πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 476 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
215937d9-739b-4198-b375-6d171bbac64a
< 13.1.2
MEDIUM 6.5 The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.… wordfence
20ee6bc7-2732-4da3-b005-a971d12b0e32
< 4.5.6
MEDIUM 6.5 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… wordfence
20da63ad-4b94-417a-b117-5270fe095aab
< 3.6.7
MEDIUM 6.5 The Library Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.6.… wordfence
20aa674b-e504-4548-8d71-f9ba654ffe54
< 2.0.3
MEDIUM 6.5 The Barcode Generator for WooCommerce – Show barcodes on products, orders, invoices and other pages plugin for WordPre… wordfence
20989781-def0-4ffd-bf24-40ed34b3e922
< 0.9.1.7
MEDIUM 6.5 Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administra… wordfence
208c8f55-14e0-47c4-b310-dd7b7edbadd4
< 1.17.6
MEDIUM 6.5 The ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support plugin for WordPress is vulner… wordfence
206261fa-58b6-4407-b8e1-2315836b6c88 MEDIUM 6.5 The Chat Bubble plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3. … wordfence
202d5cda-0957-401b-93ea-7794e08339d1 MEDIUM 6.5 The Fresh Framework plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a fun… wordfence
20066389-f20c-45af-9d86-44549f331b3d
< 1.9.9.5.1
MEDIUM 6.5 The VibeBP plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.1 due to insufficient escaping … wordfence
1ffb9a8e-b08f-451b-bdb5-268d7b618b66
< 7.5.13
MEDIUM 6.5 The WordPress Social Login and Register plugin for WordPress is vulnerable to authorization bypass due to a missing capa… wordfence
1fe363b2-8c70-45cd-9fdc-8979f894efd8
< 2.0.8
MEDIUM 6.5 The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi… wordfence
1fc179bb-cb08-4e85-887e-784016a58c26
< 5.3.1
MEDIUM 6.5 The Order Splitter for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… wordfence
1fb84512-82c3-4def-a11b-ba0b7d64c41f
< 25.1.2
MEDIUM 6.5 The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 25.1.0 due to … wordfence
1f8a69ba-2663-4c54-8aef-4c5b0f851186 MEDIUM 6.5 The Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.… wordfence
1f87298b-8dae-4201-8f3b-477eaab3663d
< 1.4.8
MEDIUM 6.5 The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and … wordfence
1f8634d1-9201-4af5-9e06-c28ffcb51046
< 1.0.107.3
MEDIUM 6.5 The RankMath SEO plugin for WordPress is vulnerable to Local File Inclusion via the 'update_schemas' and 'get_snippet_co… wordfence
1f818aad-8d05-4665-a7dc-50bc56cbde5f
< 2.3.7
MEDIUM 6.5 The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' short… wordfence
1f33a8db-7cd0-4a53-b2c1-cd5b7cd16214
< 3.3.2
MEDIUM 6.5 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf_transaction… wordfence
1ef31d64-ff37-432d-ae4b-7ab451a44e06 MEDIUM 6.5 The Woocommerce Quote Calculator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1… wordfence
1eaee0f6-968c-4004-83e7-f79baf3ff88d MEDIUM 6.5 The Woo Slider Pro – Drag Drop Slider Builder For WooCommerce plugin for WordPress is vulnerable to unauthorized modif… wordfence
1e855031-eddd-45bc-9ed2-80cae03a45df
< 1.0.5
MEDIUM 6.5 The SMSA Shipping for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Download due to missing file vali… wordfence
1e82f614-b6f0-4e78-a337-a286a33f91e6 MEDIUM 6.5 The The SP Blog Designer plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and … wordfence
1e77760b-4e61-462c-9245-0e40f161d565
< 3.24.0
MEDIUM 6.5 The YITH WooCommerce Gift Cards Premium plugin for WordPress is vulnerable to unauthorized gift card creation due to a m… wordfence
1d0d562f-cf21-487b-8386-066d24bdbb13
< 2.3.2
MEDIUM 6.5 The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection in versions up to 2.3.2 due to insufficient esc… wordfence
1caeb5e0-9e4e-4c9e-a6e4-881fb81dc5f2 MEDIUM 6.5 The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all … wordfence
← Prev 473 474 475 476 477 478 479 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top