πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 130 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
CVE-2026-6261 HIGH 8.8 The Betheme theme for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 28.4. This is d… nvd
CVE-2026-3772 HIGH 8.8 The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2… nvd
CVE-2026-3132 HIGH 8.8 The Master Addons for Elementor Premium plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… nvd
CVE-2026-2448 HIGH 8.8 The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc… nvd
CVE-2026-2001 HIGH 8.8 The WowRevenue plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check … nvd
CVE-2026-1929
< 2.37
HIGH 8.8 The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… nvd
CVE-2026-1750 HIGH 8.8 The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Privilege Escalation in all versio… nvd
CVE-2026-1426 HIGH 8.8 The Advanced AJAX Product Filters plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and … nvd
CVE-2026-1311 HIGH 8.8 The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 … nvd
CVE-2026-0912 HIGH 8.8 The Toret Manager plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc… nvd
CVE-2025-13603 HIGH 8.8 The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i… nvd
CVE-2025-12821 HIGH 8.8 The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is… nvd
CVE-2025-11993 HIGH 8.8 The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve… nvd
cffa4593-bd88-4018-b801-98d9d586111a HIGH 8.8 The KH Easy User Settings plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… wordfence
cfd35a3c-7203-4832-8b0d-56f3e7983118
< 2.81.1
HIGH 8.8 The Dataverse Integration plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks… wordfence
cfc78684-fdb7-4ce1-8464-0d057b48a7fa
< 0.4
HIGH 8.8 The Custom field finder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,… wordfence
cfc6ff21-52f5-453f-bf97-881c39be1aeb
< 2.2.10
HIGH 8.8 The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file … wordfence
cfc6c595-dad2-4abc-8187-ed72355273b8
< 2.5.3
HIGH 8.8 The Better Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5… wordfence
cfbc7af2-1e2c-4aaf-b73c-870f7519aff1
< 1.8
HIGH 8.8 The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
cf711c64-dd5e-4725-824c-fbe9063916d9
< 1.2.6
HIGH 8.8 The Ad Invalid Click Protector (AICP) WordPress plugin before 1.2.6 is affected by a SQL Injection in the id parameter o… wordfence
cf57aeaa-e37e-4b22-aeaa-f0a9f4877484
< 4.4.3
HIGH 8.8 The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress … wordfence
cf4efae5-d8ea-4c94-bc8a-c73615f2fe62
< 4.11.2
HIGH 8.8 The WpStream – Live Streaming, Video on Demand, Pay Per View plugin for WordPress is vulnerable to arbitrary file uplo… wordfence
cede8ff5-f739-4eb3-9672-5adb5d2ae0a9
< 2.1.40
HIGH 8.8 The WP FOFT Loader plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in… wordfence
ceb25a7b-da93-41eb-bae7-8bffa96f7a1c
< 1.0.3
HIGH 8.8 The Slivery Extender plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1… wordfence
cea39157-94aa-4982-983e-9c3e4b1af86d
< 2.16
HIGH 8.8 The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This… wordfence
← Prev 127 128 129 130 131 132 133 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top