πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 117 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f0b60313-042b-4e85-a117-9abd95824402
< 1.1.7
HIGH 8.8 The Deny All Firewall plugin before 1.1.7 for WordPress allows wp-admin/options-general.php?page=daf_settings&daf_remove… wordfence
f098d66f-43a6-44e9-b836-2994d2c97782
< 2.0
HIGH 8.8 lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via sh… wordfence
f082ff4a-2adb-461e-875a-b3701cfea074
< 1.8.1
HIGH 8.8 Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, … wordfence
f068abb4-cbe6-4698-b547-78503b2a455e
< 5.9.1
HIGH 8.8 The AdRotate Banner Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
f0644fc5-6b37-4730-a051-f36dec650649
< 1.0.33
HIGH 8.8 Multiple SQL injection vulnerabilities in the Mingle Forum plugin 1.0.32.1 and other versions before 1.0.33 for WordPres… wordfence
f02945e0-6214-46c4-ada8-49e8161d2ce4
< 2.16.1
HIGH 8.8 The Seriously Simple Podcasting plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
f00a12ed-d8c2-40b2-b0c8-71507469ee95
< 1.2.3
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote… wordfence
efff81ea-b88e-4f51-b8db-1f8255e7736a
< 4.2
HIGH 8.8 The ARPrice plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.1.3 via deser… wordfence
effd72d2-876d-4f8d-b1e4-5ab38eab401b
< 1.8.2
HIGH 8.8 The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aj… wordfence
efe9ca48-b6df-4a2d-8713-d8b21f6c9701
< 0.1.5
HIGH 8.8 The Point Maker plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.1.4. This… wordfence
efe86e10-c7ac-456b-b324-7e028562ff9f
< 1.24
HIGH 8.8 The Ona theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions … wordfence
efc7ad9f-714e-474c-87e8-ecbbdfabd550
< 4.2.2
HIGH 8.8 The WPFront User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and… wordfence
efc2a21d-b6f9-405d-a9a0-779a736e5d94
< 2.1.1
HIGH 8.8 admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPre… wordfence
efb48ce2-23e6-4c48-a35b-1c42e5fb0aa5 HIGH 8.8 The Advanced What should we write next about plugin for WordPress is vulnerable to SQL Injection in versions up to, and … wordfence
ef998d5e-e03b-4012-9576-d90dee3adec4
< 4.1.1
HIGH 8.8 The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code … wordfence
ef86b1f2-d5aa-4e83-a792-5fa35734b3d3
< 2.11.11
HIGH 8.8 The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
ef818472-d4ba-4ca9-b7ed-fe563107c3bd
< 5.5.2
HIGH 8.8 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to privilege es… wordfence
ef7f1209-c0e9-4958-aa92-fb2cb2a431e1 HIGH 8.8 The WP Options Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
ef7aff85-e1ca-47ce-86e9-a0fe356993a1
< 6.0.9.2
HIGH 8.8 The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forger… wordfence
ef7727e5-fb20-4d9b-baaa-c123a0100ee0
< 0.6.3
HIGH 8.8 The WP Code Highlight.js plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
ef46b08f-455a-4c61-81ac-10af19b16980 HIGH 8.8 The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… wordfence
ef45fa78-7005-483e-a708-5aab0f7ba07b
< 7.8.2
HIGH 8.8 The Avada theme for WordPress is vulnerable to Cross-Site Request forgery in versions up to, and including, 7.8.1 in cla… wordfence
ef4134a1-e2c6-495a-bc00-cc8cd783cd7a
< 1.5.59
HIGH 8.8 The users-ultra plugin before 1.5.59 for WordPress has uultra-form-cvs-form-conf arbitrary file upload. wordfence
ef1d1ae6-3019-4e48-911e-5f805f8089ca
< 5.7.0
HIGH 8.8 The RD Station plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.6.0. … wordfence
eee88bc6-b7e3-4eff-afc7-59b9a1cc9d2c
< 3.1.0
HIGH 8.8 The custom-sidebars plugin before 3.1.0 for WordPress has CSRF related to set location, import actions, and export actio… wordfence
← Prev 114 115 116 117 118 119 120 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top