πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 146 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a6b91ec6-c669-4a92-ae12-b6829f349687
< 1.1.25
HIGH 8.8 The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Privilege Escalation in all ve… wordfence
a67eb1fc-4762-4bdc-b0a0-c043c36659d0
< 3.1.6
HIGH 8.8 The NextGen Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.1.5. … wordfence
a662c904-ba2e-494c-a603-b22eeeddf43d HIGH 8.8 The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missin… wordfence
a6484a7c-449d-40ea-a5aa-ca033ee0ba95
< 4.4.7
HIGH 8.8 The Church Admin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… wordfence
a646a582-7174-4172-a193-c1606c43e6a5
< 1.7.6
HIGH 8.8 The Responsive Poll plugin for WordPress is vulnerable to Cross-Site Request Forgery to Cross-Site Scripting in versions… wordfence
a6407792-2c76-4149-a9f9-d53002135bec
< 1.3.4
HIGH 8.8 The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.3 via a s… wordfence
a6298192-2afa-4468-86d5-8487321a0ff6
< 1.8.34
HIGH 8.8 The Sucuri Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
a620810d-1b2a-4f2e-943c-aacc493f0c5b HIGH 8.8 The Event Easy Calendar plugin for WordPress is vulnerable to Multiple Cross-Site Request Forgery in versions up to, and… wordfence
a6096b9a-f7bb-454a-8203-50ac99d37100
< 6.4.0
HIGH 8.8 The WP Affiliate Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
a6090c3d-e4ee-4c9d-9605-e18000f283c5
< 3.3.99
HIGH 8.8 The Zephyr Project Manager plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi… wordfence
a5bcf456-f991-4775-8c3e-a3c0212a5765
< 2.1.2
HIGH 8.8 The Kali Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.1.… wordfence
a5ba9285-9f41-44dd-83c7-e9c377d9de51
< 4.1.0
HIGH 8.8 The WP Google Map Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1… wordfence
a59f7a1b-ae58-4015-bb77-814707579847
< 4.0.27
HIGH 8.8 The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress … wordfence
a550e489-904b-4785-b6f3-992b7dfe5bd2
< 2.6.8
HIGH 8.8 When deleting a date in the Xllentech English Islamic Calendar WordPress plugin before 2.6.8, the year_number and month_… wordfence
a522fb0b-ce75-4593-90dd-f7c04d2ba9e0
< 2.5.0
HIGH 8.8 The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did … wordfence
a5155cee-df51-4da3-be86-38df2ab9908f
< 1.0.2
HIGH 8.8 The WP Mail Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1… wordfence
a501c2d6-cdcc-4003-99df-245f5253e20f
< 3.3.0
HIGH 8.8 The Aeropage Sync for Airtable plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type val… wordfence
a4f2112f-d5dc-4045-ac58-3895d6ac7179 HIGH 8.8 The PHP Execution plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0… wordfence
a4e7f51c-5f44-4d01-8865-9d86067374ec
< 12.1.11
HIGH 8.8 The SEO Plugin by Squirrly SEO for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1… wordfence
a4c1f966-aa10-45cc-9fb0-2e703dd3098e
< 2.10
HIGH 8.8 The Album and Image Gallery with Lightbox – Flagallery Photo Portfolio plugin for WordPress is vulnerable to SQL Injec… wordfence
a4999de1-07b7-49ef-8897-267b836bc469
< 5.10.2
HIGH 8.8 A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 … wordfence
a46cd288-5272-4e6c-b01a-f26eb7081168
< 1.3.2
HIGH 8.8 The Solace Extra plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… wordfence
a449d1eb-badb-41ca-a4b1-ae230a46dcde
< 3.4.5
HIGH 8.8 The Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder plugin for WordPress is v… wordfence
a437e3ac-5428-4820-8037-8592b86e0dd5
< 3.0
HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the configuration page in the Recaptcha (aka WP-reCAPTCHA)… wordfence
a4219c10-9d2a-429d-9ac7-61efc02bd4cf
< 1.2.3
HIGH 8.8 The Management App for WooCommerce – Order notifications, Order management, Lead management, Uptime Monitoring plugin … wordfence
← Prev 143 144 145 146 147 148 149 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top