πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 129 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
d245dc6c-c579-4e28-a953-9227261911d4 HIGH 8.8 The Custom Content Shortcode plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
d2278347-d961-47d7-b89d-61a82441597c HIGH 8.8 The WZone - Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.… wordfence
d225dee1-305c-4378-bc07-192347a0c838
< 4.7.0
HIGH 8.8 The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the '… wordfence
d22013e5-896a-4dcb-bbe4-e6be7d697816
< 3.42.10
HIGH 8.8 The WP Fusion Lite – Marketing Automation and CRM Integration for WordPress plugin for WordPress is vulnerable to Remo… wordfence
d21bebcc-8dba-407d-8a3a-b91d3cddd38f
< 6.4.1
HIGH 8.8 The WP Ultimate CSV Importer plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
d20ffc7c-0e12-45ec-940f-a42655093021
< 5.1.5
HIGH 8.8 The Shopping Cart & eCommerce Store WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_currency_s… wordfence
d2031289-eaf3-4a1b-8771-769c08d99ca3
< 1.3.56
HIGH 8.8 The Royal Elementor Addons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
d1d21339-3a86-4bee-be86-2d2ab9190b26
< 1.5.2
HIGH 8.8 The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
d1b3d4d5-9d2b-4924-a830-27c07fa1ba98
< 1.5.4
HIGH 8.8 The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, … wordfence
d18c17f1-7b85-46d6-a92e-948be98adf87
< 2.0.9
HIGH 8.8 The MZ MBO Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0… wordfence
d151c9a1-d47e-4155-8539-133f6abd57a5
< 2.1.1
HIGH 8.8 The hndtst_action_instance_callback AJAX call of the Handsome Testimonials & Reviews WordPress plugin before 2.1.1, avai… wordfence
d143cefc-e387-47bd-aff6-a2099f704d20
< 1.6.0
HIGH 8.8 The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… wordfence
d10a0372-1ab3-474e-8d5c-33f71fddfe06
< 2.1.4
HIGH 8.8 The Mail Subscribe List WordPress plugin before 2.1.4 does not have CSRF check in place when deleting subscribed users, … wordfence
d10336c2-656f-40f7-a95a-dbf829c2ce38
< 1.2
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a re… wordfence
d0d8d660-4f8f-4fd5-b001-b182219cf327 HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Post to Twitter plugin 0.7 and earlier for WordPress a… wordfence
d0c72033-ab9b-49bb-be28-e09a810137fe
< 2.3
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attac… wordfence
d0b1fa88-2fc6-41af-bd39-12af92dc6533
< 9.3
HIGH 8.8 The Message ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and… wordfence
d0999244-4097-4e8c-8f7e-4accd7727d69
< 4.0.14
HIGH 8.8 The Dropshix plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several func… wordfence
d056eeea-6ed2-4139-ba32-727a95f29aaf
< 2.5.1
HIGH 8.8 The Polylang plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. Thi… wordfence
d0506137-82e3-4988-9b23-370465a866c0
< 4.7.2
HIGH 8.8 The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu… wordfence
d038f1a2-4755-417f-965d-508b57c05738 HIGH 8.8 The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.… wordfence
d03459d8-b1f2-4270-a294-403754db1f2f
< 3.2.0
HIGH 8.8 The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress i… wordfence
d0301141-bbc6-4a9e-b816-888554600b57
< 3.3.3
HIGH 8.8 The iubenda plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.2. Th… wordfence
d0177510-cd7d-4cc5-96c3-78433aa0e3f6
< 1.1.6
HIGH 8.8 The BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin plugin for WordPress is vulnerable… wordfence
CVE-2026-8365
< 2.1.35.
HIGH 8.8 The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_… nvd
← Prev 126 127 128 129 130 131 132 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top