πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 116 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f33a13dc-ebff-4033-9b8d-10076b1c2d0d HIGH 8.8 The Mmm Simple File List plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 2.3… wordfence
f30f5251-54ba-4a8c-b849-2a4ea11637a1
< 4.3.2
HIGH 8.8 The ReachShip WooCommerce Multi-Carrier & Conditional Shipping plugin for WordPress is vulnerable to arbitrary file uplo… wordfence
f2ef8ee4-7388-4263-ad6a-bb043b09c97c
< 2.7.5
HIGH 8.8 The Elementor Website Builder plugin for WordPress is vulnerable to arbitrary file upload by subscriber level users and … wordfence
f2e981ae-4958-45c5-9f5f-6298223fac46
< 1.0.4
HIGH 8.8 The Togo – Travel & Tour Booking WordPress Theme theme for WordPress is vulnerable to Privilege Escalation in all vers… wordfence
f2c88c5a-ea87-4aab-a0ce-8246e5cb540a
< 7.3.7
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attack… wordfence
f29b905c-57cf-4fb8-b6af-eb0c367cd3e4
< 5.17.8
HIGH 8.8 The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and includin… wordfence
f28826e7-913e-4a88-a48a-3b8dd5623d39
< 1.9.7
HIGH 8.8 The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_a… wordfence
f2862cee-0412-42ba-9a8e-e5722bece775
< 3.6.4
HIGH 8.8 The Redirection plugin suffers from a critical Cross-Site Request Forgery vulnerability that allows remote attackers to … wordfence
f270c73f-ccdb-4575-ab9b-014c65873607
< 2.5.18
HIGH 8.8 The Slideshow SE plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.17… wordfence
f25a5b1a-9a33-4e61-8a32-ecebfa64e4bb
< 2.3.12
HIGH 8.8 The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,… wordfence
f24f0673-b5c8-4086-8795-692228a413af HIGH 8.8 The WordPress Awesome Import & Export Plugin - Import & Export WordPress Data plugin for WordPress is vulnerable arbitra… wordfence
f248b116-b4b7-43ba-8fbf-3de86935582d
< 5.3.0
HIGH 8.8 The EduAdmin Booking plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.2.0.… wordfence
f234f05f-e377-4e89-81e1-f47ff44eebc5
< 1.3.11
HIGH 8.8 The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute … wordfence
f21f757b-43f8-4371-886c-b9f7fd79c715
< 2.3
HIGH 8.8 WordPress Pricing Table Plugin Plugin 2.2 has a Cross-Site Request Forgery vulnerability via in the core/views/arprice_i… wordfence
f21cbe18-77e1-4a9a-96a0-74edaef0db3e
< 2.0.7
HIGH 8.8 The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via des… wordfence
f215e320-8563-4d25-9963-ed3664b4901d
< 2.4.17
HIGH 8.8 The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 2.4… wordfence
f208ca5a-a404-4664-80f5-643e713f600a
< 1.1.0
HIGH 8.8 The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in … wordfence
f1de4899-532a-4558-bff0-f4610bfdd49d HIGH 8.8 The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalatio… wordfence
f1cbe675-4c0f-430a-b2db-85ba8605d172 HIGH 8.8 The Deeper Comments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability … wordfence
f1c2cb3f-2f9e-40c5-9e5f-5b85a53e5868
< 1.33.25
HIGH 8.8 The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to arbitrary file creation due to a mis… wordfence
f1add368-81d2-455f-a95a-c13566c58d39 HIGH 8.8 The Web Invoice plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.1.3 due to insuf… wordfence
f1a75a95-e61e-4786-b882-8ca186843d57 HIGH 8.8 The Genemy - Creative Minimal Landing Page Builder for Digital Startup Design Studio Agency in Marketing theme for WordP… wordfence
f18be13a-1b16-40f8-85a7-bd77b49e243c
< 2.2.6
HIGH 8.8 The Otter - Gutenberg Blocks plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fallback'… wordfence
f15415aa-b820-4697-8360-b526312c89d3
< 10.12.0.3
HIGH 8.8 The ICS Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 10.12.0.2. T… wordfence
f107496b-020b-4222-91f3-49caba1a39db
< 1.3.8
HIGH 8.8 The Advanced Import plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
← Prev 113 114 115 116 117 118 119 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top