🛡️ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 148 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
a20b4870-2ef0-4932-a0e3-39876ce4b10c HIGH 8.8 The Blogzee theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
a1d4df4b-ec7a-43f6-8617-161b1600d6d2
< 1.4.3
HIGH 8.8 The Houzez CRM plugin for WordPress is vulnerable to time-based SQL Injection via the notes ‘belong_to’ parameter in… wordfence
a1c4c632-66f2-4987-b7da-048dbe4a3044 HIGH 8.8 The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the … wordfence
a1ae2060-5eca-47c9-a196-0ff75c3f523e
< 6.1.5.0
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows rem… wordfence
a18fa7e6-813d-4b48-bd4e-5232fb8382d1
< 16.7
HIGH 8.8 The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c… wordfence
a18089d8-32f1-4827-af14-c45055892fb2 HIGH 8.8 The jQuery Reply to Comment WordPress plugin through 1.31 does not have any CSRF check when saving its settings, nor san… wordfence
a1264108-6b96-4e17-bac8-4957a615f0b9
< 2.4.19.1
HIGH 8.8 The WP Multilang plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.4.19. Th… wordfence
a11f264a-24fe-44da-b325-3fbdc4cd81d0
< 2.8.1
HIGH 8.8 The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authentic… wordfence
a114faf9-cada-4132-abe3-c0137b66e276
< 7.19.1
HIGH 8.8 The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file uploads due to mis… wordfence
a0b1e907-0c31-4b40-b3f9-0ac665f3394a HIGH 8.8 The Smartkit plugin for WordPress is vulnerable to Cross-Site Request Forgery via the show_smartkit_menu() function in v… wordfence
a09298b3-3b5c-4a92-9332-79ff83234479
< 3.2.0
HIGH 8.8 The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via s… wordfence
a07a643e-1a4b-47fe-9e4a-b4cc070bce74
< 1.1.5
HIGH 8.8 The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF. wordfence
a058e6bf-109f-4985-8aad-08858553c4c3 HIGH 8.8 The WordPress Review Plugin: The Ultimate Solution for Building a Review Website plugin for WordPress is vulnerable to L… wordfence
a041f15c-0e30-459b-8df7-0465c0bc268a
< 6.9.1
HIGH 8.8 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation … wordfence
a0164123-11b0-4b3b-bc76-c6aee8ca9d34
< 2.0.4
HIGH 8.8 The Nexter theme for WordPress is vulnerable to SQL Injection via the 'to' and 'from' parameters in versions up to, and… wordfence
9fe78766-0beb-4d6d-a2e6-92f79f117f50 HIGH 8.8 The Pont theme for WordPress is vulnerable to arbitrary option updates due to a missing capability check on the of_ajax_… wordfence
9fc4b26a-cb76-4b2c-adad-62e21263b957
< 6.5.1
HIGH 8.8 The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to PHP Object Injection in all v… wordfence
9fa3f24e-3e28-4e50-8801-e4f0a089e3a1
< 2.6.01
HIGH 8.8 The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php. wordfence
9f9e5212-caed-46db-bbf2-81c4df88439f
< 3.2.7.3
HIGH 8.8 The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection in versions up to, and inclu… wordfence
9f8575cb-0620-4db8-a5e9-0a7f115ee8fe HIGH 8.8 The Question Answer plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2.70 … wordfence
9f33096a-dfd5-48c1-84d8-30a0faa2a7f5 HIGH 8.8 The NewsBlogger theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 0.2.5.6 to 0.2.6.1. This is… wordfence
9f07d76e-1973-4ea7-b448-666466cd688f
< 4.5.5
HIGH 8.8 The WP Meta SEO plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 4.5.4 due t… wordfence
9ecaaa86-9de1-4b90-b6cf-885621cffb19
< 8.7
HIGH 8.8 The Ultimate Membership Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl… wordfence
9ec1aed2-d299-4fa9-add6-10b63ed6aa30
< 3.1
HIGH 8.8 The Meta Tag Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.… wordfence
9ec17c72-6426-4e7e-840d-f8c050a25460
< 6.5.0
HIGH 8.8 The Photo Engine (Media Organizer & Lightroom) plugin for WordPress is vulnerable to arbitrary file uploads due to missi… wordfence
← Prev 145 146 147 148 149 150 151 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top