πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 478 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
18ce05fa-0b10-4796-9e78-03e653b862da
< 16.9
MEDIUM 6.5 The Malcure Malware Scanner β€” #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary… wordfence
18a0b8f2-4512-46a5-92a6-66d375c986dd
< 1.0.8
MEDIUM 6.5 The Upload Media By URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
184ee992-1479-4528-9ff7-036affaecdbb
< 1.3.7
MEDIUM 6.5 The WP Mega Menu plugin for WordPress is vulnerable to unauthenticated settings updates that can lead to stored cross-si… wordfence
1830f1be-f95f-422e-9e3b-5f2e46ec5d15
< 5.9.2
MEDIUM 6.5 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection in versions up to, and including… wordfence
1829d178-a35b-4577-9522-8765efec7775
< 1.9.9.5.3
MEDIUM 6.5 The WPLMS plugin for WordPress is vulnerable to SQL Injection in versions up to 1.9.9.5.3 due to insufficient escaping o… wordfence
181f578f-011b-4819-8b4d-1e7e78176e10
< 30.0.1
MEDIUM 6.5 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to SQL… wordfence
181edcec-a57d-4516-935d-6777d2de77ae
< 4.4.3
MEDIUM 6.5 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
1813aaca-3d5a-4650-8a8d-6b54311670f4
< 1.0.6.3
MEDIUM 6.5 The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to unaut… wordfence
1811827d-88ae-45e0-a41e-d15fd0adf44a
< 5.9.1
MEDIUM 6.5 The WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi… wordfence
17d59705-7bd6-4b61-a849-867d76316ca3 MEDIUM 6.5 The Website price calculator plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 4.1 d… wordfence
17872fe4-b566-44ca-8218-3677fb75cb1c MEDIUM 6.5 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to arbitrary file deletion due … wordfence
176a01ae-0f67-4e4a-a9b7-d91cbae2b810
< 1.1.12
MEDIUM 6.5 The Korea for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an… wordfence
175fe7f4-ac92-4c52-9889-47635c21cd9b
< 93.0.0
MEDIUM 6.5 The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of… wordfence
175d0550-3489-4601-8819-a30511544773
< 3.0.5
MEDIUM 6.5 The Mailing Group Listserv plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.4 d… wordfence
1716ef84-759e-4b40-aaa3-ae6ead41fcb5
< 1.3.7
MEDIUM 6.5 The Login with phone number WordPress plugin before 1.3.7 includes a file delete.php with no form of authentication or a… wordfence
16dd90c3-3962-4c8e-993f-b6824c48ab76
< 2.0.8
MEDIUM 6.5 The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for Wo… wordfence
16b407ab-9687-4a10-b458-ad39661e4fb0
< 3.4.2
MEDIUM 6.5 The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated us… wordfence
1689c9bc-4af8-437a-b403-6af9ca4fd959
< 3.0.8
MEDIUM 6.5 The Collapsing Archives plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.7 due … wordfence
1674e81e-6a75-436c-b219-8ec0a484a134
< 7.6.2
MEDIUM 6.5 The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.… wordfence
1653de8f-62eb-488b-9e97-8b30221b509f
< 7.1.9
MEDIUM 6.5 The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and… wordfence
16444905-b111-4b4f-a9f0-d8728da2ebfb MEDIUM 6.5 The WPQuiz plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'wpquiz' shortcode in all v… wordfence
15e671e5-a9a6-4439-93cc-8d46fe0cde16
< 1.10.46
MEDIUM 6.5 The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient… wordfence
15b93e63-5ef2-4fb1-8c6b-28fcfab8e34d
< 1.3.0
MEDIUM 6.5 The WIP Custom Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
1595f231-d300-484a-a0e1-1e2bc7b82ed3
< 4.3.4
MEDIUM 6.5 The BetterDocs plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
1575e301-a26f-485e-bdf3-526b71c8306a
< 2.0.2
MEDIUM 6.5 The Better Font Awesome plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on … wordfence
← Prev 475 476 477 478 479 480 481 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top