πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 480 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
1088f498-e718-41bc-866e-7027352a2a5b MEDIUM 6.5 The Splashscreen plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 0.20. … wordfence
102e17f3-2c56-48c0-b8f5-992a69abfacc
< 4.7
MEDIUM 6.5 The Justified Image Grid - Premium WordPress Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery i… wordfence
10262aa9-5656-4a2b-aeb5-060018798369
< 4.12.0
MEDIUM 6.5 The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, an… wordfence
10253537-1a54-471c-bf0d-e8523b0c6ae1 MEDIUM 6.5 The WP Featured Entries plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 due to… wordfence
1009c839-849f-47ce-bfab-c297aacbc23c MEDIUM 6.5 The Image Zoom plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several o… wordfence
0fc675e8-8ba1-40b0-829e-7a48d5eb586d
< 2.6.5
MEDIUM 6.5 The Japanized For WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification due to missing … wordfence
0f916d4c-fb79-4d7c-a5a6-08d1e159ebd3 MEDIUM 6.5 The WooCommerce Amazon Affiliates - Wordpress Plugin plugin for WordPress is vulnerable to SQL Injection in versions up … wordfence
0f8e2fec-c388-449e-892a-c09c09587028
< 3.15.0.6
MEDIUM 6.5 The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to arbitrary file deletion … wordfence
0f4bb514-80bd-4d66-a60f-0a6a287af5de MEDIUM 6.5 The WP Image Carousel WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wpic shortcode… wordfence
0f2c46f7-b7c9-41a5-8cf9-61a683c3922c
< 1.2.6.1
MEDIUM 6.5 Cross-Site Request Forgery (CSRF) vulnerability discovered in Contact Form 7 Database Addon – CFDB7 WordPress plugin (… wordfence
0f1c95a2-a3d8-41d5-a635-9dcd012dbdbb MEDIUM 6.5 The Include URL plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.3.5. This m… wordfence
0f19194c-dbe8-455d-bee7-2f7d4ce9224f
< 3.7.16
MEDIUM 6.5 Directory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php … wordfence
0f18a1c5-a0b7-49f9-acc1-5604304fd72f
< 10.12.0.2
MEDIUM 6.5 The ICS Calendar plugin for WordPress is vulnerable to Directory Traversal in all versions up, and including, 10.12.0.1 … wordfence
0ec64507-b77e-4685-978f-7408fe8db5ee
< 2.3.6
MEDIUM 6.5 The EazyDocs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
0e7ac22f-cb50-46b6-b244-22b5e8dc8142
< 1.6.0
MEDIUM 6.5 The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization due to a missing capa… wordfence
0dd53fad-1bd7-41ed-95cb-205a9b421724
< 1.4.9
MEDIUM 6.5 The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to… wordfence
0dc5479e-629b-4ad8-8bef-b35e22372eb4 MEDIUM 6.5 The Market 360 Viewer plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.01 due to … wordfence
0d583c43-7da9-40c6-a71d-ec5834e6c427 MEDIUM 6.5 The fwdevp theme for WordPress is vulnerable to Path Traversal in all versions up to, and including, 10.0. This makes it… wordfence
0d42ca2f-f061-4cd1-812b-46d42c440498
< 2.4.0
MEDIUM 6.5 The WP Media Category Management plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 2.0 to 2.3… wordfence
0cf7ec81-625b-4abf-9304-256701e933ee
< 1.3.3
MEDIUM 6.5 The WholesaleX – WooCommerce Wholesale Plugin (Wholesale Prices, Dynamic Pricing, Tiered Pricing) plugin for WordPress… wordfence
0cf614a2-d5fe-4881-9a88-c993da58ca2a MEDIUM 6.5 The CardCom Payment Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check … wordfence
0ce2d464-b467-47cb-b3ac-0487de778434
< 1.6
MEDIUM 6.5 The Magic Responsive Slider and Carousel WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to… wordfence
0c6a49d1-633b-47aa-8390-5df3bf8f71a5
< 4.6.2
MEDIUM 6.5 wordfence
0c479ceb-170f-46d6-b1ce-ca5469147d5f MEDIUM 6.5 The The Auros Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includ… wordfence
0c424ffa-2aa8-4126-afba-d93ae696e7fa
< 1.1.33
MEDIUM 6.5 The Hydra Booking plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.32 due to in… wordfence
← Prev 477 478 479 480 481 482 483 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top