πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 120 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ea4fd340-6e94-4032-9202-8ccfa7481223
< 4.1
HIGH 8.8 Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery… wordfence
ea4e9263-36f7-490c-9dad-d3b806bcfdf4
< 3.1
HIGH 8.8 The Visitor Traffic Real Time Statistics Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
ea4b35ef-99ae-4ef9-8618-f9993306521b
< 1.36.21
HIGH 8.8 The Ultimate Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and … wordfence
ea2d4716-2ae1-45ca-a4b2-4edb4a89d7b4 HIGH 8.8 The Specialist theme for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonc… wordfence
ea097cb7-85f4-4b6d-9f29-bc2636993f21
< 4.7.0
HIGH 8.8 The Fancy Product Designer plugin for WordPress is vulnerable to unauthorized modification of site options due to a miss… wordfence
e9fa55cc-c686-43e4-a028-dd2721d2db85
< 2.5.17
HIGH 8.8 The Most And Least Read Posts Widget plugin for WordPress is vulnerable to SQL Injection via the widget settings in all … wordfence
e9d58191-769c-4632-a086-4dbce9bfb6ad
< 3.0.9
HIGH 8.8 The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.0.8. T… wordfence
e9d545fc-fed0-428a-bad5-a0d7d09c04a7
< 2.2
HIGH 8.8 The AdminPad plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1. Thi… wordfence
e9a94b81-6430-4f04-ac16-4bf79318b5de
< 4.4.13
HIGH 8.8 The Simple File List plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e996f71a-f0b9-4e10-873e-a0299a099dce
< 2.9
HIGH 8.8 The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, … wordfence
e98594d4-5385-4ac1-80c6-005c25098549
< 2.0.1
HIGH 8.8 The nutrie theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versio… wordfence
e982ae88-cfd0-46b9-ad64-00e398d307d6
< 2.3
HIGH 8.8 The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to unauthoriz… wordfence
e96f31e0-4b2e-4ea1-a3e5-fd7452a2fea9
< 2.5.0
HIGH 8.8 The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation… wordfence
e96b3d21-edeb-4dec-b13c-3688d3996cb5 HIGH 8.8 The plugin Clean-Contact is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validati… wordfence
e9404fe4-855e-4eb4-81c4-5246f6e9be0c
< 1.12.18
HIGH 8.8 The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for … wordfence
e93ccf9d-cd8b-4399-8d2d-c844a23d66c8
< 3.5.8
HIGH 8.8 The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the pos… wordfence
e93632e3-7321-48ee-828a-c539e16f07b2
< 3.1
HIGH 8.8 There is a CSRF vulnerability in the File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path… wordfence
e92cc6a3-062c-4f0e-9539-07d0fa0e9404
< 1.4.36
HIGH 8.8 The Users Ultra Membership, Users Community and Member Profiles With PayPal Integration Plugin for WordPress is vulnerab… wordfence
e92c6374-d11d-458c-b089-0ee79c33e4a6 HIGH 8.8 The Copify plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.0. Thi… wordfence
e9224b37-d6ce-4847-afb0-9a42c9fa665c HIGH 8.8 The Blogstand Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e91c0935-4213-4376-86ec-7ff78808fb9e
< 1.3.6
HIGH 8.8 Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin be… wordfence
e8fe4aa7-13e6-48ec-afec-2888edd999f5
< 0.8.6.0
HIGH 8.8 The WP Fastest Cache plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 0.8.5.… wordfence
e8c16dd9-0c04-42b9-a2d3-28b442cecdb3
< 3.2.3
HIGH 8.8 An issue was discovered in the svg-vector-icon-plugin (aka WP SVG Icons) plugin through 3.2.2 for WordPress. wp-admin/ad… wordfence
e8c0f9d8-c5cf-4e31-bc0b-289ad7c1d197
< 1.7.1
HIGH 8.8 The SoundRise Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… wordfence
e8bed9c0-dae3-405e-a946-5f28a3c30851
< 5.1.5
HIGH 8.8 The UserPro plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1.4 due to in… wordfence
← Prev 117 118 119 120 121 122 123 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top