πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 111 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fe25bfef-34f0-4d57-9cba-9dcbf58281c6
< 4.0
HIGH 8.8 The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i… wordfence
fe1f8c51-d3f1-456b-bf73-362ff33ee879
< 3.6.8
HIGH 8.8 The wp-timelines plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.7.… wordfence
fe0fedc1-d4bd-40bf-8d8f-953db4bf2120
< 3.14
HIGH 8.8 The WP RSS Multi Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 3.14. This … wordfence
fe02377a-8d09-4d86-a049-3002516cf933
< 2.1.0
HIGH 8.8 The YITH WooCommerce Compare plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including… wordfence
fe00b89f-b475-4aec-8df8-89d842d92e4f
< 26.6
HIGH 8.8 The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via des… wordfence
fdeaf745-9a1b-4377-b9de-0d03e709a21b
< 1.1.1
HIGH 8.8 The WPMozo Addons Lite for Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and i… wordfence
fdc18341-135b-4522-a9db-510e4c4d9704
< 1.8.6
HIGH 8.8 The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
fdba439d-90ee-413c-842d-19704b08c33e
< 3.4.27.1
HIGH 8.8 The Ninja Forms plugin before 3.4.27.1 for WordPress allows CSRF via services integration. This makes it possible for at… wordfence
fdacd8b2-ef34-424d-bc05-bc059f6ab3b0
< 7.1
HIGH 8.8 The WP Yelp Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up to, and … wordfence
fda10117-b562-496e-8a17-88ee350ce8f2
< 4.1.12
HIGH 8.8 The "Popup Builder – Create highly converting, mobile friendly marketing popups." plugin for WordPress is vulnerable … wordfence
fd97ef7d-80c7-4987-be79-23eb380fa460
< 7.1.0
HIGH 8.8 The CAPTCHA 4WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.0.6… wordfence
fd56e59b-3879-4ab6-ae9a-7a301ee6aa20
< 2.3.12
HIGH 8.8 The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati… wordfence
fd216743-ce8d-4632-9fd1-d63502c2dfcd
< 2.1.42
HIGH 8.8 The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_… wordfence
fd15f5c3-f4c3-40d3-b0ae-eee7ed9ed434
< 1.0.9
HIGH 8.8 The Spider Facebook plugin for WordPress is vulnerable to generic SQL Injection via the β€˜id’ parameter in versions u… wordfence
fd154b26-985b-4e72-976f-1858a783c667
< 4.5.1
HIGH 8.8 Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.5.0 allows a remote attack… wordfence
fce15e1c-e2eb-4bd9-8b07-78d87a6ae1cc
< 4.9.3.3
HIGH 8.8 The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in versions up … wordfence
fcdeba37-ba65-400d-9c07-36503a03e857
< 4.70
HIGH 8.8 The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via the sp_cdm_display_project_sh… wordfence
fca9bd3a-2489-4672-95c1-9e00d60d6525
< 1.2.1
HIGH 8.8 The Availability Calendar WordPress plugin before 1.2.1 does not escape the category attribute from its shortcode before… wordfence
fca3d106-49df-49fc-a90d-e0cb26bd34b6
< 1.5.3
HIGH 8.8 The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object In… wordfence
fca3259b-bf0e-4b4a-815f-1eb399b8b674
< 3.5.26
HIGH 8.8 The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 … wordfence
fc64c550-0d19-42d4-aa2b-829e74b166bc
< 2.5.3
HIGH 8.8 The WP Coder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.2. T… wordfence
fc2a0723-52cf-4b46-ab1c-52275537c1b5
< 7.9.0
HIGH 8.8 The SUMO Memberships for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to, a… wordfence
fbf85cbc-88fa-4430-b005-a1f1e141241b
< 5.5.0
HIGH 8.8 The Icegram Express plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.4.19 due to… wordfence
fbedf0da-699e-429d-9ec7-6803f3c77a84 HIGH 8.8 The options.php file of the WP-Board WordPress plugin through 1.1(Beta) accepts a postid parameter which is not sanitise… wordfence
fbe42214-0a01-4b9c-8149-68c47082d9d9
< 1.5.2
HIGH 8.8 Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP co… wordfence
← Prev 108 109 110 111 112 113 114 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top