🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 123 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e3551218-e272-4c96-94fe-9db0aee0d4f4
< 1.0.21
HIGH 8.8 The Build App Online plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability… wordfence
e342244a-58c4-462d-9b2c-3070f3d87ab4
< 7.2
HIGH 8.8 The Pin = Pinterest Style / Personal Masonry Blog / Front-end Submission theme for WordPress is vulnerable to arbitrary … wordfence
e30187da-c25d-4651-a32d-abdc6da53978
< 1.6.8
HIGH 8.8 The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validati… wordfence
e2e6b451-9835-4887-ade7-b18807223a88
< 2.3.0
HIGH 8.8 The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability… wordfence
e2e62675-e3d5-4545-bb80-0330da966368
< 4.0.2
HIGH 8.8 An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page functi… wordfence
e2e2f446-5391-4189-8c9c-3be2459808d0
< 2.0.5
HIGH 8.8 The Social Slider Feed plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 2.0.… wordfence
e2defe79-137f-45a0-85a1-f61dce9afd28
< 1.1.5
HIGH 8.8 The WP LMS – Best WordPress LMS Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
e2d46ac3-6751-475d-8d91-eabbc27a6295 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module up to and including 1.5.1 for… wordfence
e2ce98c3-b0a5-4b6b-ac3c-26e0a3195944
< 3.6.2
HIGH 8.8 The Contact Us Page – Contact People plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
e2ca42f3-776f-4ba4-a409-863799338c85
< 7.6.3
HIGH 8.8 The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … wordfence
e2b020c3-0eb9-4ff1-b94e-e32452695b5d HIGH 8.8 The Copy Or Move Comments plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 5.0.4 du… wordfence
e28f0ff6-eee3-45bb-be7e-91e2349a91d5
< 1.6
HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) discovered in tarteaucitron.js –… wordfence
e287e85d-8687-4079-99ea-92718031f343
< 1.6
HIGH 8.8 The Elementor Contact Form DB plugin before 1.6 for WordPress allows CSRF via backend admin pages. wordfence
e2793547-5edf-4d2a-bc3b-fcaeed62963d
< 3.7.0
HIGH 8.8 The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu… wordfence
e27825b9-c3ef-4740-bd19-7198c806c70b HIGH 8.8 The Intimate Payments plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
e27634f8-493b-4edb-a0c7-1bc8890b70f0
< 1.0.2
HIGH 8.8 The Ship To eCourier plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
e267c589-6b2a-40b3-beeb-0e397d9076e7
< 7.7.18
HIGH 8.8 The The Post Grid plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.7.17. T… wordfence
e25ca990-eee1-4f72-b543-7a65bc4855a8
< 1.7.9
HIGH 8.8 The Industrial theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalat… wordfence
e23e7d66-4b57-4feb-bf77-46238bc6ce7c
< 1.1.6
HIGH 8.8 The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. … wordfence
e2389b9c-c766-4cb7-83d6-b0ad7d2a075e
< 1.2
HIGH 8.8 The No Page Comment plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
e23335c9-0830-4c6b-8e0d-6897a7176ba5
< 1.13.1
HIGH 8.8 The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all ver… wordfence
e203fc8f-fc57-4918-8ef2-3ba6ae979d40
< 2.0.6
HIGH 8.8 The WooCommerce Conversion Tracking plugin for WordPress is vulnerable to Cross-Site Request Forgery and Cross-Site Scri… wordfence
e1f230f5-d40c-43b2-82f2-c920dca9707f HIGH 8.8 The Owl carousel responsive plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in… wordfence
e1ae8af9-36da-421b-8759-c93f78af3a66 HIGH 8.8 The VG PostCarousel plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. Th… wordfence
e1a3cc98-3bee-4d52-a4bf-2a1a284b9311
< 1.0.73
HIGH 8.8 The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable… wordfence
← Prev 120 121 122 123 124 125 126 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top