ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 112 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
fbda7670-179a-41ed-8ec9-ae7f5102e645 HIGH 8.8 The ToolBar to Share plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
fbb601ce-a884-4894-af13-dab14885c7eb
< 5.1.1
HIGH 8.8 The UserPro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.0. Th… wordfence
fb900810-23a2-4920-a5e8-4388c4474de0
< 2.6.04
HIGH 8.8 The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including… wordfence
fb61159a-e501-4c55-a384-b6049e0f0bc8
< 2.2.8
HIGH 8.8 The Frontend Dashboard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on t… wordfence
fb4dc258-a1b2-4e7c-8bba-1b3162b8954b HIGH 8.8 The Social Link Groups plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.0 due t… wordfence
fb4b6d33-82cd-4c41-ba54-dbc7fe5f6ac6
< 10.4.5
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to h… wordfence
fb310bdb-fc74-47b2-9371-3d10abd287fb
< 1.7
HIGH 8.8 The Animation Addons for Elementor Pro plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation … wordfence
fafd0159-25ab-430d-88ef-c4d09d23baa7
< 3.2.5
HIGH 8.8 The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil… wordfence
faf3fb76-847f-447f-b6c6-49bd0d30d3c7
< 1.5.1
HIGH 8.8 SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrar… wordfence
faf020d0-62a2-41cc-ad3b-da3b56ed0d97 HIGH 8.8 The Apa Banner Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
fae1b795-8939-4229-8f89-fedf6f320ec1
< 5.1.1
HIGH 8.8 The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
fac81cc0-c6c9-4009-aacb-52adc70c0261
< 1.0.5
HIGH 8.8 The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the han… wordfence
fac308c6-780d-44ea-ba78-d15e1ee260e4
< 1.2.4
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the IP Ban (simple-ip-ban) plugin 1.2.3 for WordPress allo… wordfence
fab0a42e-fa99-4451-91fd-c924a33d33c8
< 2.2.7
HIGH 8.8 The Booking and Rental Manager for Bike | Car | Resort | Appointment | Dress | Equipment plugin for WordPress is vulnera… wordfence
faac24e5-94f2-40e5-932e-93ddc2c8af7c
< 7.5.15
HIGH 8.8 The WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to Cross… wordfence
fa9450a4-2b96-45e4-b2dc-9a4b26449d19
< 1.3.12
HIGH 8.8 The Contact Form Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
fa86bcb9-e558-4b60-9473-65cd6f9663fd HIGH 8.8 The Embedder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalati… wordfence
fa7ca972-ddb0-416b-8c5a-b4e9648ca957
< 6.0.0
HIGH 8.8 The Booster for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
fa586468-d6ff-46a3-97f3-e2e1d365e5b1
< 2.9.0
HIGH 8.8 The Contact Form Generator plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up t… wordfence
fa53c5ee-fe7f-4fb2-baaa-2c1a151d4b2c HIGH 8.8 The WP Enable WebP plugin for WordPress is vulnerable to arbitrary file uploads due to improper file type validation in … wordfence
fa52ecbf-9c8d-4103-acce-255f36c57d0b HIGH 8.8 The Institutions Directory plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includi… wordfence
fa1d953f-6a5c-46af-a1a5-2c4f90da679a
< 3.0.3
HIGH 8.8 The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the … wordfence
fa0881ab-d731-4e57-8323-c49b9306bf50
< 2.0.40
HIGH 8.8 A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress a… wordfence
f9fe858e-5c89-4cc2-8b66-5c86965f7889 HIGH 8.8 The Travel Light for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0. This i… wordfence
f9d70f5c-e05f-47c9-994c-0e1da5b2fe01
< 1.3
HIGH 8.8 The WP Super Cache plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.2. Th… wordfence
← Prev 109 110 111 112 113 114 115 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top