πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 121 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e8ac60ae-f67e-4d62-a3a7-fb2e9b334ec9 HIGH 8.8 The TuriTop Booking System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … wordfence
e89fc348-1146-4593-8bf5-127f783ab786
< 8.1
HIGH 8.8 The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Re… wordfence
e89d912d-fa7a-4fb1-8872-95fa861c21ca
< 1.0.3
HIGH 8.8 The WP User Switch plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.2. … wordfence
e865324e-a2a2-40fb-8c6a-a89317b59c8c
< 6.2.1
HIGH 8.8 The Booking Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e84b1f01-1c3b-4498-aea9-02ced5f1109e
< 2.1.8
HIGH 8.8 An issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php. wordfence
e8336c89-44ac-4e41-bc81-7dae9599c050 HIGH 8.8 The Widgets for WooCommerce Products on Elementor plugin for WordPress is vulnerable to Local File Inclusion in all vers… wordfence
e8263908-95b3-4b72-a9de-a982618eba2c HIGH 8.8 The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc… wordfence
e7fcda2b-d679-44af-9592-4a96a0115a08
< 19.1.5.1
HIGH 8.8 The Contest Gallery (Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 d… wordfence
e7fb6233-3f58-4237-aaaf-4bc60c5cc8ca
< 3.5
HIGH 8.8 The Erident Custom Login and Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-… wordfence
e7ecd712-a7b3-40e2-b982-be8b58e9b8c3
< 2.1.1
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the 'search[order_column][0]' POST parame… wordfence
e7e83cee-f2c6-4de0-8801-fb63398f98fc HIGH 8.8 The daac_delete_booking_callback function, hooked to the daac_delete_booking AJAX action, takes the id POST parameter wh… wordfence
e7d7ec5b-0616-4895-b5bf-be25ac37fb17
< 1.8
HIGH 8.8 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer … wordfence
e78f4832-6d14-4eef-8e4b-f4136b0c1902
< 3.26.7
HIGH 8.8 The Wishlist Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and excluding, 3.2… wordfence
e78097a6-6828-4d62-abf0-995a906ad68b
< 2.3.3
HIGH 8.8 The Button Generator WordPress plugin before 2.3.2 within the wow-company admin menu page allows to include() arbitrary … wordfence
e73fd28f-51d0-44a3-8400-9148bb46ea18 HIGH 8.8 The xSmart - App Landing Page WordPress Theme in Tech Presentation, Promo Marketing & Advertising Agency theme for WordP… wordfence
e70e2b73-0627-41a4-b3e8-3c23dfbc3dd5
< 4.3.2
HIGH 8.8 The Estatik plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.3.1. This mak… wordfence
e703d411-d608-43cc-8806-1d1e837cf797
< 5.0.1
HIGH 8.8 The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or use… wordfence
e702bb88-23b6-460e-829b-87f1adc1843f HIGH 8.8 The I Draw plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
e6e7889b-a1e2-439f-891d-c7c9a052cafc HIGH 8.8 The Bulk Change Role plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the… wordfence
e6e114a3-8a17-4c79-9829-374646b53ed4
< 5.0
HIGH 8.8 A SQL injection vulnerability in the Xpert Solution "Server Status by Hostname/IP" plugin 4.6 for WordPress allows an au… wordfence
e6ac52eb-ced6-4888-becf-1294d34d3e88
< 2.2.5
HIGH 8.8 The Rankology SEO – On-site SEO plugin for WordPress is vulnerable to unauthorized modification of data that can lead … wordfence
e647d1ff-2d2c-43e4-b723-28ed410c4b3a
< 2.6.4
HIGH 8.8 The Classic Editor Addon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includi… wordfence
e62ad97d-2f66-4ee9-9062-4cdb74f76a3a
< 0.5.5
HIGH 8.8 The Kids Gift Shop theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
e620328e-f4f4-4f3a-8767-efbc676f72a4
< 3.7.17
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in WordPress before 4.7.1 allows remote attackers to hijack the authenti… wordfence
e61f1835-2e56-40c8-b4b9-b3b9766d7e46 HIGH 8.8 The Homepage PopUp plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
← Prev 118 119 120 121 122 123 124 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top