🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 145 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a86301cd-1268-4168-a8e7-6946711dc256
< 5.9
HIGH 8.8 The WPQA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, but not including, 5.9. Thi… wordfence
a8540a39-87e4-4a78-abf2-c7e09dbfa4f9
< 3.9
HIGH 8.8 The 3D Tag Cloud plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.8.… wordfence
a8526106-847a-420f-9275-f759a8dd4dfb
< 1.0.8
HIGH 8.8 The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1… wordfence
a83def40-27fa-4141-bebf-f86944e4c618 HIGH 8.8 Due to missing checks the Static Page eXtended WordPress plugin through 2.1 is vulnerable to CSRF attacks which allows c… wordfence
a833fe01-caf5-434a-82f9-8d3ac755a66f HIGH 8.8 The Easy Bet plugin for WordPress is vulnerable to generic SQL Injection via multiple parameters in versions up to, and … wordfence
a827cea5-e8c2-47dd-81d7-e3700c19c8da HIGH 8.8 The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escal… wordfence
a82769ae-84b2-45e3-a637-c98e0c0e77a9
< 2.4.4
HIGH 8.8 The wpForo Forum plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.3.… wordfence
a816e5a8-2494-4bcf-869d-5214b21f7791
< 4.4.1
HIGH 8.8 The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, … wordfence
a7f82847-433d-49b1-815d-b0d9e70068c2
< 1.2.6
HIGH 8.8 The Instantio – WooCommerce Quick Checkout | Instant Checkout, Side Cart & Popup Cart plugin for WordPress is vulnerab… wordfence
a7d5e21e-8046-42bd-9c11-998d0d1bd822 HIGH 8.8 The WPAMS - Apartment Management System for wordpress plugin for WordPress is vulnerable to Privilege Escalation in all … wordfence
a7c31409-c84a-4197-b08c-b70df5e66a80
< 27.5.7
HIGH 8.8 The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via d… wordfence
a7af1a03-8382-4593-a41f-8cdb1bb9e53b
< 3.16
HIGH 8.8 The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver… wordfence
a7ac96db-2d9a-4eaf-8916-a02e3e64ca4a
< 3.5.3
HIGH 8.8 The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ … wordfence
a7a61446-a5ef-44e4-bd64-9c2e844953fb HIGH 8.8 Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks.… wordfence
a772041e-015e-48e8-9fab-79f1fcdb265c
< 1.10.3
HIGH 8.8 The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver… wordfence
a76dcb33-4c6b-44dc-9b27-6daf4f0a1376 HIGH 8.8 The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d… wordfence
a758fcbe-1be0-4845-9ce9-795f3e5c4bd8
< 1.2
HIGH 8.8 The sendpress plugin before 1.2 for WordPress has SQL Injection via the wp-admin/admin.php?page=sp-queue listid paramete… wordfence
a743a2c5-61ba-43d4-bbc3-0f82969be78f
< 9.2.0
HIGH 8.8 The Xelion Webchat plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.… wordfence
a7372314-fff1-42c4-99b6-10d7541d1a29
< 2.1.5.1
HIGH 8.8 The Wholesale Suite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2… wordfence
a71d13b2-5c0b-4e19-b1b3-b97a996d4019 HIGH 8.8 The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which c… wordfence
a6fda35d-8b82-4a7a-8db6-21dc38a841f4
< 1.16.3
HIGH 8.8 The WP Githuber MD – WordPress Markdown Editor plugin for WordPress is vulnerable to arbitrary file uploads in all ver… wordfence
a6dde21f-f747-4a80-a5eb-c4af847fbfc7 HIGH 8.8 The WP Super Edit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
a6d9d093-1e31-4d36-ac55-79cf82b231bb
< 2.5.16
HIGH 8.8 woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerabilit… wordfence
a6d4e207-9751-4c97-b004-e97c69af81dd
< 2.0.0
HIGH 8.8 The Asgaros Forum WordPress plugin before 2.0.0 does not sanitise and escape the post_id parameter before using it in a … wordfence
a6ca0a45-cbb3-419b-a2fd-7427935524d8 HIGH 8.8 The Royal Core plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escala… wordfence
← Prev 142 143 144 145 146 147 148 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top