πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 141 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b2670e15-a71a-4800-882d-5d04faeaeee1
< 3.8.9
HIGH 8.8 The Simple Download Monitor plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including… wordfence
b2642726-a878-46d1-9c17-a4c8f4d5e315
< 1.0.1
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress all… wordfence
b2401dd1-d132-4899-80fc-9281280806a2 HIGH 8.8 The Easy Embed for HubSpot Forms, CTAs, Links, Files & add HubSpot to WP Search Results plugin for WordPress is vulnerab… wordfence
b23ab054-11c9-4229-9adc-6eef6f81c3f9
< 19.6.2
HIGH 8.8 The Rehub theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.6.1 due to insufficien… wordfence
b2286e96-59e1-465a-b600-8a88e9e97418
< 6.4.1
HIGH 8.8 The ARforms plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to, and incl… wordfence
b2251afd-7c0c-444f-b458-aaeeb48b8a6a HIGH 8.8 The WHMpress plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 6.2-revision-9… wordfence
b211f05e-fc6a-4aaf-b75e-b044243f9176
< 3.6.1
HIGH 8.8 The GD Rating System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.… wordfence
b1f17a83-1df0-44fe-bd86-243cff6ec91b
< 1.7.6
HIGH 8.8 The ImageMagick Engine plugin for WordPress is vulnerable to remote code execution via the 'cli_path' parameter in versi… wordfence
b1ecfa60-9b43-4b70-bd60-278dfb0e7dbb
< 1.4.4
HIGH 8.8 A vulnerability was found in XYZScripts Contact Form Manager Plugin. It has been declared as problematic. Affected by th… wordfence
b1d7f2f5-0685-4be0-bd3b-93c39d9bb7ee
< 2.2
HIGH 8.8 The Animated Number Counters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu… wordfence
b1bc4a87-d5de-4d66-9cc5-802ef11f886c
< 1.2.9.3
HIGH 8.8 The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2… wordfence
b1a3666b-2329-49c3-b017-9b495d90415e HIGH 8.8 The Platform 4 theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.4. … wordfence
b191a337-ec45-4357-9b37-6ca0af9cb2f9
< 6.8.2
HIGH 8.8 The Ask me WordPress theme before 6.8.2 does not perform CSRF checks for any of its AJAX actions, allowing an attacker t… wordfence
b1853c88-277b-4955-b042-aeed1cffb49b
< 4.2.1
HIGH 8.8 The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up … wordfence
b17d1280-2bae-4c45-b2e1-fbfcb2c7c15b
< 3.2.0
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote atta… wordfence
b155f8ca-9d09-47d7-a7c2-7744df029c19
< 1.5.108
HIGH 8.8 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injecti… wordfence
b150f90a-ccb7-4c19-a4b3-eaf9ec264ba8
< 1.9.20
HIGH 8.8 The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege e… wordfence
b14bc75a-0bfb-4d46-89db-c31fb6bfa7cf
< 2.9.9.2.9
HIGH 8.8 The Pinpoint Booking System plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions u… wordfence
b142859d-780f-47f8-aaed-000bdd0aaaa7
< 5.0.3
HIGH 8.8 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for Word… wordfence
b13e1916-2a02-4a91-acf1-6e5d7c55bd57
< 5.12.5
HIGH 8.8 The Advanced Custom Fields plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, … wordfence
b12efe6c-63e9-4d5c-9437-7c0b6abe2ee5 HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the SPNbabble plugin 1.4.1 and earlier for WordPress allow… wordfence
b12a25e1-98a7-427b-85b0-8503f74687d5 HIGH 8.8 The SP Blog Designer plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.0.… wordfence
b11ed628-f736-4262-80a2-62b32948a3a4
< 1.0.12
HIGH 8.8 The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request F… wordfence
b10d8f8a-517f-4286-b501-0ca040529362
< 9.2.0
HIGH 8.8 The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up t… wordfence
b0c646b7-8f4d-4966-b866-8764ca98af35
< 1.8.13
HIGH 8.8 The Simple SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.12… wordfence
← Prev 138 139 140 141 142 143 144 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top