🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 475 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
2493a2f8-d4e4-4c42-b748-5632b96b085e
< 4.4
MEDIUM 6.5 The Export All URLs for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 4.3 due to… wordfence
247df9e2-0a63-49ad-86fa-cb4c6e62c4cf
< 1.5.2
MEDIUM 6.5 The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and i… wordfence
24741fa0-5075-445b-91fe-d896a9101b45
< 1.4.2
MEDIUM 6.5 The Classic Editor and Classic Widgets plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
24696285-094a-40a6-af33-6b7aefbbdc05
< 2.6.1
MEDIUM 6.5 The Multimedia Responsive Carousel with Image Video Audio Support plugin for WordPress is vulnerable to SQL Injection in… wordfence
241b29c2-eaeb-4abb-a33c-631e768e03b8
< 10.2.4
MEDIUM 6.5 The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 10.2.3 du… wordfence
23e1a1e0-fcc2-441f-b77e-1b3d991262ea
< 5.9.5.4
MEDIUM 6.5 The ProfileGrid plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.9.5.3 due to in… wordfence
23d75811-37cc-4bb0-94a3-0f8dd363c679
< 9.0.12
MEDIUM 6.5 The teachPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.0.11 due to insuf… wordfence
23b4e19d-d8ba-469c-8463-bace9a7d9726 MEDIUM 6.5 The WP Guppy plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.3.3 due to insuffic… wordfence
23b2d82a-5c2b-405e-b52e-b1b968f3f48a
< 1.8.5
MEDIUM 6.5 The KiotViet Sync plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.4 due to ins… wordfence
23521bba-8f3a-4d87-901a-cf2d666eefa4
< 3.6.4
MEDIUM 6.5 The Ubigeo de Perú para Woocommerce WordPress plugin before 3.6.4 does not properly sanitise and escape some parameters… wordfence
22ddafad-9214-4d32-9fc3-3f3c759633ad MEDIUM 6.5 The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versi… wordfence
22cc3d7b-b85c-473b-9573-44d36dde7b82
< 1.0.5
MEDIUM 6.5 The Spreadr Woocommerce Plugin – Amazon Importer for Dropshipping and Affiliate plugin for WordPress is vulnerable to … wordfence
22c82c75-a1ab-45a6-90ef-50b993ede483 MEDIUM 6.5 The LambertGroup - AllInOne - Banner with Thumbnails plugin for WordPress is vulnerable to SQL Injection in versions up … wordfence
22b18a9c-89e5-43e1-9553-5862df25bf47
< 3.8.1.3
MEDIUM 6.5 The Pie Register plugin for WordPress is vulnerable to arbitrary user deletion in versions up to, and including, 3.8.1.3… wordfence
22a1920e-2a3f-4996-873d-26e3930e6929
< 1.6.3
MEDIUM 6.5 The Advanced Local Pickup for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing cap… wordfence
22930940-8e2c-446a-954c-90d617f3ca6d
< 6.6.0
MEDIUM 6.5 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to privi… wordfence
229245a5-468d-47b9-8f26-d23d593e91da
< 1.0.19
MEDIUM 6.5 The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification … wordfence
227886e8-99d9-49b3-a1a8-b06b02d331bc
< 2.5.4
MEDIUM 6.5 The Like Button Rating plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in t… wordfence
2273f637-a80d-46af-8ce6-dfcd25a87679
< 1.5.0
MEDIUM 6.5 The ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin for WordPress is vulnerable to SQL Injectio… wordfence
21ffbb00-7c84-4d00-9a7f-0e412d8d5ed7 MEDIUM 6.5 The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up … wordfence
21bc2595-0760-42a6-b11b-3f7609223d8b
< 1.8.3
MEDIUM 6.5 The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulne… wordfence
21a27a8b-f599-42b9-9439-4456995dd3fe
< 1.10.5
MEDIUM 6.5 The jQuery Manager for WordPress plugin for WordPress is running a vulnerable version of jQuery in all versions up to, a… wordfence
2180dc08-25a8-474b-b382-5ce359de04b5 MEDIUM 6.5 The Popup Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in versio… wordfence
217d68dc-6133-4b7e-9d8f-bb8fc18f1c12 MEDIUM 6.5 The 001 Prime Strategy Translate Accelerator plugin for WordPress is vulnerable to authorization bypass due to a missing… wordfence
21708205-dd43-4b22-9151-bc6f882422cb
< 0.92.0
MEDIUM 6.5 The List category posts plugin for WordPress is vulnerable to time-based SQL Injection via the ‘starting_with’ param… wordfence
← Prev 472 473 474 475 476 477 478 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top