🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 119 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ececa0ea-3d44-4b1b-b962-809a8b24c890
< 4.7.9
HIGH 8.8 The Quiz And Survey Master plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
ecdfb19e-ef3a-4c5a-96a5-4c9ce3dca3a6 HIGH 8.8 The MyCSS WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow a… wordfence
ec83bf1f-a2da-4ecf-8d82-9a555c751073
< 1.8.3
HIGH 8.8 The tutor_answering_quiz_question/get_answer_by_id function pair from the Tutor LMS – eLearning and online course solu… wordfence
ec7b77d8-490e-4eaf-a9df-54de63f128d4 HIGH 8.8 The E Unlocked - Student Result plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and … wordfence
ec6331e1-7a7c-486d-873b-02b3af38387c
< 2.4.1
HIGH 8.8 The wp-d3 plugin before 2.4.1 for WordPress has CSRF. wordfence
ec5fa360-6fff-46f5-8221-4b28a6db3e73
< 1.1.1
HIGH 8.8 The JSON REST API plugin for WordPress is possibly vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
ec281e0d-0217-4cdd-af31-71158bb3a25d
< 2.1
HIGH 8.8 The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plug… wordfence
ec20d5c4-4c41-4ec9-8d0a-ec8f03634f7d
< 4.2.6.6
HIGH 8.8 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… wordfence
ec162cdc-d4cd-47d9-b941-24bfee6c48fd
< 3.2.29
HIGH 8.8 The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all … wordfence
ebd6acc9-b7df-4cf8-a211-1e39f3abcf79
< 1.2.0
HIGH 8.8 The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and… wordfence
ebc0c8e6-a365-4ef7-9c1a-41454855096c
< 1.5.105
HIGH 8.8 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based … wordfence
eb89a16c-fae0-4d36-85aa-79beab753cba
< 1.9.9.41
HIGH 8.8 The BP Better Messages WordPress plugin before 1.9.9.41 does not check for CSRF in multiple of its AJAX actions: bp_bett… wordfence
eb85faa4-0261-4fb0-a70d-9fb03170e032 HIGH 8.8 The QRMenu Restaurant QR Menu Lite plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and inc… wordfence
eb85ed32-c391-45d2-9e86-cb97009210cd HIGH 8.8 The Integração entre Eduzz e Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due t… wordfence
eb6ac547-59fd-4d51-a140-06f7f70a43ab
< 4.5
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows r… wordfence
eb3aa518-ef12-4168-a524-ad36397f67cb
< 1.2.3
HIGH 8.8 The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id… wordfence
eb32a095-7d2b-4a57-9d91-f79fb3486f9a
< 1.0.1
HIGH 8.8 The Copy or Move Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in… wordfence
eb23c4d7-d9be-4162-bb7b-8a74f3c339eb
< 2.2.36
HIGH 8.8 The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using … wordfence
eb06c43c-bf8c-412b-8b1d-fee004d728d2
< 0.0.8
HIGH 8.8 The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrar… wordfence
eb022e51-32fd-403e-a9b3-34114e957020
< 4.6.16
HIGH 8.8 The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to arbitrary file uploads due to mi… wordfence
eade6ab0-ff79-4107-83ce-e85b37d97442
< 5.25.10
HIGH 8.8 The EZ SQL Reports Shortcode Widget and DB Backup plugin for WordPress is vulnerable to Cross-Site Request Forgery in ve… wordfence
eac9d9b5-6812-4fe2-9427-500d4bb2ea09 HIGH 8.8 The WP Opt-in plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.1. … wordfence
ea99795f-45fa-4d4c-a6bd-2197b58efcb2
< 3.0
HIGH 8.8 The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
ea6c7b63-00da-4476-a024-97fe99af643d
< 0.1.0.84
HIGH 8.8 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Cross-Site Request Forgery … wordfence
ea615395-2c63-415d-b0bf-6bd2489ad540
< 1.0.1
HIGH 8.8 The RealHomes CRM plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
← Prev 116 117 118 119 120 121 122 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top