πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,891
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 18, 2026
Last Updated

39,891 vulnerabilities found (page 482 of 1596)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
07b1dc05-1340-4ea3-9315-3e1ca4a0cb7f
< 1.5.1
MEDIUM 6.5 The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for W… wordfence
07068c38-9cae-4f3e-beee-388de26b9741
< 4.4.7
MEDIUM 6.5 The Radio Player Shoutcast & Icecast WordPress Plugin plugin for WordPress is vulnerable to SQL Injection in versions up… wordfence
06f3c08a-9791-4c66-a173-8bbbb38d05ab
< 1.7.5
MEDIUM 6.5 The DeepL Pro API Translation plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and inclu… wordfence
06ecc40c-6a63-4354-9f49-1925896622f5
< 2.14.10
MEDIUM 6.5 The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i… wordfence
063d452b-2a35-40aa-a002-ea55da778222
< 2.1.8
MEDIUM 6.5 The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due… wordfence
05dbb5f4-b73b-46b4-9177-ba1d36fe0ee7
< 4.6.1
MEDIUM 6.5 The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to… wordfence
0538f5dc-0f1e-40e7-a179-7b8d30b85ecc MEDIUM 6.5 The Cube Portfolio plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.16.8 due to i… wordfence
05220967-dd42-4cb9-9c2f-9c7ac3c0926b
< 3.11.2
MEDIUM 6.5 The Fusion Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.… wordfence
04d51f3c-4dff-4777-b46c-516546560d90
< 3.0.4
MEDIUM 6.5 The Booking (Reservation & Appointment) plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… wordfence
04c23273-47de-4f40-8254-14c86b8362ff MEDIUM 6.5 The WordPress Google Map Professional plugin for WordPress is vulnerable to SQL Injection in versions up to, and includi… wordfence
049ffab1-677d-4112-9f1d-092ee01299f1
< 3.0.0
MEDIUM 6.5 The wpForo Forum plugin for WordPress is vulnerable to unauthorized modification of data due to the use of `extract($arg… wordfence
04881aac-9d3b-48c0-b095-e91797df46e3
< 4.5.15
MEDIUM 6.5 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injectio… wordfence
04604090-e40c-4480-8432-483ebbda5f45 MEDIUM 6.5 The Hero Mega Menu - Responsive WordPress Menu Plugin plugin for WordPress is vulnerable to SQL Injection in versions up… wordfence
0439d2ee-7742-4aa7-ba4e-db55c6b2718e
< 2.0.8
MEDIUM 6.5 The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
0402e4a6-73ba-49e6-bf80-997ac83b4cfe
< 2.21.7
MEDIUM 6.5 The Bit Form – Contact Form Plugin plugin for WordPress is vulnerable to unauthorized workflow execution due to missin… wordfence
03ffb77e-fcb2-42ff-9010-d067d746c543
< 7.8.8
MEDIUM 6.5 The Cornerstone plugin for WordPress is vulnerable to SQL Injection in versions up to 7.8.8 due to insufficient escaping… wordfence
03177018-94cb-4e14-9476-e2d369414c38
< 5.0.3
MEDIUM 6.5 The Product Catalog Mode For Woocommerce plugin for WordPress is vulnerable to unauthorized access and modification of d… wordfence
02fde6b1-d709-4329-ae9c-fea444c1aec8
< 7.1.2
MEDIUM 6.5 The Woodmart theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.1.1. Th… wordfence
029c3606-caba-4964-aefd-6000a1b4832d MEDIUM 6.5 The WORDPRESS VIDEO GALLERY plugin for WordPress is vulnerable to authorization bypass due to a missing capability check… wordfence
0297d524-e016-4f8d-920c-d58c62edb2a0
< 2.2.1
MEDIUM 6.5 The GenerateBlocks plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc… wordfence
01eef49c-79c1-40a0-9b4b-05a699d47a41
< 1.9.5
MEDIUM 6.5 A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to p… wordfence
01ba179f-f515-4928-a96b-5ecb45b95811
< 1.6.3
MEDIUM 6.5 The Store Locator WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.2 … wordfence
01a8221c-355d-453d-87a5-7a9b388b268b
< 3.6.3
MEDIUM 6.5 The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to SQL Injection in versions up to, and including,… wordfence
0148c70f-38e4-43d9-994e-f2b01dd168a1
< 1.9.9
MEDIUM 6.5 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in al… wordfence
01465fd0-defe-4754-a4a1-10073fcd1902
< 4.5.1
MEDIUM 6.5 The Groundhogg β€” CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to SQL Injection in ver… wordfence
← Prev 479 480 481 482 483 484 485 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top