🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 479 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
15613da5-f900-4a33-8eec-6c9e52ed30fc MEDIUM 6.5 The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability… wordfence
1543265e-dbbf-4d48-aaa9-353e2a5c3fe9
< 3.1.43
MEDIUM 6.5 The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Inj… wordfence
1531ed5e-cb47-447d-87dc-5a06a88073d5 MEDIUM 6.5 The Neon Product Designer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.1 du… wordfence
14e9d0a2-a1cb-4d3e-b6df-fba01d476936
< 1.7.9.8
MEDIUM 6.5 The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.9.7 d… wordfence
14d7d6a9-64f7-4209-8ee9-eac4d7a8dea1
< 1.3.93
MEDIUM 6.5 The Appointment Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
14a84b47-b176-475f-b983-00416b603fc4
< 3.36
MEDIUM 6.5 The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.35 d… wordfence
148cc174-c6cf-46d7-98d7-1a07e19055e1
< 2.2.2
MEDIUM 6.5 The Page Restrict plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'message' parameter in versi… wordfence
148573a1-ccdc-4515-8e49-b1b04911abcf MEDIUM 6.5 The Eagle Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.4.3 due to i… wordfence
147b7be2-8bbe-4e95-bfcb-1c4ff8a41a3b
< 2.0.7
MEDIUM 6.5 Vulnerable versions of the JupiterX Theme allow any logged-in user, including subscriber-level users, to access any of t… wordfence
144895c9-5800-435e-9f75-a8de17ca2d93
< 5.12.8
MEDIUM 6.5 The Shortcodes Ultimate for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
140fa6e8-4381-4df2-af62-44d40b116daf
< 5.9.4.8
MEDIUM 6.5 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to blind and time-based SQL… wordfence
1405cdd2-2b68-4b2f-bae6-9465c96da918 MEDIUM 6.5 The Unicamp - University and College WordPress Theme theme for WordPress is vulnerable to SQL Injection in versions up t… wordfence
13245eab-9a72-44d7-bbcd-a0d3e2879814
< 2.2
MEDIUM 6.5 The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to PHP Object Injection in all vers… wordfence
12ecb8ae-9aa3-4826-959e-cbac8eb5e76c
< 0.9.2
MEDIUM 6.5 The Media Search Enhanced plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.9.1 du… wordfence
12dc548c-01df-4934-9d18-1d4584545599
< 12.4.06
MEDIUM 6.5 The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 12.… wordfence
12891613-1447-4e5d-bf01-fa14abe6e9d6 MEDIUM 6.5 The Golf Tracker plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 0.7 due to insuff… wordfence
11fbe76c-dc5c-413c-b6a8-d0f4aa56935d
< 1.9.9
MEDIUM 6.5 The Two Factor (2FA) Authentication via Email plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in … wordfence
11e97adc-b402-4d82-ae39-4dccbd70bcf2
< 1.11.8
MEDIUM 6.5 The Elementor Addon Elements plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
11e7617d-6d45-4e8d-a82f-fc9da4aeabcf MEDIUM 6.5 The The Duka Market - Multipurpose eCommerce Template theme for WordPress is vulnerable to arbitrary shortcode execution… wordfence
11b8c13b-2167-4fca-a981-a331fadc0439
< 1.1.2
MEDIUM 6.5 The Olive One Click Demo Import plugin for WordPress is vulnerable to unauthorized modification of data due to a insuffi… wordfence
115d549c-2dea-4d94-9c50-75b8149be1e4 MEDIUM 6.5 The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its se… wordfence
111a1e7f-bc87-4130-a0b2-422d0f98afb6
< 1.27.7
MEDIUM 6.5 The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plugin for WordPress is vulnerable to Path Travers… wordfence
10ed13e9-f196-47cc-9e45-a7646444cc5b
< 4.1.1
MEDIUM 6.5 The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes. wordfence
10d5bc57-9512-4f70-98fc-e1307178a071 MEDIUM 6.5 The SHOUT plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.5.3 due to insufficien… wordfence
10a6f9cb-5adf-44b0-b7d1-f245637e00b3
< 5.8.14
MEDIUM 6.5 The EasyCart plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.8.13 due to insuffi… wordfence
← Prev 476 477 478 479 480 481 482 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top