πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 154 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
91e61664-3b98-4a97-b35c-1ec88034d05b
< 3.7.17
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the widget-editing accessibility-mode feature in WordPress before 4.7… wordfence
91c147f9-8179-4ce0-8d17-87ea47cf08fe
< 3.0.21
HIGH 8.8 The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC… wordfence
91aa1f4c-ace7-43a4-a9e6-82c15e00d0eb HIGH 8.8 The Inline Google Maps WordPress plugin through 5.11 does not have CSRF check in place when updating its settings, which… wordfence
91998552-bf97-40e0-b5b2-be35a8d58b54
< 2.4
HIGH 8.8 pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot… wordfence
916e6f8b-cb29-4062-9a05-0337cfdb382a
< 4.1
HIGH 8.8 The WP Replicate Post plugin for WordPress is vulnerable to SQL Injection via the post_id parameter in versions up to, a… wordfence
914e17ce-ab09-4e9f-9466-0ed21712cf66
< 1.5.50
HIGH 8.8 The Events Made Easy plugin for WordPress is vulnerable to Cross-Site Request Forgery to Stored Cross-Site Scripting in … wordfence
91417d83-b645-4072-92f5-e0f3a398ac95 HIGH 8.8 The Eximius theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versi… wordfence
9133fa10-036b-4f42-9d0c-8e15d2625f5e
< 3.0.0
HIGH 8.8 The a3 Lazy Load, a3 Portfolio, Contact Us Page – Contact People, Dynamic Product Gallery for WooCommerce, a3 Responsi… wordfence
910c3d74-63ed-476d-b014-659d7780260f
< 1.1.19
HIGH 8.8 An issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.p… wordfence
90bab2a1-7c19-45d2-909f-05014fb24740
< 1.09
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the underConstruction plugin before 1.09 for WordPress allows remote … wordfence
90783d75-a255-4133-ac7b-32e0a70c8c69
< 3.1.2
HIGH 8.8 The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to,… wordfence
9077bdce-31c9-4877-8bb5-db87046125cc
< 5.2
HIGH 8.8 The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker to make a logged in ad… wordfence
90752679-4b21-4db7-89f4-19a1b2adb914
< 4.2.4
HIGH 8.8 The Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets plugin for WordPress is vu… wordfence
90465354-0174-4f85-a66b-589d9408c3c8 HIGH 8.8 The Delhivery Logistics Courier plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.… wordfence
8fd1de2b-bb88-4f7c-b9eb-784eb7af17a6 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote … wordfence
8fc28132-eae6-4082-988c-2d9e56ff1283
< 9.5
HIGH 8.8 The Easy Social Share Buttons for WordPress plugin for WordPress is vulnerable to Local File Inclusion in all versions u… wordfence
8fb7dc15-45e6-4209-a4c6-34c9c268e17b
< 1.3.1
HIGH 8.8 The Subscribe to Unlock Lite plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
8f9db3b8-dd37-4d8b-b041-50b453858a39
< 5.6.4
HIGH 8.8 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Es… wordfence
8f64361a-e5b5-4481-b25c-bdffeb80c198
< 5.0.6
HIGH 8.8 The Genolve – AI image AI video generation plugin for WordPress is vulnerable to unauthorized modification of data due… wordfence
8f5722b0-0d54-4c44-b168-a886da1077cb HIGH 8.8 The Browse As plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.2. This is… wordfence
8f53a8d1-e7d6-4085-a1e6-f4263ec341b6
< 1.8.1
HIGH 8.8 The Progress Planner plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege … wordfence
8f4a9f9f-a342-4053-b4e0-cbaa9796e4ba
< 2.3.9
HIGH 8.8 Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem… wordfence
8efa8e86-6260-484a-a6da-18574bf41ed9 HIGH 8.8 The Dynamic Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including… wordfence
8e926708-3c7f-4d7b-a64b-209f696984f9
< 3.1.17
HIGH 8.8 The Classified Listing plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.1.… wordfence
8e50c519-7d79-4270-92e8-75e54bb08cff
< 7.1.2
HIGH 8.8 The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempo… wordfence
← Prev 151 152 153 154 155 156 157 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top