πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 143 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
adfd506e-7b47-4aeb-a21e-034624210574 HIGH 8.8 The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to arbitrary file uploads due t… wordfence
adf51c03-b0bb-4864-b64d-6b0cba4b0130 HIGH 8.8 The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and includin… wordfence
adeb4e0b-13fe-4f80-9b24-62bf2a057ead
< 2.0.5
HIGH 8.8 The Password Policy Manager | Password Manager plugin for WordPress is vulnerable to privilege escalation via account ta… wordfence
ada52ae9-7d14-405d-9efc-b993ea273a26
< 2.7.2
HIGH 8.8 The Woody Code Snippets – Insert PHP, CSS, JS, and Header/Footer Scripts plugin for WordPress is vulnerable to Remote … wordfence
ad8dff1e-b9f8-4383-8efb-8bceaa8c86c6
< 3.0
HIGH 8.8 The Mediamatic – Media Library Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up… wordfence
ad66015d-7831-4590-9583-3abf7ca43c3b
< 3.2.5
HIGH 8.8 The JetEngine plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.2.4. Th… wordfence
ad5aeea0-ba5a-488a-9087-9b7567f31c70
< 8.1.4
HIGH 8.8 The WP Customer Area plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
ad2e1d91-03bd-4e47-b679-81c42414238b
< 4.6.4
HIGH 8.8 The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and incl… wordfence
acff00f2-586d-474c-8dec-f27c488e9045
< 15.0.2
HIGH 8.8 The cforms2 plugin before 15.0.2 for WordPress has CSRF related to the IP address field. wordfence
acf1e98a-9e9d-453d-afce-6e47fce3a2d2
< 4.3.1
HIGH 8.8 The wp-database-backup plugin before 4.3.1 for WordPress has CSRF. wordfence
acbea2eb-fa87-4117-b347-049c819599c7
< 2.4.1
HIGH 8.8 The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() functi… wordfence
aca8482e-7a5b-4f2d-965c-a1184fb6a374
< 2.0.0
HIGH 8.8 The Voice Feedback – Voice Recorder for Audio Feedback plugin for WordPress is vulnerable to Privilege Escalation in a… wordfence
ac53f2b6-85fe-4475-975f-6dbd15fa87f4 HIGH 8.8 The PDF 2 Post plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.0. … wordfence
ac4de440-a446-4b96-ba9b-115e3186ce1c HIGH 8.8 TechyTalk Quick Chat WordPress Plugin All up to the latest is affected by: SQL Injection. The impact is: Access to the d… wordfence
ac4c6bd8-179f-4553-b1b4-549300bae374
< 2.2.1
HIGH 8.8 Unrestricted file upload vulnerability in WordPress before 2.2.1 and WordPress MU before 1.2.3 allows remote authenticat… wordfence
ac23cd7d-193d-4fa1-8c1c-79ca92da98d7 HIGH 8.8 The User Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2… wordfence
ac1c4818-6384-48cf-a1e3-a8ced6884749
< 2.2.4
HIGH 8.8 The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints … wordfence
abb10680-6208-44c8-8cf0-8d2531465a04
< 1.0.27
HIGH 8.8 The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
ab796de7-2bc6-4e25-be00-25d0941045fb
< 1.5.5
HIGH 8.8 The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to Cross-Site Request Forg… wordfence
ab770acd-9420-4201-9e67-dfea86dba168
< 12.2
HIGH 8.8 The WP Review Slider plugin for WordPress is vulnerable to SQL Injection via the $tid value in versions up to, and inclu… wordfence
ab520bcb-5739-4b99-ad93-73416ab39084
< 1.2.2
HIGH 8.8 The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
ab248283-e331-4159-9fe4-249243772c9b HIGH 8.8 The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls,… wordfence
aadf1f4c-c852-4167-9b09-7e679a953725
< 8.3.5
HIGH 8.8 The WP Customer Area plugin for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file pat… wordfence
aab16b6f-4daf-4eb1-9526-dd05b2b41dee
< 2.85.5
HIGH 8.8 The MapPress Maps for WordPress plugin for WordPress is vulnerable to SQL Injection via the get_maps function in version… wordfence
aa9ba135-3b08-4ee9-9a06-3c9880bfdd18 HIGH 8.8 The Insurance theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.5 via deseri… wordfence
← Prev 140 141 142 143 144 145 146 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top