πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 115 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f5ff0ff4-0878-4e9e-8082-e0f6effef92c
< 3.31.0
HIGH 8.8 The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up … wordfence
f5f19184-60ff-4cf9-85c3-86a6c84a2a63
< 2.0.4
HIGH 8.8 The import_data function of the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4 had no capability or n… wordfence
f5f18cae-b7f8-4afd-adfa-c616c63f9419
< 2.2.91
HIGH 8.8 The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to … wordfence
f5e984d5-2537-4a4a-a071-084e0c1c3b5e
< 26.6
HIGH 8.8 The Betheme theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 26.5.1.4 via des… wordfence
f5e4a172-38de-49d3-8a5d-62253cf6d67c
< 5.7.3
HIGH 8.8 The WP Media folder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation fun… wordfence
f5cdd3c1-6353-4bee-a4f9-5b7972f0970c
< 3.1.0
HIGH 8.8 The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… wordfence
f5c449f1-4715-4033-b0a3-6a8ca968aabc
< 1.3.1
HIGH 8.8 The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This mak… wordfence
f5bcad01-02ca-46a0-9196-df9f2110bc8a
< 1.0.2
HIGH 8.8 The 404Like plugin for WordPress is vulnerable to SQL Injection via the searchWord parameter in all versions up to, and … wordfence
f59004bb-b026-4137-a332-f46a09237e7b
< 2.9.5
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
f582eb1d-fcd0-4758-9922-969f8eb6efea
< 2.0.11
HIGH 8.8 SQL injection vulnerability in options.php in WordPress 2.2.1 allows remote authenticated administrators to execute arbi… wordfence
f52d5c44-4a5e-4a45-b622-66aa4e509fd8
< 1.2.6
HIGH 8.8 The Knews Multilingual Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, a… wordfence
f52c1e84-3421-42f6-b8cd-db814c77f9f6
< 2.3.7
HIGH 8.8 The JetReviews plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.3.6. This … wordfence
f52aede5-21c3-46b9-800e-860a677a4b90
< 2.9.46
HIGH 8.8 The WordPress Download Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
f4e12192-d24b-48b7-8533-714e9be78f0b
< 3.0.5
HIGH 8.8 The WPC Smart Upsell Funnel for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that… wordfence
f4c8932b-ede8-4f17-9612-5493c1130170
< 3.10.1
HIGH 8.8 The Profile Builder Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
f4b45791-4b85-4a2d-8019-1d438bd694cb
< 8.3.8
HIGH 8.8 The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation an… wordfence
f49408da-79d5-4653-b4c2-a9247f597380
< 1.2.2
HIGH 8.8 The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF. wordfence
f3f821d6-6a4e-4e3b-98e1-e38a34d5c8f9
< 5.2
HIGH 8.8 The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action discy_reset_options, allowing an … wordfence
f3f01b88-6f93-4ee8-8d59-9165ebcd4dd1 HIGH 8.8 The Social Streams plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.… wordfence
f3c9c798-8545-475e-879b-7e44dac493f0
< 3.2.51
HIGH 8.8 The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.… wordfence
f3c8b3fa-dc27-4c00-844f-e95cac028247
< 5.11.2
HIGH 8.8 The Business Directory Plugin – Easy Listing Directories for WordPress WordPress plugin before 5.11.2 suffered from a … wordfence
f3855e84-b97e-4729-8a48-55f2a2444e2c HIGH 8.8 The Absolute Privacy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
f3664a96-4ce7-4561-9b4b-dff91cd49384
< 4.0.6
HIGH 8.8 The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and… wordfence
f357fe2a-aa24-42cd-ac2c-c948e18a4710
< 6.8.7
HIGH 8.8 The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for Word… wordfence
f33d77b7-5412-47bf-9bed-8617151723c9
< 1.5.110
HIGH 8.8 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL I… wordfence
← Prev 112 113 114 115 116 117 118 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top