πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 131 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
ce90db0c-d4ca-4b32-8a64-681642aaf032 HIGH 8.8 Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress allows deleting… wordfence
ce779d08-93bf-4634-bb83-f5573876e086
< 2.5.9
HIGH 8.8 The Powerkit plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.8 Th… wordfence
ce5b3390-75c2-4288-91a6-f9ceb893a952
< 1.4
HIGH 8.8 The Duplicate Title Validate plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0 d… wordfence
ce3ff7f9-ccad-45c0-a278-f66fbb6263ee HIGH 8.8 The Auto Delete Posts WordPress plugin through 1.3.0 does not have CSRF check in place when updating its settings, which… wordfence
ce340b88-cbab-4ba8-93ae-8790f2348456
< 5.1.1
HIGH 8.8 The All In One WP Security & Firewall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
ce1ac711-6026-49ef-b66b-2cc199697942
< 1.5.67
HIGH 8.8 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file upl… wordfence
cde6e758-9723-43f2-9972-32be8aeb2b91
< 7.11.5
HIGH 8.8 The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due … wordfence
cdd7971c-6f1c-437a-832c-e2b2817a197e
< 2.2.1
HIGH 8.8 The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc… wordfence
cd97a7a4-9f57-4882-9e3e-0e9853416af9
< 3.6.7
HIGH 8.8 The Simple JWT Login – Allows you to use JWT on REST endpoints. plugin for WordPress is vulnerable to Authentication B… wordfence
cd90d9c0-0cab-4fd3-b016-106032f300f7
< 7.2
HIGH 8.8 The Vertical marquee plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a… wordfence
cd7c763f-5c2b-407e-bdb1-4ea34fac5f4d
< 3.1.3
HIGH 8.8 cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary co… wordfence
cd393566-b037-40ce-b3cd-12e323e9451b
< 3.1.26
HIGH 8.8 The FULL Customer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.25. T… wordfence
cd36530d-4165-4b98-a75f-b9c88178a5b6 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attacker… wordfence
cd2b419f-7b79-4988-ade3-5e7f53f3da58
< 1.3.3
HIGH 8.8 The Qi Blocks plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.2. This m… wordfence
cd106b92-48ee-46f4-b0a3-f595d227a0a1
< 1.0.6
HIGH 8.8 The pretix widget plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.5. Th… wordfence
cd091bd5-6b6a-4964-9249-525bbbec702c
< 3.29.3
HIGH 8.8 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i… wordfence
ccc75dee-1cf8-4fda-b2a1-f5d68e6c7887 HIGH 8.8 The Advanced AJAX Page Loader plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload … wordfence
ccad206a-407e-4c49-9a4a-d5dce3e9612a
< 3.1.5
HIGH 8.8 The Two Way Chat plugin for WordPress is vulnerable to multiple Cross-Site Request Forgery in versions up to, and includ… wordfence
cc994b2a-b3da-4edc-ada3-1150065efd30
< 7.3.6
HIGH 8.8 The themify-ultra theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 7.3.5.… wordfence
cc910c27-d83c-4f3d-b491-f3e169d8f25f
< 2.2.7
HIGH 8.8 The Fluid Responsive Slideshow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
cc886378-cebf-4c0b-a089-62e9469dd954
< 2.3
HIGH 8.8 The KONTXT Content Advisor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
cc6d943d-32c0-45d7-9de9-b576199e6fe7
< 2.3
HIGH 8.8 The Login/Signup Popup, Waitlist Woocommerce ( Back in stock notifier ), and Side Cart Woocommerce (Ajax) WordPress plug… wordfence
cc525501-1fe9-4c31-a126-c1984446b978
< 3.3.0
HIGH 8.8 The Houzez Login Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… wordfence
cc13d13c-6b79-4bf1-8e77-c8cb836dc0c5
< 3.41.2
HIGH 8.8 The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escala… wordfence
cc0d15ab-e0a4-4ac5-8558-23aeaf00b11a
< 2.0.3
HIGH 8.8 Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary c… wordfence
← Prev 128 129 130 131 132 133 134 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top