πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 140 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b5fd7bca-7754-4f83-8e51-5278e6e8cc78 HIGH 8.8 The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeov… wordfence
b59ef0f8-3186-48f8-ade3-a7afe9e4f8ff
< 0.9.0
HIGH 8.8 The Kids Online Store theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… wordfence
b5818587-0a52-4734-8f75-263b4ab5020e
< 2.1.0
HIGH 8.8 The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure … wordfence
b55128e9-f79f-4872-931f-c6f4d1d12032
< 1.9.19
HIGH 8.8 The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter. wordfence
b536563f-b978-4ba6-8a28-d8ee6b87964a
< 3.3.1
HIGH 8.8 The acf-better-search (aka ACF: Better Search) plugin before 3.3.1 for WordPress allows wp-admin/options-general.php?pag… wordfence
b536028d-4e11-4bda-8097-b37857a28309 HIGH 8.8 The Thumbnail For Excerpts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inclu… wordfence
b530d1a3-dd3c-4efb-9cff-39b6908f11c9
< 1.0.4
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Disable Comments plugin before 1.0.4 for WordPress allows remote … wordfence
b4ff715e-056e-48d8-bb82-d4f89047384f
< 5.16.6
HIGH 8.8 Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[… wordfence
b4eb5833-25cd-4a6c-9240-37a9f8c1b120
< 2.0.0
HIGH 8.8 The WP Brutal AI plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions before 2.0.0 d… wordfence
b4e0ee4f-fc45-4682-9ed4-aa1301205bb4
< 3.3.5
HIGH 8.8 The Rate my Post plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.3.… wordfence
b4de2c22-4d8f-45b1-bccb-c536eefd58a8 HIGH 8.8 The WordPress BasePress Migration Tools plugin for WordPress is vulnerable to arbitrary file uploads due to missing file… wordfence
b4d33e69-3620-42d9-adb3-267a5ed02a58
< 1.9
HIGH 8.8 WP Maintenance Mode & Site Under Construction Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versio… wordfence
b4accf10-710e-4cba-8d61-04e422324f9d
< 12.1
HIGH 8.8 The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up t… wordfence
b4599c7f-5e5d-4571-97d9-54d6fd0c9c63
< 2.12.1
HIGH 8.8 The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of dat… wordfence
b3f75424-b9f3-42ee-a96c-ff0ed30cbd2f
< 1.4.6.1
HIGH 8.8 The WPS Limit Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
b3ce53e5-8666-4227-83d3-58f35db0ce68
< 3.0.12
HIGH 8.8 The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.… wordfence
b3bb31c8-b1d9-4189-a27f-ac62d19532b2
< 8.7.4
HIGH 8.8 The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
b3adfe9e-ebdf-4a50-b60f-03a606a84ec0 HIGH 8.8 The Realty Portal – Agent plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization with… wordfence
b37e6b44-810a-49c8-8903-30a9e228027d
< 4.5
HIGH 8.8 The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and i… wordfence
b3758f06-2b69-458f-a7c8-f604f0fbda31
< 6.60
HIGH 8.8 The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of i… wordfence
b2cf3b85-2e2d-43dc-9877-9a740d4fd2fb
< 3.7.3.6
HIGH 8.8 The WordPress CRM, Email & Marketing Automation for WordPress | Award Winner β€” Groundhogg plugin for WordPress is vuln… wordfence
b2cea890-b131-47cd-9050-a484fb1895f6
< 1.1
HIGH 8.8 The 5 Star Hotel theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1… wordfence
b2c83287-13ca-4fdc-95b6-97da150b0c09
< 4.5.3
HIGH 8.8 The WP Meta SEO plugin for WordPress is vulnerable to SQL Injection via the β€˜ids’ parameter in the bulkImageCopy fun… wordfence
b2a98c69-5f76-41f4-8a12-0523285647fb
< 4.1.0.2
HIGH 8.8 The All in One SEO – Best WordPress SEO Plugin – Easily Improve Your SEO Rankings before 4.1.0.2 enables authenticat… wordfence
b29113d6-7a9a-4e10-a446-147ec146ac93
< 9.1.0
HIGH 8.8 The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions … wordfence
← Prev 137 138 139 140 141 142 143 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top