
27941859-f784-4401-a233-9a58a6e52eb3 MEDIUM 6.5 The Flickr set slideshows plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.9 due … wordfence
278d2d44-16e1-4560-9988-02d900443e42 MEDIUM 6.5 The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape… wordfence
2741ec8c-7bd3-42f9-b964-4532216e1cea
< 2.0.24
MEDIUM 6.5 The Distance Based Shipping Calculator plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
27394b03-3604-4fb0-950f-e1f838cabb05
< 1.8.41
MEDIUM 6.5 The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based blind SQL … wordfence
26fa1781-3919-41a4-9954-325bec856688
< 3.6
MEDIUM 6.5 The Tuturn - Online Tutors Marketplace WordPress Theme plugin for WordPress is vulnerable to Path Traversal in all versi… wordfence
26c4008a-9043-4293-aaf3-8e72de667ad8 MEDIUM 6.5 The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode… wordfence
26a82493-a6a5-4d8e-8322-942925a54cc3
< 6.7.17
MEDIUM 6.5 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress … wordfence
266b1004-a374-4770-9659-bac3d167b585
< 1.22.3
MEDIUM 6.5 The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the re… wordfence
263f7a72-8887-42c3-a1df-3dee904f957e
< 3.2.1
MEDIUM 6.5 The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
260d1418-e489-43af-b28a-a44abf6b9f93 MEDIUM 6.5 The Share Buttons – Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… wordfence
25e0c269-55c2-49f0-96bb-ae2696e2cea8 MEDIUM 6.5 The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficien… wordfence
2591f473-44ff-4319-8b17-b0f793a29d66
< 5.7.0
MEDIUM 6.5 The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization… wordfence
2586662d-c80b-4b6f-85eb-fb472655ea34
< 1.7.0
MEDIUM 6.5 The Docket (WooCommerce Collections / Wishlist / Watchlist) plugin for WordPress is vulnerable to unauthorized access du… wordfence
255cdf64-93cd-434c-9a3c-3b8e49593ffe
< 2.1.15
MEDIUM 6.5 The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection. wordfence
249caa5b-c1b0-4b72-98f3-31bbb574c834
< 2.9.6
MEDIUM 6.5 Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exp… wordfence
← Prev 471 472 473 474 475 476 477 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top