πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 477 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1caa8baa-0783-4bc9-af03-46a3a2cf3538
< 8.0.4
MEDIUM 6.5 The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.… wordfence
1c874d4a-7ec0-4024-bc05-80160388507c MEDIUM 6.5 The The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to arbitrary shortcode execution in all ver… wordfence
1c225bea-78db-4f4c-a201-833436c1df78
< 4.29991
MEDIUM 6.5 The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Directory Traversal in versi… wordfence
1bfc5467-6610-4516-8c50-d47d05e2677d
< 2.1.3
MEDIUM 6.5 The Booking for Appointments and Events Calendar - Amelia plugin for WordPress is vulnerable to SQL Injection via the `s… wordfence
1be68c82-c22c-4d45-8c7f-a7aa21fe3ddf
< 1.0.27.1
MEDIUM 6.5 The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.p… wordfence
1bcb675e-bd69-4003-9adc-45a2e0d66347 MEDIUM 6.5 The Cool fade popup plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 10.1 due to in… wordfence
1bc19bfa-ce44-4654-b074-c8126b60a155
< 1.4.7
MEDIUM 6.5 The Hybrid Composer plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the … wordfence
1baa7b7a-49b5-48bd-b45f-31fae707c199
< 1.0.9
MEDIUM 6.5 The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to unauthorized modification o… wordfence
1b786e22-9fbe-4d84-9139-3d18f9339d2f MEDIUM 6.5 The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.0 due to in… wordfence
1b3df470-d0b7-49e8-bcb2-ac999e0b71d1
< 1.4.2
MEDIUM 6.5 The Ultimate SMS Notifications for WooCommerce plugin for WordPress is vulnerable to CSV Injection in versions up to, an… wordfence
1ab4dc20-ce50-4ad0-aff4-9fc529d1911f
< 3.3.2
MEDIUM 6.5 Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripti… wordfence
1aab38ba-ade7-48c9-ac7c-dff1237a9d89
< 8.2.8
MEDIUM 6.5 The Recipe Cards For Your Food Blog from Zip Recipes plugin for WordPress is vulnerable to SQL Injection in versions up … wordfence
1a8b194c-371f-4adc-98fa-8f4e47a38ee7
< 3.3.2
MEDIUM 6.5 The Metform Elementor Contact Form Builder for WordPress is vulnerable to Information Disclosure via the 'mf' shortcode … wordfence
1a74d5f4-1dd8-4d49-b4ce-8ba7ac9cbcc7 MEDIUM 6.5 The Enable jQuery Migrate Helper plugin for WordPress is vulnerable to unauthorized modification of data due to a missin… wordfence
1a4414b1-6a49-42f8-9927-93763d1502ce
< 6.0.7
MEDIUM 6.5 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization by… wordfence
1a23ee5c-275f-4d51-8199-1cc2b0086f73
< 12.4.06
MEDIUM 6.5 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in a… wordfence
1a081788-007e-463b-b757-afefcf4c6e17
< 4.8
MEDIUM 6.5 All In One Favicon plugin for WordPress is vulnerable to Directory Traversal via the 'aioFaviconUpdateSettings' function… wordfence
19f94c4f-145b-4058-aabd-06525fce3cea
< 2.2.8
MEDIUM 6.5 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of… wordfence
19ac688c-d07c-40fa-8155-e3ae45e17b5b
< 1.2.4
MEDIUM 6.5 The WP Subscription Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2.3 du… wordfence
1983cc82-c527-47d9-84ba-f903dda1b1ca
< 1.3
MEDIUM 6.5 The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any… wordfence
193f0a25-4400-40e0-8070-94fbf9c28c11
< 1.9.9.5.3
MEDIUM 6.5 The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping o… wordfence
191f5bc3-9b8e-4ec7-b8b3-91572ef97911
< 2.10.1.5
MEDIUM 6.5 The Beaver Builder plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.10.1.2 due to… wordfence
19062e84-7ce5-400e-a404-2bb4286cc09e
< 2.1.6
MEDIUM 6.5 The miniOrange Discord Integration plugin for WordPress is vulnerable to authorization bypass due to a missing capabilit… wordfence
18e51b35-90fa-4ea0-95f9-644ab864b406
< 2.14.2
MEDIUM 6.5 The WordPress Real Cookie Banner: GDPR (DSGVO) & ePrivacy Cookie Consent WordPress plugin before 2.14.2 does not have CS… wordfence
18daa19e-81f8-4ea8-837b-3f1fce26d2b2 MEDIUM 6.5 The Responsive HTML5 Audio Player PRO With Playlist plugin for WordPress is vulnerable to SQL Injection in versions up t… wordfence
← Prev 474 475 476 477 478 479 480 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top