πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 110 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b8613acf-d6e8-434f-820b-d854ed1f6299
< 1.3.5
CRITICAL 9.0 The Export any WordPress data to XML/CSV WordPress plugin before 1.3.5 does not sanitize the cpt POST parameter when exp… wordfence
9d0c144b-609b-4b4a-bfb2-de38b5969a9e
< 4.6
CRITICAL 9.0 The BP Profile Search plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.3… wordfence
79e2011c-5e4d-4d02-831f-6b4dcfcaa51e
< 18.3
CRITICAL 9.0 The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up… wordfence
6b2e210b-e5e3-46f1-b730-64d970160a5e
< 3.8.8
CRITICAL 9.0 SQL injection vulnerability in the All In One WP Security & Firewall plugin before 3.8.8 for WordPress allows remote att… wordfence
5412fd87-49bc-445c-8d16-443e38933d1e
< 1.2.0
CRITICAL 9.0 The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1… wordfence
50e4e070-8f68-4bac-8011-ac9d3b99a24f
< 7.9
CRITICAL 9.0 The SEOPress – On-site SEO plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu… wordfence
4deb128d-0163-4a8e-9591-87352f74c3ef
< 2.13.10
CRITICAL 9.0 The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil… wordfence
4b159d4f-494e-4ab4-8ed7-3421b437597e CRITICAL 9.0 The ToTop Link WordPress plugin through 1.7.1 passes base64 encoded user input to the unserialize() PHP function, which … wordfence
12ea26be-93e4-43de-bb32-21cdc2f80569
< 3.9.5
CRITICAL 9.0 The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputti… wordfence
fff8dfbc-fd59-47db-85bb-de2a7c6a9a5f
< 1.3.5.3
HIGH 8.8 The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the '… wordfence
ffd6e18d-9173-4911-af64-5d54c6d2e052
< 2.9.0
HIGH 8.8 The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing cap… wordfence
ffd438ea-ddc2-4d97-b187-4cd54b6f638d
< 8.6.13
HIGH 8.8 The MapSVG plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and excluding, 8.6.13. This… wordfence
ffcc85a1-fc79-4bc6-b50e-c87988d4cad3 HIGH 8.8 The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function foun… wordfence
ffac779c-c17f-46bd-9276-a1ce2db4e95c
< 2.4.0
HIGH 8.8 The WooCommerce One Page Checkout plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… wordfence
ff9364a9-18f8-47d3-b992-e39c8d99d6ea
< 2.0.9
HIGH 8.8 The Demo Importer Plus plugin for WordPress is vulnerable to unauthorized modification of data, loss of data, and privil… wordfence
ff65e2cc-2052-45b6-bb42-58b8ce73adee HIGH 8.8 The Hospital Doctor Directory plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl… wordfence
ff29e160-993b-422c-b49b-a216db5a0765
< 1.6.0
HIGH 8.8 The CM Pop-Up banners plugin for WordPress is vulnerable to generic SQL Injection via the getStatistics function in vers… wordfence
ff21e539-8ba0-4edd-a90c-27a4cd1cdbc7
< 2.9.9
HIGH 8.8 The Translate WordPress with GTranslate <= 2.9.8 & Translate WordPress – Google Language Translator <= 6.0.13 WordPr… wordfence
ff09292b-c8a6-4cd8-a8dd-d79b4c713d6f HIGH 8.8 The WP donimedia carousel plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
fef6c603-2beb-44df-8895-10ad0a9ef644 HIGH 8.8 Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter. wordfence
feecd1f9-a933-43f5-971b-459bb27340d4
< 0.2.18
HIGH 8.8 The AnyComment WordPress plugin before 0.2.18 does not have CSRF checks in the Import and Revert HyperComments features,… wordfence
fee18df2-75ea-416a-8aa6-139018016b9a
< 1.1.4
HIGH 8.8 The Bulk Page Creator WordPress plugin before 1.1.4 does not protect its page creation functionalities with nonce checks… wordfence
fea96f84-f75b-4f02-9ca8-f8fda439d565
< 3.1.1
HIGH 8.8 The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… wordfence
fe99d636-bb71-431e-88d6-130767341c83 HIGH 8.8 The INK Official plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… wordfence
fe8b6a16-0a39-42fd-bb0f-9114ec08a885 HIGH 8.8 The Axle Demo Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
← Prev 107 108 109 110 111 112 113 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top