🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 144 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
aa972bbc-2123-45d4-b313-1e53397a5dc1
< 5.6.83
HIGH 8.8 The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to unauthorized arbitrary pl… wordfence
aa916029-b526-4ff3-ba70-2875b62d33a6 HIGH 8.8 The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which c… wordfence
aa8f75dc-7ecd-498d-b41a-e788b4d4bcdd HIGH 8.8 Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote adm… wordfence
aa6b63bc-6e5f-498e-83e1-45e8e6c72df4 HIGH 8.8 The Task Manager Pro plugin for WordPress is vulnerable to blind SQL Injection via the 'task' parameter in versions up t… wordfence
aa64d6b4-5673-4d88-b5c7-d3441eaa0706 HIGH 8.8 The WP Popup Banners plugin for WordPress is vulnerable to a time-based SQL Injection via the 'value' parameter of the g… wordfence
aa55dfe1-7ee8-4d25-a9f6-cbefeebb1376
< 5.7.3
HIGH 8.8 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to boolean-based SQL Injection via the ‘model_n… wordfence
a9cc4dcf-7485-458c-8376-a19b2c32f8d6 HIGH 8.8 The iBryl Switch User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1… wordfence
a9b3b6cc-faaa-46c2-ab82-00c7138a8f27 HIGH 8.8 The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, … wordfence
a9af89a7-7d02-4656-a7b1-89f7a3555334
< 4.23.0
HIGH 8.8 The KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme theme for WordPress is vulnerable to arbitrary file uploa… wordfence
a971c80b-c71a-4c58-8291-c8918af034d9
< 2.0.4
HIGH 8.8 A lack of capability checks and insufficient nonce check on the AJAX action in the Simple 301 Redirects by BetterLinks W… wordfence
a95e98e4-97a7-436f-9ceb-6ff6fecd860f HIGH 8.8 The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu… wordfence
a9461354-0e69-47d9-a11c-838cfa94be67
< 1.3
HIGH 8.8 SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for Wo… wordfence
a929efaf-80a1-45c1-9426-6c5b45a66530
< 2.3.3
HIGH 8.8 The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerabl… wordfence
a928247a-3eb5-4889-bd42-b0263f4cd140
< 5.2.2
HIGH 8.8 The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file… wordfence
a908ac17-666f-4725-86f4-c9af4589fb69
< 2.8.22
HIGH 8.8 The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the order data edit page in versions up t… wordfence
a8f31b4b-c8d8-4028-b419-f8396a5cb2a9
< 1.0.34
HIGH 8.8 The wp_ajax_upload-remote-file AJAX action of the External Media WordPress plugin before 1.0.34 was vulnerable to arbitr… wordfence
a8eb3ec8-0784-4702-86bf-a621b288e7a0 HIGH 8.8 The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all ve… wordfence
a8e8d724-60fe-4333-8c55-cb7df0d4345d
< 3.3.3
HIGH 8.8 The ubenda plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.3.2. This is d… wordfence
a8b10d0c-e2fc-47a3-9df9-8df58eee964c
< 4.0.7
HIGH 8.8 The MStore API plugin for WordPress is vulnerable to SQL Injection via the $name and $search variables in versions up to… wordfence
a8a67cad-b52d-4294-9c27-13b1dc1f2e59
< 1.6.0
HIGH 8.8 The Creative Mail plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5… wordfence
a895e2cf-9eba-4c46-b19f-d008e1058f64
< 10.8.2
HIGH 8.8 The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and includi… wordfence
a88e8853-3a52-462b-bde8-658a794545dc
< 1.4.0
HIGH 8.8 The Comment License WordPress plugin before 1.4.0 does not have CSRF check in place when updating its settings, which co… wordfence
a8742e30-e49c-46c9-92d5-216d32d00d51 HIGH 8.8 The YDS Support Ticket System plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
a86d196f-9613-4352-8a96-87ea147eb1c8 HIGH 8.8 The Scroll Baner WordPress plugin through 1.0 does not have CSRF check in place when saving its settings, nor perform an… wordfence
a868226f-4ca1-4ec1-b55e-3029e3ed2d5b
< 2.3.4
HIGH 8.8 The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3… wordfence
← Prev 141 142 143 144 145 146 147 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top