πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 481 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
0c410d91-08cc-496d-9c8e-c57f107399da
< 4.2.6.4
MEDIUM 6.5 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all ve… wordfence
0b4cb873-77b7-44f9-820c-38e5d43393f3
< 3.2.1
MEDIUM 6.5 The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via… wordfence
0b32c63d-ce6b-4fac-8198-3a598fc84f7a
< 6.7.7
MEDIUM 6.5 The WooCommerce Frontend Manager – Ultimate plugin for WordPress is vulnerable to SQL Injection in versions up to 6.7.… wordfence
0b301c6e-a3c5-4435-9bc9-fab18085fe2d
< 2.0.4
MEDIUM 6.5 The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… wordfence
0b04ab77-880b-423a-bba6-59822f0463bc
< 2.18.0
MEDIUM 6.5 The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of … wordfence
0add0b7c-c47a-4ff0-b750-9b1433970d85
< 1.23.3
MEDIUM 6.5 The Timber plugin for WordPress is utilizing a vulnerable version of Twig in all versions up to, and including, 1.23.1. … wordfence
0abd2533-5cb3-4568-8ad2-f2852ab3a8db
< 2.5.25
MEDIUM 6.5 The Html5 Video Player plugin for WordPress is vulnerable to SQL Injection via the 'id’ parameter in all versions up t… wordfence
0aa21fad-4dd0-4ccd-a325-de3532a6ffaf
< 5.0.0
MEDIUM 6.5 The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, … wordfence
0a69e4e0-0872-4604-98ae-6a0502e7e965
< 1.0.6
MEDIUM 6.5 The The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to arbitrary shortcode execution… wordfence
0a4521af-692a-4a84-ba9b-1904a42786c1 MEDIUM 6.5 The App Builder – Create Native Android & iOS Apps On The Flight plugin for WordPress is vulnerable to Privilege Escal… wordfence
09bfe9c2-fea2-4876-8f7c-0bd14060e4ad
< 3.8.2
MEDIUM 6.5 The SALESmanago plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functio… wordfence
09aa2a44-8665-4f70-97a5-2e869c4610a4
< 1.9.7
MEDIUM 6.5 The ActiveCampaign plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the c… wordfence
09925777-5a25-4c7a-bc05-970512992943 MEDIUM 6.5 The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to SQL … wordfence
09831b2f-8f79-4833-8fc6-f1af56c6abc8
< 5.0.0
MEDIUM 6.5 The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of da… wordfence
095a2262-1da2-4f79-896c-6d48eb079a7b
< 1.1.7
MEDIUM 6.5 The AffiEasy plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.… wordfence
093611bc-1b09-4654-a7f8-b4c6bd7c72c5 MEDIUM 6.5 The Video List Manager plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7 due to … wordfence
08eb1d49-9928-43f8-97fc-14105e3a4a25
< 1.2.2
MEDIUM 6.5 The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow unspecif… wordfence
08bebfbd-08f4-45d9-9570-46f5c848afca
< 1.1.2
MEDIUM 6.5 The User Meta plugin for wordPress is vulnerable to Arbitrary File Uploads in versions up to, and including 1.1.1, due t… wordfence
08bd24ca-eec6-4b62-af49-192496e65a5b
< 1.2.6
MEDIUM 6.5 The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPres… wordfence
08aabd8d-8add-423e-835f-dc4d8bbdb72c
< 8.6.10
MEDIUM 6.5 The The MapSVG – Vector maps, Image maps, Google Maps plugin for WordPress is vulnerable to arbitrary shortcode execut… wordfence
085d06e1-31d3-4c01-8d8e-588c04b79ae3
< 9.7.0
MEDIUM 6.5 The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜tooltip’ parameter in… wordfence
085a4fae-c3f4-45f9-ab30-846c6297d04e
< 3.1.3
MEDIUM 6.5 The Product Filter for WooCommerce by WBW plugin for WordPress is vulnerable to unauthorized data loss due to a missing … wordfence
0830d0c3-99c0-423e-99ab-f0c1cbec52d9
< 3.9.4
MEDIUM 6.5 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized access of data… wordfence
07c79459-66b8-4c93-a1cd-6e3ede95643f
< 5.1.3
MEDIUM 6.5 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom… wordfence
07c0b4c5-d76e-4bdc-87d1-3144a1466c77
< 3.1.4
MEDIUM 6.5 The SupportCandy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, … wordfence
← Prev 478 479 480 481 482 483 484 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top