πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 118 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
eec21717-dffa-40c0-90c0-007b568609cc HIGH 8.8 The SEO Wizard for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.2. This i… wordfence
eeb2c829-579f-41e2-ad5f-8e4fc125d980
< 17.8
HIGH 8.8 The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient … wordfence
ee4c5d34-74cb-443b-9323-90580dbe675e
< 1.32.31
HIGH 8.8 The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up t… wordfence
ee4b1dac-6ec6-4c1c-9103-60e53d980b95
< 1.1.2
HIGH 8.8 The Hive Support | AI-Powered Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin for WordPress is vulnerable… wordfence
ee2b4055-8cbd-49b7-bb0b-eddef85060fc
< 2.8
HIGH 8.8 The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and in… wordfence
ee23629c-6147-4527-929f-8c932cd7d7a7
< 1.2.3.6
HIGH 8.8 The Filr – Secure document library plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ty… wordfence
ee20726a-b5a8-4778-b5b4-5ea232ca4fc8
< 1.5.6
HIGH 8.8 The get_results() and get_items() functions in the Survey Maker WordPress plugin before 1.5.6 did not use whitelist or v… wordfence
ee1624fd-d98b-4953-99dc-a952dda48aa1 HIGH 8.8 The External image replace plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
ee0c0e29-b117-4480-b5b7-995878af8c57
< 1.4.25
HIGH 8.8 The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vul… wordfence
ee03ca88-97c1-45b0-a9d9-1ed57e124f13 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress… wordfence
edf4b588-8b67-425a-b0e1-d4382cb88dd1
< 1.6.4
HIGH 8.8 The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion du… wordfence
edd7f442-32a1-4ce9-bf47-96f313a8d5df
< 2.18.10
HIGH 8.8 The Wicked Folders WordPress plugin before 2.18.10 does not sanitise and escape the folder_id parameter before using it … wordfence
edd6239d-5525-4dad-8358-f328e3175105 HIGH 8.8 The Shopready plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.5. This mak… wordfence
edcc23e0-075a-47e6-979d-7e75eed4337d
< 4.2.22
HIGH 8.8 The Ultimate Product Catalog plugin for WordPress is vulnerable to authorization bypass and Cross-Site Request Forgery i… wordfence
edacede9-8a31-4d7f-b075-8265e3bbe2d0
< 2.3.4
HIGH 8.8 The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use… wordfence
ed6e0136-f4fa-4739-b02d-b53091991e58
< 3.2.34
HIGH 8.8 The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using … wordfence
ed61a6b5-5c54-408b-973c-69b0f12d2df5
< 2.1.1
HIGH 8.8 The Gwolle Guestbook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
ed5251e7-64d2-4210-9864-144952a49327
< 7.3.6
HIGH 8.8 The themify-ultra theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in dur… wordfence
ed4e1a56-708d-4a12-8153-9568d11fe4d0
< 5.1.8
HIGH 8.8 The Seamless Donations WordPress plugin before 5.1.8 does not have CSRF check in place when updating its settings, which… wordfence
ed488dcd-7400-47ab-a161-47c7caa414c2
< 5.3
HIGH 8.8 The Jquery Validation For Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
ed40b874-68e2-49f3-95b0-653600394e78
< 3.1.19
HIGH 8.8 The WordPress Download Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
ed2796b0-0667-451d-9208-272651bc6a4c HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Codestyling Localization plugin 1.99.30 and earlier fo… wordfence
ed1f3d5a-9551-421e-8f38-416976a704ba
< 1.0.2
HIGH 8.8 The Polls CP plugin for WordPress is vulnerable to SQL Injection via the 'lu' parameter in all versions up to, and inclu… wordfence
ed117fb8-c13a-4088-aa33-8d44fc5dcf37
< 5.6.2
HIGH 8.8 The miniOrange's Google Authenticator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
ecf36533-1dd1-43d7-b12e-7b425c13530a
< 4.0.0
HIGH 8.8 Cross-site request forgery (CSRF) vulnerabilities exist in the Auth0 plugin before 4.0.0 for WordPress via the domain fi… wordfence
← Prev 115 116 117 118 119 120 121 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top