ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 152 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
96b8186c-dfe9-4137-b28d-cc09a25aa9ac
< 2.6.1
HIGH 8.8 The WPshop 2 – E-Commerce plugin for WordPress is vulnerable to privilege escalation via account takeover in versions … wordfence
96b5a1d3-57f7-46da-919d-b4344421bf94
< 1.3.1
HIGH 8.8 The Bravis Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in al… wordfence
96a0ca0c-7cd5-4be4-a833-fc15fff62362
< 6.1.6
HIGH 8.8 The Advanced Page Visit Counter WordPress plugin through 6.1.5 does not escape the artID parameter before using it in a … wordfence
9687e8e5-add1-477d-9cb7-f94b8af10da5
< 4.8
HIGH 8.8 The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refU… wordfence
9687a88f-ac5b-4746-a68c-91c358b5fb87 HIGH 8.8 The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat… wordfence
96844c67-671b-4159-a6fd-a91eadde6cbe HIGH 8.8 The Job Board Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.6… wordfence
9669fbae-cf7a-4715-a1f3-cdbbb1c1cedd
< 1.3.9
HIGH 8.8 The WPSection plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8 via… wordfence
96608c76-6dfd-4ff8-b114-070ff6706214
< 4.19
HIGH 8.8 The Ajax Search Pro plugin for WordPress is vulnerable to SQL Injection via the ‘p_blogid’ parameter in versions up … wordfence
9646cfdc-1cf4-4785-8b3e-86143658c149
< 1.3.4
HIGH 8.8 The Lawyer Directory plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… wordfence
963cb544-165e-4378-9844-753c72bf2274
< 2.2.28
HIGH 8.8 The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is… wordfence
96388c82-2392-42b3-b0a0-c3d92910fb5c
< 4.1.10
HIGH 8.8 The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and includin… wordfence
96288db4-2758-4562-8b26-0523926c9156
< 3.2.3
HIGH 8.8 The Rencontre – Dating Site plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
9622c839-a1dd-4633-8a9c-cec41d1041ff
< 2.1.15
HIGH 8.8 In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via… wordfence
96192fdc-e9fe-403f-b233-28faa497a5c4 HIGH 8.8 The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to Privilege Escalation due … wordfence
96170b82-6ed9-4a52-8592-944163cdd3cf
< 2.3.6
HIGH 8.8 The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
95e74e70-9dc9-4e63-b371-fd2a38692907 HIGH 8.8 The Woocommerce Multiple Addresses plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and… wordfence
95e4163d-e9fc-4470-91bb-a408a35d5113
< 1.3.7.1
HIGH 8.8 The HUSKY plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.7. This makes… wordfence
95624a3b-70cc-4815-a604-c6b19fc84e93
< 5.1.5
HIGH 8.8 The Avada theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.1.4. This … wordfence
95269053-59fa-4396-bd2b-c8c4f9c05595
< 0.9.9
HIGH 8.8 SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remo… wordfence
95247ff5-0277-4270-a1ea-221ea2ecee0c
< 1.7.17
HIGH 8.8 The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includ… wordfence
951e3497-8fbc-4cc9-a784-edf7bb679175
< 6.6.19
HIGH 8.8 The Slider Revolution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 6.6.19 (exclusive… wordfence
94e17808-9eb7-4a4d-8287-30d571df0f77
< 2.4
HIGH 8.8 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Privilege Escalation i… wordfence
94d8211d-4027-4335-8c06-d8080231e511
< 1.1
HIGH 8.8 WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter. wordfence
94bef2d7-3f71-4231-bc54-c9120ccc779e
< 5.00
HIGH 8.8 The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t… wordfence
94ab250a-387c-431e-9b75-16ede94bf0ef
< 1.4.1
HIGH 8.8 The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 v… wordfence
← Prev 149 150 151 152 153 154 155 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top