πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 151 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
9a03f2dc-21c4-44e9-b7bf-8d4420430466
< 11.12.24
HIGH 8.8 Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote … wordfence
99e64e62-d09e-4b94-a982-12630fd2e946 HIGH 8.8 The KONTXT Improves WordPress Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,… wordfence
99db7ac5-b7ac-4a4f-bd05-e563a3dfb839
< 1.6.0
HIGH 8.8 The RESTful Content Syndication plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type va… wordfence
999115b1-8bac-4323-ba55-4e8a6df632e8 HIGH 8.8 The FAT Event Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1. Thi… wordfence
9965ea42-56c4-4ec9-9159-d971e913469e HIGH 8.8 An editid GET parameter of the Cashtomer WordPress plugin through 1.0.0 is not properly sanitised, escaped or validated … wordfence
9939f297-e3ca-4d7d-9acd-c416ee2014c9
< 2.4.7
HIGH 8.8 The WooODT Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec… wordfence
992b362b-b01f-4c91-83ac-dd612b93ee03
< 26.6
HIGH 8.8 The Woocommerce Customers Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, an… wordfence
98df8fbb-51c3-4b6c-8f99-56abfe11447e
< 1.3.2
HIGH 8.8 The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter. wordfence
98df88f8-5aeb-4f57-8525-6a9357173b1d
< 1.6.5
HIGH 8.8 The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vul… wordfence
98cb9fdd-d01d-4ad2-a617-6c0da702e8fd
< 3.2.1
HIGH 8.8 The Advanced Classifieds & Directory Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up t… wordfence
98c1363e-b25d-46fc-b6bf-0285a37f748c
< 8.2.4
HIGH 8.8 The WoodMart plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.2.3 via … wordfence
989f0e0b-8a57-4435-95b0-21fec215112d
< 4.1.4
HIGH 8.8 The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio… wordfence
9864507c-c09c-413c-ba5a-18792ba7598f
< 5.2.2
HIGH 8.8 The μ›Œλ“œν”„λ ˆμŠ€ 결제 μ‹¬ν”ŒνŽ˜μ΄ plugin for WordPress is vulnerable to Local File Inclusion in versions up to, an… wordfence
9829ec10-ad37-4345-b4d6-cd0429b2d8f7
< 2.1.6
HIGH 8.8 The Booking Manager plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode attributes in all ver… wordfence
98286172-99b0-43d6-9876-972e270aa19f
< 2.2
HIGH 8.8 The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.… wordfence
9826c91c-0f6e-4d3b-bc14-4af6b60ef246
< 1.5.113
HIGH 8.8 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based … wordfence
97f1b126-5056-496e-b5fb-49e777392233 HIGH 8.8 The Marketing Automation by AZEXO plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type … wordfence
97c441c3-ae8b-4b7a-8480-da81c0f339ab HIGH 8.8 The Donate With QRCode plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
97a3fc27-4b58-400a-b831-6423e3de5cb7
< 4.9
HIGH 8.8 WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remot… wordfence
9799df3f-e34e-42a7-8a72-fa57682f7014
< 2.3
HIGH 8.8 The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in ve… wordfence
974b9211-04e4-4309-8a7b-aeccc5b55ce7 HIGH 8.8 The wordpress-meta-robots plugin through 2.1 for WordPress has wp-admin/post-new.php text SQL injection. wordfence
97460a9c-e996-4170-afa3-47db9097f3f4
< 3.0.1
HIGH 8.8 The Feed Them Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
9742a4d0-34b0-4f7f-aa2b-a6f7cb6aacd4
< 2.0.7
HIGH 8.8 The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site reques… wordfence
9711efe5-dd9b-4451-9bc4-22c8a5095cd8 HIGH 8.8 The Mortgage Calculator Estatik plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and includ… wordfence
96f149a9-cf2e-49b7-8a5f-e87d3e5209ca
< 1.1.3
HIGH 8.8 The JetGridBuilder β€” Grid Builder for Elementor and Gutenberg plugin for WordPress is vulnerable to Local File Inclusi… wordfence
← Prev 148 149 150 151 152 153 154 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top