πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 137 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
bf11aed9-8782-4579-95a5-e88b19641ae8
< 1.4.3
HIGH 8.8 The Falang multilanguage for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to,… wordfence
beb47081-ad9c-4ecb-bbcd-2ae916e55baf
< 5.2.6
HIGH 8.8 The Media File Renamer – Auto & Manual Rename plugin for WordPress is vulnerable to authorization bypass due to a miss… wordfence
be6c08b9-bba7-4780-99b9-4b80e6b4872a
< 1.5.3
HIGH 8.8 Multiple SQL injection vulnerabilities in admin.php in the Collne Welcart plugin before 1.5.3 for WordPress allow remote… wordfence
be60b765-3bd6-43dd-8cdc-d9c493a503e5 HIGH 8.8 The accurate-form-data-real-time-form-validation plugin 1.2 for WordPress has CSRF with resultant XSS via wp-admin/optio… wordfence
be5142f6-36da-4715-91d2-7d6665c0efa6
< 1.3.8
HIGH 8.8 The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for Word… wordfence
be4061ef-849a-4797-aeee-07da2afc1a40
< 1.3.0
HIGH 8.8 A Cross-Site Request Forgery leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.… wordfence
be0e0e79-00c3-4237-ac65-9c5df625dd89 HIGH 8.8 The gSlideShow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.1. T… wordfence
be0d4cf1-db98-4388-9d88-27746ef239ee
< 1.0.10
HIGH 8.8 The Vite Coupon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.9… wordfence
be098ee9-b749-4908-85e8-e717d019609a
< 4.6.5
HIGH 8.8 The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and inc… wordfence
bde2a8a5-2d18-4659-bb35-dff4f521dbb4
< 1.6.2.1
HIGH 8.8 The Xserver Migrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi… wordfence
bdd9045e-5869-446b-9a6e-4c6766b91d05 HIGH 8.8 The Sync Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '… wordfence
bdd70819-57dd-4a60-9398-68d6b87da3ca
< 1.0.47
HIGH 8.8 The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user… wordfence
bdc946ed-8891-4f97-af7e-2034760eef5b HIGH 8.8 The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Cross-Site… wordfence
bdb35f31-60a6-40b5-aed3-102a1c8c4fd1
< 2.4.1
HIGH 8.8 The WordPress REST API Authentication plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to… wordfence
bda2f3f6-b036-4feb-bb38-1d4eaf965c24
< 5.30.3
HIGH 8.8 The YARRP plugin for WordPress is vulnerable to SQL Injection via the 'limit' parameter set via a shortcode in versions … wordfence
bd715375-6bf8-4602-9554-b1f81aa5afa2
< 2.2.1
HIGH 8.8 SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL co… wordfence
bd478bb7-f0d7-4a29-8236-96ad69b5ae67
< 3.3.1
HIGH 8.8 The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to … wordfence
bd42c89e-57db-458f-910c-404a5615f280
< 3.9.9.3
HIGH 8.8 The Eventer - WordPress Event & Booking Manager Plugin plugin for WordPress is vulnerable to SQL Injection via the reg_i… wordfence
bd3c1e65-fcb2-4e31-973b-8271a833c6ba
< 5.6
HIGH 8.8 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter … wordfence
bd38b5f2-f13e-4433-9a8a-2f42cc1782c6
< 1.6.0
HIGH 8.8 The MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics plugin for Wo… wordfence
bd302d8e-bba1-4fa1-bcbc-591d894ca1d6
< 5.7.0
HIGH 8.8 The Simple Link Directory plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 5… wordfence
bd1838c4-00df-4177-84be-1f8c19ceae4e
< 9.3
HIGH 8.8 The wp-championship plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 9… wordfence
bced4547-3264-43dc-8bb1-89a06f74ccbd HIGH 8.8 Multiple plugins and/or themes for WordPress are vulnerable to Arbitrary File Uploads due to a missing capability check … wordfence
bcd40c75-9c27-46b3-9ab8-dc8aad45c74c HIGH 8.8 The Mimoos plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.2 due to insufficient… wordfence
bc69ec54-b30f-402e-ad3b-24fd680ea72b
< 2.0.8
HIGH 8.8 The Groundhogg plugin for WordPress is vulnerable to generic SQL Injection via the '/wp-content/plugins/groundhogg/inclu… wordfence
← Prev 134 135 136 137 138 139 140 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top