πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 124 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
e18aba51-46a8-4670-8e15-85b12f5d06e6
< 1.18
HIGH 8.8 Cross-site request forgery vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the auth… wordfence
e158a13d-5452-492a-875e-53791e1ff840 HIGH 8.8 The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation f… wordfence
e1549ae5-267d-4fbb-be07-5b3842efd4f1
< 5.6.9
HIGH 8.8 The OWM Weather plugin for WordPress is vulnerable to unspecified SQL Injection via the β€˜post’ parameter in versions… wordfence
e140973b-d37c-45bf-aed2-9223bd812957
< 4.35.0
HIGH 8.8 The Webpushr plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.34.0. … wordfence
e12c14c8-9603-483b-9b07-fa36c9f98285
< 1.36.32
HIGH 8.8 The Ultimate Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and … wordfence
e11f1a56-d5a2-47a4-a5cc-34345966495a HIGH 8.8 The ScrollTo Top plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions u… wordfence
e0f295f9-1090-4b10-abc5-3f73c5b4e28d
< 3.6.5
HIGH 8.8 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
e06c7e0a-f972-430a-9f87-786e0c6e1a84 HIGH 8.8 The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php. Thi… wordfence
e0662c3a-5b82-4b9a-aa69-147094930d1f
< 1.3.0
HIGH 8.8 The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code In… wordfence
e029bc15-8128-42d1-8874-b0689312cb35 HIGH 8.8 The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 v… wordfence
dfd7b788-03a0-41a4-96f2-cfca74ef281b HIGH 8.8 The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.… wordfence
dfa3efa2-c542-44b9-8039-13e6eac75101
< 1.0.12
HIGH 8.8 The Free Live Chat Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
df8a8ce0-7258-40ae-bf73-f8c6185fdd16
< 5.2.0
HIGH 8.8 The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1… wordfence
df48f7f9-7bc9-4f9b-b9b5-6bfb86309030
< 1.0.7
HIGH 8.8 The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of … wordfence
df32e1d0-3645-432c-a2e4-2d63709c4ffd
< 0.8.3.5
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest… wordfence
df09af41-399a-4878-8420-721f1198d895
< 1.1.20
HIGH 8.8 The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file ext… wordfence
deffd646-5117-4086-bf4b-8a17ffdaad8b
< 2.0.0
HIGH 8.8 The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Arbitrary Plugin Installation in all v… wordfence
def28d93-744f-4232-b745-8430d466b9fa
< 4.1.1
HIGH 8.8 The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation. wordfence
deeeb78d-1757-44ec-968b-968d919b84f1
< 2.34.0
HIGH 8.8 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… wordfence
decb80c9-8f04-4d39-8e77-220f7862995e
< 1.6.5.7
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in HTML5 Maps 1.6.5.6 and earlier allows remote attackers to hijack the … wordfence
de7cde2c-142c-4004-9302-be335265d87d
< 1.7.50
HIGH 8.8 The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… wordfence
de2d77f4-91eb-4e94-8847-19e125c9a0cb
< 1.1.9
HIGH 8.8 The Advanced Scrollbar – Custom Scrollbar Styling and Behavior plugin for WordPress is vulnerable to Privilege Escalat… wordfence
de28d287-af14-45c9-b69c-125968fc4879
< 2.4
HIGH 8.8 The Timeline and History slider plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in… wordfence
de1da248-2e03-40fa-8997-7176dc06abc9
< 0.9.36
HIGH 8.8 The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file uploads due to a missing… wordfence
ddfbde0f-8e41-45c9-b808-bee82c2ff172
< 1.2.2
HIGH 8.8 The WP Remote Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
← Prev 121 122 123 124 125 126 127 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top