πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 149 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9e9cfb9b-6951-4246-9cd6-dd64fee3a1bc HIGH 8.8 The Account Switcher plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… wordfence
9e991342-b0d1-486c-a24d-e4d3f2be9b91
< 6.4.4
HIGH 8.8 The Nasa Core plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 6.4.4. This m… wordfence
9e3e996b-6988-42ab-9766-ddc070243c1f
< 1.0.4
HIGH 8.8 The Easy Username Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includ… wordfence
9e15727a-35c4-42c0-9997-cdcd40ac8e5f HIGH 8.8 A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to unauthorized plugin de… wordfence
9e0d441d-1da5-45e7-8a14-ce178099c0cc
< 4.0.35
HIGH 8.8 The Eventin plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i… wordfence
9e0cba5b-5833-4c02-ac17-830994b0f207
< 1.9.31
HIGH 8.8 The Vikinger theme for WordPress is vulnerable to privilege in all versions up to, and including, 1.9.30. This is due to… wordfence
9df24b5e-109e-43ae-b55b-8514281a631f
< 2.1
HIGH 8.8 The Favicon Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
9dd1e52c-83b7-4b3e-a791-a2c0ccd856bc
< 7.6.6
HIGH 8.8 The wpDiscuz plugin for WordPress is vulnerable to SQL Injection via the 'visibleCommentIds' parameter in versions up to… wordfence
9dbaafbb-ab7b-41d8-a8f7-178b9d42b4c5
< 9.2
HIGH 8.8 The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions 8.3 to 9.1.2. Thi… wordfence
9d979950-d365-4750-a4f1-df9335d3452d
< 1.6.4
HIGH 8.8 The Qi Addons For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ… wordfence
9d866870-dff4-44c0-b1ee-781370f7e8ae
< 2.4.2
HIGH 8.8 The EventON plugin for WordPress is vulnerable to Local File Inclusion via the evo_block_render_callback() function in v… wordfence
9d72a965-5d81-4619-ad8b-46960a89bf1b
< 3.1.2
HIGH 8.8 The Survey Maker plugin for WordPress is vulnerable to SQL injection in versions before 3.1.2 via the 'ays_surveys_expor… wordfence
9d47df99-cff5-4be7-ab8e-ef333cf3755b
< 3.0.9
HIGH 8.8 The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of da… wordfence
9d387a5c-717c-4383-af7d-5a5f48628cb7
< 2.4
HIGH 8.8 Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptc… wordfence
9d2dde9f-c3c3-4e6e-a7e2-a0e511bff010
< 57.0
HIGH 8.8 The School Management System for Wordpress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions … wordfence
9d15e418-36bb-4f53-ac67-8f6122591dd2
< 4.0.2
HIGH 8.8 The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1.… wordfence
9cfd5cfa-9075-4408-bfb1-fb0c3494f61e
< 1.4.5
HIGH 8.8 The Hero Banner Ultimate plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.… wordfence
9cd2ca03-e644-4bcd-b4b1-a547494fed7d
< 2.2.6
HIGH 8.8 The Booked plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on several functi… wordfence
9ccdf08b-8b74-4b58-8779-3b07ef2d7b2f
< 2.1.7
HIGH 8.8 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th… wordfence
9cae7702-e531-45b9-9131-42edbc073a07
< 6.5.6
HIGH 8.8 The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vuln… wordfence
9c97283b-404d-4138-b8a1-057f068e3564
< 3.5.29
HIGH 8.8 The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.5.28.… wordfence
9c7cf6f9-6fd0-487f-93cf-516b52736512
< 1.1
HIGH 8.8 The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value. wordfence
9c32fcaf-afc3-4493-8cd8-6f49bbe40c7b
< 1.5.9
HIGH 8.8 The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions… wordfence
9c17d18a-090f-4b35-a257-cfc0a16d5459 HIGH 8.8 The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… wordfence
9bed2e86-1cc0-4fed-a44f-0c495c423e22
< 2.3.5
HIGH 8.8 The BuddyPress plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.3.4. This … wordfence
← Prev 146 147 148 149 150 151 152 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top