πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 122 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e61396d0-9396-449c-b8c4-53fc4e2c57bb
< 3.3.0
HIGH 8.8 The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Br… wordfence
e5ce4685-547c-40d2-9498-e50f390deeea
< 2.8.1
HIGH 8.8 The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Privilege Escalation in all versions up… wordfence
e5ca3c84-9d3d-4bbe-90f7-44c9d77a6690
< 2.2.3
HIGH 8.8 The Plugin for Google Reviews for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
e5b01e96-63e6-4ba0-8c83-f9b05e4050b3
< 4.0.9
HIGH 8.8 The Eventin plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.0.7. This mak… wordfence
e5aa9b71-67e4-4049-8dd4-23b76dbd87bb
< 3.29.10
HIGH 8.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i… wordfence
e597b677-e298-4507-86a5-70a93a9afd6e
< 1.4.14
HIGH 8.8 The SpiderCalendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.… wordfence
e579b7fd-141f-4d5f-9e0e-a1e6b985f0b9
< 1.31
HIGH 8.8 The ClickBank Affiliate Ads WordPress plugin before 1.31 does not have CSRF check when saving its settings, allowing att… wordfence
e55b86e2-b42e-483d-93cd-2f09af64dbc7
< 2.2
HIGH 8.8 The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi… wordfence
e556d8c9-3ca5-4bec-a840-7a6d67532e59
< 2.0.40
HIGH 8.8 An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.0.39 for WordPress. It is possible (due… wordfence
e54f98bc-c538-4f3c-b24a-6e778a3748ef
< 2.2.17
HIGH 8.8 The School Management System – WPSchoolPress plugin for WordPress is vulnerable to Privilege Escalation due to a missi… wordfence
e53bb240-8784-4d34-8d3f-4a7af917f3f4
< 4.3.5
HIGH 8.8 The Simple Membership plugin for WordPress is vulnerable to account takeover due to missing input validation on the proc… wordfence
e52c95b3-0126-4139-9944-6becef4c4d53 HIGH 8.8 The Widget Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.… wordfence
e5240171-6051-455c-b6df-630e2cd8308d
< 1.2.5
HIGH 8.8 The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id … wordfence
e4e6e410-5778-41f7-a259-daa506bfb161 HIGH 8.8 The Media File Manager Advanced plugin for WordPress is vulnerable to Local File Disclosure, SQL Injection, Cross-Site S… wordfence
e4b16cf2-7e29-47c5-921e-188e2db33084
< 1.7.2
HIGH 8.8 The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, a… wordfence
e4966f96-713c-471f-8f36-55977a547f12
< 3.1.0.2
HIGH 8.8 The Easy Digital Downloads plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 3.1.0.1… wordfence
e4930b03-9142-464e-98ae-a910dfa46f2a
< 1.6.7.9
HIGH 8.8 The Appointment Booking Calendar β€” Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to S… wordfence
e491cdac-4946-41aa-91c1-92e56e862090
< 3.7
HIGH 8.8 The Hotel Booking plugin for WordPress is vulnerable to Local File Inclusion via the nd_booking_ss_rooms() function in v… wordfence
e489a90e-f226-4900-938c-b5a7550d199c
< 4.68
HIGH 8.8 The SP Project & Document Manager plugin for WordPress is vulnerable to SQL Injection via an unknownparameter in versio… wordfence
e489960e-254a-4b8d-85ab-0f749ff48e8c
< 7.1.2
HIGH 8.8 The Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
e4632899-c3bf-48f3-8a69-8fa32bfd902d
< 3.16.3
HIGH 8.8 The BM Content Builder plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privileg… wordfence
e4421c1b-742c-4307-9736-d6263bab4ae4
< 1.7.9
HIGH 8.8 The WP ALL Export Pro plugin for WordPress is vulnerable to SQL Injection via the cc_sql parameter in versions up to, a… wordfence
e437ef90-5321-4543-a4ef-716b898315eb
< 2.5
HIGH 8.8 The My wpdb plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.12. T… wordfence
e4045a2b-2bbc-4335-b6d2-af7a046f1f92 HIGH 8.8 The AP Background plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization and insuffic… wordfence
e3e340b8-4eed-4622-b7c4-73d5bafb7e8e
< 1.7
HIGH 8.8 The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. wordfence
← Prev 119 120 121 122 123 124 125 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top