πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 139 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b9793793-44d5-4628-a57b-c1254645e648
< 3.5.26
HIGH 8.8 The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in… wordfence
b9769bc3-236f-4c9d-a4ce-544e49eee2ec
< 4.3.2
HIGH 8.8 The Astra Pro Addon plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.… wordfence
b95ec70c-ac76-48fa-9d9d-01cf1983e504
< 6.2.7
HIGH 8.8 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i… wordfence
b9567f63-9161-49a3-9b94-dd6dee5a5628
< 5.4
HIGH 8.8 The democracy-poll plugin before 5.4 for WordPress has CSRF via wp-admin/options-general.php?page=democracy-poll&subpage… wordfence
b946ee73-4cf9-48c8-b456-285b118c6b05
< 3.8.3.5
HIGH 8.8 The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form &… wordfence
b91f3db6-5331-48d4-9c79-9ecba0870be2
< 1.8.6
HIGH 8.8 The Photo Gallery by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
b910b678-5869-43e6-8993-fcf53fe4c66f HIGH 8.8 The BuddyPress Customer.io Analytics Integration pluginfor WordPress is vulnerable to Cross-Site Request Forgery in vers… wordfence
b8f30220-4f6e-458b-a053-8d8277150237
< 2.8.3
HIGH 8.8 The MZ Mindbody API for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.8.2. T… wordfence
b8eec2f0-1b6f-45cf-8291-019bc1d08f9b
< 26.6.3
HIGH 8.8 The Betheme theme for WordPress is vulnerable to authorization bypass in versions up to, and including, 26.6.2. This is … wordfence
b8a41eb6-8fb2-4274-a50b-571e85ac87f8
< 1.14.0.3
HIGH 8.8 The import-users-from-csv-with-meta plugin before 1.14.0.3 for WordPress has CSRF. wordfence
b86ff40d-45dd-4cb6-9a4e-16aaf1d35196
< 0.4.7
HIGH 8.8 WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=… wordfence
b81c2990-68d1-4d45-9724-262ec017caf1
< 1.6.0
HIGH 8.8 The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege e… wordfence
b7fe772a-542e-4c3e-b1cb-05cce3b2ec3f
< 1.2
HIGH 8.8 The "wordpress vertical image slider plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery via severa… wordfence
b7d475d5-9c00-409c-ac07-276242540123
< .51.1
HIGH 8.8 SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPres… wordfence
b7cc5b51-5fb4-470b-8d2d-581eceadde7b
< 3.7.4
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote … wordfence
b7a57c3b-0d1b-40ad-9e55-6a1eab4e0380
< 4.25
HIGH 8.8 The User Role Editor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the… wordfence
b790db69-cccd-4adf-a7fa-f7db4dd96be6
< 2.0.6
HIGH 8.8 The JS Help Desk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… wordfence
b7832d37-19a9-491b-879e-4a22f2ba46ec
< 1.5.0
HIGH 8.8 The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capab… wordfence
b70e8bce-1793-40f0-bdb1-100cf5f431e9
< 1.8.6
HIGH 8.8 The Export any WordPress data to XML/CSV plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
b6cf6390-480f-44e2-ae36-67e3398add33
< 1.2.66
HIGH 8.8 The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This… wordfence
b6b68e35-ecfb-4876-8fee-c389077b2b4a
< 2.2.2
HIGH 8.8 The Zlick Paywall plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.2… wordfence
b6b0dc03-3715-41f8-8888-1cccddb39c0b HIGH 8.8 The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege… wordfence
b691560e-e285-467c-9d52-1620c63de1f0
< 1.6.21
HIGH 8.8 The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
b64921fe-1b09-49e7-b2ec-f708fba99c2a
< 1.4
HIGH 8.8 The 404 SEO Redirection WordPress plugin through 1.3 is lacking CSRF checks in all its settings, allowing attackers to m… wordfence
b62fb1a8-d62d-4d1f-bcce-a081432b9e61 HIGH 8.8 The Avirato hotels online booking engine plugin for WordPress is vulnerable to SQL Injection via the β€˜id’ attribute … wordfence
← Prev 136 137 138 139 140 141 142 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top