🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 142 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
b0907cb0-b101-4c88-9a8b-b35133e1d0a2
< 1.0.6
HIGH 8.8 The MiwoFTP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.0.6. This makes it pos… wordfence
b06ce1e4-5cfb-415d-ad09-db194d6b4354
< 1.0.9
HIGH 8.8 The Frontend Login and Registration Blocks plugin for WordPress is vulnerable to privilege escalation via account takeov… wordfence
b02ca3a1-4e85-4bc3-a5f6-a02bec6bddef
< 2.0.4
HIGH 8.8 In the Simple 301 Redirects by BetterLinks WordPress plugin before 2.0.4, a lack of capability checks and insufficient n… wordfence
b01ee276-baed-4678-894d-1407e538a0a3
< 1.0.9
HIGH 8.8 The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. wordfence
aff4d42c-133e-4ca8-9664-6878a22f7058
< 3.0.8.1
HIGH 8.8 The custom-sidebars plugin before 3.0.8.1 for WordPress has CSRF. wordfence
afd7aeb7-2c6f-4b23-b8b1-52fb010e5aac
< 1.1.1
HIGH 8.8 The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc… wordfence
afd4f2ca-9c27-4de0-ac82-3cd107b6a092 HIGH 8.8 The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insuff… wordfence
afcfacab-4847-4394-9f85-83dbaeed0857
< 3.9
HIGH 8.8 The Red Art theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.8 via deserial… wordfence
afc00118-e87e-475a-8ad6-b68d09ee2e44 HIGH 8.8 The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versio… wordfence
afa44a28-2368-4c52-b234-309476526290 HIGH 8.8 The eewee admin custom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu… wordfence
af7d935b-05a2-4eaa-af98-4e6a88abab46
< 3.2.6
HIGH 8.8 The acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordP… wordfence
af6bd2db-47a4-4381-a881-d5f97a159f8d HIGH 8.8 The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.5.3 due to … wordfence
af67a544-daff-469f-a66b-e998b79b7845
< 1.1.6
HIGH 8.8 The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
af4b659b-6a14-46bc-9ffe-6f118c6b1e8d
< 4.3000000024
HIGH 8.8 The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads throu… wordfence
af2d004f-fa9e-4e26-a1e3-03fb31cb95c4
< 8.6.2
HIGH 8.8 The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
af075ffe-553a-4351-a696-5c678788f3b9
< 4.9.3.4
HIGH 8.8 The Slimstat Analytics plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in versions up … wordfence
aee4fb6f-8ee6-4d6e-8167-876c9453f78f
< 1.2.6
HIGH 8.8 The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 1.2.6. This is due to m… wordfence
aed40456-43c3-4647-9bce-e7c6139c84cd
< 2.3.5
HIGH 8.8 The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… wordfence
ae81917e-0367-4c64-9254-fd74751ada48
< 3.5.1.11
HIGH 8.8 The Smart Slider 3 plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5.1.9 … wordfence
ae741363-b0aa-4263-bb49-d3baa213167a
< 1.14
HIGH 8.8 The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF. wordfence
ae4c7354-b179-43d7-8a41-0f54dc855fd3
< 4.0.13
HIGH 8.8 The Post Snippets – Custom WordPress Code Snippets Customizer plugin for WordPress is vulnerable to Remote Code Execut… wordfence
ae4a8e70-6b94-428f-8672-407dc4cd2f3f HIGH 8.8 The Peter’s Collaboration E-mails WordPress plugin through 2.2.0 is vulnerable to CSRF due to missing nonce checks. Th… wordfence
ae39fac4-6b65-42a6-bd34-c364922ef675
< 2.11.16
HIGH 8.8 The Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking plugin… wordfence
ae397949-12d2-4323-871e-4fd4f14f35c6
< 0.5.1
HIGH 8.8 The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise an… wordfence
ae201118-bacf-4849-92f5-569cef57ee30 HIGH 8.8 The AI Mortgage Calculator plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, … wordfence
← Prev 139 140 141 142 143 144 145 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top