🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 114 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f813f1f3-4494-4899-93d1-fa6f786e94cd HIGH 8.8 The APA Register Newsletter Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and… wordfence
f7ed6255-d8df-4f57-961b-1a0c21e352ac
< 1.3
HIGH 8.8 The WP-Orphanage Extended plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… wordfence
f7d5a077-8836-4c28-8884-5047585a99e5
< 1.5.5
HIGH 8.8 The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all … wordfence
f7b24b7c-1a15-4b38-b59e-bcad39cc4340
< 2.0.10
HIGH 8.8 The PropertyHive plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.9 … wordfence
f7b24a89-816d-4021-b8de-d1ca14ce3cb9
< 1.1.0
HIGH 8.8 The WP Multiple Meta Box plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter in version… wordfence
f7ad9f8c-9b76-4b3e-987c-ed99beeb2937 HIGH 8.8 The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJA… wordfence
f7acbb6f-99e0-483a-95ed-c60905dcbd50
< 1.4.5
HIGH 8.8 The WishSuite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.4.4. This m… wordfence
f796b282-0012-4d86-914d-72c7707dce42
< 1.3.1
HIGH 8.8 The bbPress Members Only plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
f795a46c-ba0c-45d5-9ff7-638752f1681b
< 3.4.7
HIGH 8.8 The User Meta Manager plugin for WordPress is vulnerable to blind SQL Injection via the ‘umm_user’ parameter in vers… wordfence
f77cc1ed-d30e-4651-af23-29d34d76dc92 HIGH 8.8 The Occasions plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. Th… wordfence
f7686b11-97a8-4f09-bbfa-d77120cc35b7
< 3.4
HIGH 8.8 The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versi… wordfence
f75936d7-12bc-47cc-b901-17fd42c05d66
< 1.2.0
HIGH 8.8 The Login rebuilder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.2.0. This is du… wordfence
f753b536-6ccd-4f79-83da-48cabb15b72a
< 2.5.0
HIGH 8.8 The Twitter Cards Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
f745652d-12d6-46cd-8599-0a42696cb45a
< 2.8.6
HIGH 8.8 The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an … wordfence
f727d82e-8295-4440-90fa-dc41b1d02f8f HIGH 8.8 The MyTweetLinks plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.1 due to insu… wordfence
f71fc65f-cdc1-4f20-b37e-849ade49ee41
< 7.3.21
HIGH 8.8 The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is vulnerable to Privilege Escalation in… wordfence
f70ec123-fff3-4f03-a424-37e0e579b765
< 3.0.9
HIGH 8.8 The Customer Reviews Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
f70a2a58-d9b8-456d-ae4f-9c60b3d6b8a5
< 1.0.4
HIGH 8.8 The plugins 'Integration for Billingo & Gravity Forms' up to version 1.0.3, 'Integration for Szamlazz.hu & Gravity Form… wordfence
f6f0fb78-ad6b-4a9e-ae1a-5793f3426379
< 1.4
HIGH 8.8 Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that … wordfence
f6c94024-20fb-4cc1-a093-1b9974e61220 HIGH 8.8 The Address Autocomplete plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
f690e67c-119f-4ea6-9505-101e7f7a3dea
< 2.9.5
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation … wordfence
f67ce101-3b4f-45be-9aed-d9055cc09fd3
< 1.9.9.149
HIGH 8.8 The Better Messages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
f66457a1-7406-46f9-9a14-4ce6d77c4b84
< 2.2.9
HIGH 8.8 The WP Job Portal plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.2.8. Th… wordfence
f65fdde9-1133-4e29-a70a-be977f96acce
< 1.1.13
HIGH 8.8 The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to privilege escalation in… wordfence
f648e7f3-d93a-4a46-ae77-81a94880869c HIGH 8.8 The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in … wordfence
← Prev 111 112 113 114 115 116 117 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top