πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

41,761
Total CVEs
67
CISA KEV (Actively Exploited)
Sep 27, 2026
Last Updated

41,761 vulnerabilities found (page 104 of 1671)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
655e6486-e35f-4e7b-b894-55606d3eba56
< 1.5
CRITICAL 9.6 The WP Fast Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4… — wordfence
63b67652-d10e-4a5a-97d5-04e6c848b752
< 1.7.2
CRITICAL 9.6 The Jetpack Scan team identified a Reflected Cross-Site Scripting in the Login Form of the Patreon WordPress plugin befo… — wordfence
5b3f4ccb-fcc6-42ec-8e9e-03d69ae7acf2
< 4.9.1
CRITICAL 9.6 The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as … — wordfence
585d0368-7557-46aa-9ea3-26cd6d7df51b
< 4.57
CRITICAL 9.6 The SP Project & Document Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… — wordfence
5717b835-7feb-4bb8-8f1b-1f44d4630cd3
< 3.4.5
CRITICAL 9.6 The Ali2Woo Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.… — wordfence
2fd58397-7598-4d98-a6b3-c5837cb3b73e
< 1.5.7
CRITICAL 9.6 The Armour Honeypot Anti Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce vali… — wordfence
2be6c7d8-6dd4-4701-9baa-694496e7388a CRITICAL 9.6 The RB Internal Links WordPress plugin through 2.0.16 does not have CSRF check in place when updating its settings, whic… — wordfence
2b897790-43f7-4ca4-8abe-9dc736a7c011 CRITICAL 9.6 The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which coul… — wordfence
25199281-5286-4d75-8d27-26ce215e0993
< 4.9.1
CRITICAL 9.6 The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9… — wordfence
24d08127-67b6-434a-8dbe-233a47854f9b CRITICAL 9.6 The Add Post URL WordPress plugin through 2.1.0 does not have CSRF check in place when updating its settings, which coul… — wordfence
22b539c8-a6f1-4543-9e63-08ee4d468ee0
< 1.0.5
CRITICAL 9.6 The Google Authenticator WordPress plugin before 1.0.5 does not have CSRF check when saving its settings, and does not s… — wordfence
19b4a27d-d9de-4567-86cd-8ec821ee299a
< 2.5
CRITICAL 9.6 Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote atta… — wordfence
0a9b4c03-e7ec-48d6-87fe-67e8a5780703
< 2.2.0
CRITICAL 9.6 The a3 Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… — wordfence
618f644b-a92c-4f7f-aaea-c03ee7d6e0f9
< 2.0.46
CRITICAL 9.4 The Ultimate Member – User Profile, User Registration, Login & Membership Plugin plugin for WordPress is vulnerable to… — wordfence
f6f91414-5035-4cab-81ad-18558fe43500
< 2.2.3
CRITICAL 9.3 The Better Search plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and in… — wordfence
ca38c423-2df8-4f20-bd95-2ecd84167a7f
< 4.0.1
CRITICAL 9.3 The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password… — wordfence
9729ebf5-ef78-4ef4-81d4-165f422c3847
< 7.3.15.727
CRITICAL 9.3 The FV Flowplayer Video Player plugin for WordPress is vulnerable to SQL injection in versions up to, and including, 7.3… — wordfence
54a425b0-592a-433d-b9e7-776760536668
< 3.3.1
CRITICAL 9.3 A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d… — wordfence
23d762e9-d43f-4520-a6f1-c920417a2436
< 2.8.9
CRITICAL 9.3 The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (… — wordfence
224a2d6d-7fdc-43a8-a8c9-26213b604433 CRITICAL 9.3 The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in a… — wordfence
fdd1359f-ce16-4cfe-a6a8-245a21ad16c9
< 18.5
CRITICAL 9.1 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … — wordfence
fb85aacf-a8cf-4054-97fd-b285fcc2a7f9 CRITICAL 9.1 The WP Pipes plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a… — wordfence
faed1198-b8c4-46b1-b6a6-5fc35cd7bdf8
< 2.0.22
CRITICAL 9.1 The Formidable Form Builder plugin for WordPress is vulnerable to authorization bypass in versions up to, and including,… — wordfence
fa8f0688-8c54-43f8-acea-2aec2fcfbdce
< 3.7.43
CRITICAL 9.1 The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Arbitrar… — wordfence
f9de8e90-5bda-4ab1-aa78-2748cd717376
< 2.2.4
CRITICAL 9.1 The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… — wordfence
← Prev 101 102 103 104 105 106 107 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top