🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 147 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a4204099-1065-4167-8b42-3da25945236c
< 2.2
HIGH 8.8 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Insecure Direct Object… wordfence
a414de0a-ae44-4955-bd25-ec6ad7860835
< 2.4.45
HIGH 8.8 The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension va… wordfence
a4059a0b-1446-4711-a47d-eb0107d58900
< 1.4.2
HIGH 8.8 The Best Restaurant Menu by PriceListo plugin for WordPress is vulnerable to SQL Injection in versions up to, and includ… wordfence
a401a2dd-9b31-47d9-b841-f2e7042b8333
< 2.2.3.1
HIGH 8.8 The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin… wordfence
a3e54f9b-db12-42ef-a0fa-2d40c0f7908c
< 1.2.7
HIGH 8.8 The JVM Gutenberg Rich Text Icons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and i… wordfence
a3e34ec7-eeb2-4966-bac3-c7d4723355d7
< 1.9.9.149
HIGH 8.8 The Better Messages plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1… wordfence
a3cd1c3e-5bb0-4653-8764-2ca38d9a7c77
< 1.5.0
HIGH 8.8 The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable… wordfence
a37e2106-1590-4a40-ae68-172d3817b063
< 1.1.19
HIGH 8.8 The Creator LMS – Online Courses and eLearning Plugin plugin for WordPress is vulnerable to Privilege Escalation in al… wordfence
a331c3c7-3d78-4973-919c-066ad1658a29
< 2.1.2
HIGH 8.8 The The Pack Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includin… wordfence
a3311097-d477-441e-9bf3-3f991a9b6af9
< 1.4.11
HIGH 8.8 The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all version… wordfence
a321b112-ce37-4a0e-800f-f3feef6ac799
< 2.1.13
HIGH 8.8 The Post Grid plugin for WordPress is vulnerable to blind SQL Injection via post metadata in versions up to, and includi… wordfence
a3178ed8-568c-4439-9e4b-975fc60e591b
< 2.8.0
HIGH 8.8 The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to privilege e… wordfence
a313f4d0-fd9e-47f1-99eb-351a2aff9bea
< 2.0.6
HIGH 8.8 The wpForo Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.… wordfence
a2e802a6-d2f1-47cc-883a-89110e569168
< 7.0.11
HIGH 8.8 The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_… wordfence
a2e0c425-91d2-4adc-8a3b-71ad2be54f5a
< 2.1.18.1
HIGH 8.8 The JetWooBuilder plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.18. T… wordfence
a2d9a568-9a0a-48bb-97ae-6f6920c67eec HIGH 8.8 The Absolute Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and incl… wordfence
a2d87a05-81a7-40d9-a60f-94a4d88bf87a
< 4.0.3
HIGH 8.8 The MainWP Code Snippets Extension for WordPress is vulnerable to code injection in versions up to, and including, 4.0.2… wordfence
a2cd027b-fbaa-41ce-8822-2fa16aa93eb5
< 2.0.3
HIGH 8.8 The PHP Everywhere plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.… wordfence
a29b5972-36c9-4477-ad16-d89a2e9bd9f7
< 3.1.0
HIGH 8.8 The WordPress Contact Form 7 PDF, Google Sheet & Database plugin for WordPress is vulnerable to arbitrary file uploads d… wordfence
a29832db-f85f-475b-8671-3d2115f33f19
< 3.5.9
HIGH 8.8 The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gute… wordfence
a2874a5f-71f4-4bcd-87e8-a20bb19a5847
< 6.1
HIGH 8.8 The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi… wordfence
a26473b9-8cc1-47e6-a3d3-4ebf1f9e902a
< 3.0.8
HIGH 8.8 The Visual Form Builder WordPress plugin before 3.0.8 does not enforce nonce checks which could allow attackers to make … wordfence
a22b2724-2541-4345-bd42-e8a5844f3f0a
< 1.2.2
HIGH 8.8 The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable… wordfence
a21df06c-4e56-4625-ae8b-89c9fc046939
< 1.8.2
HIGH 8.8 The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_… wordfence
a20c9a22-53a8-4885-8840-2788934e1a05
< 1.0.4
HIGH 8.8 The Blogmatic theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all ver… wordfence
← Prev 144 145 146 147 148 149 150 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top