πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 155 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8e25914f-f2c6-4224-a2f4-0b691d1e77aa
< 4.10.7.2
HIGH 8.8 CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists via the "All Post> Ticket… wordfence
8e039295-2ccf-450c-8f2a-d113117b9dce
< 3.6.67
HIGH 8.8 The WP Fluent Forms plugin < 3.6.67 for WordPress is vulnerable to Cross-Site Request Forgery leading to stored Cross-Si… wordfence
8ddeaf57-df82-48f0-b53d-a35a6cd80aca
< 3.7.18
HIGH 8.8 SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attack… wordfence
8ddc4593-bdb4-4b01-be28-4317c76ae6b0
< 1.12.4
HIGH 8.8 The WPS Bidouille plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1… wordfence
8dd3e94d-4397-4f8e-af21-b12e87e0cfb8
< 2.9.4.2
HIGH 8.8 The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to Remote Code Exec… wordfence
8dc548cd-16ea-47ac-b4be-eecaf4799690
< 2.8.7
HIGH 8.8 The Responsive Slider – Image Slider – Slideshow for WordPress plugin for WordPress is vulnerable to blind SQL Injec… wordfence
8dc3cd92-db38-4aa4-8907-9ba7e99380f6
< 1.1.10
HIGH 8.8 The WR ContactForm plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜post’ parameter in versio… wordfence
8da2619f-bc41-4088-9192-902b3c24ec5d
< 1.1.3
HIGH 8.8 The Plugin LBstopattack plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
8d8ffb68-cd85-4ea9-a772-3539728c76e1
< 1.4
HIGH 8.8 The Members Import for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3. This… wordfence
8d5fad17-3b28-4f99-9508-f807cb06cfe5
< 1.4.0
HIGH 8.8 The package json5 before 1.0.2 and between 2.0.0 and 2.2.1 inclusive is vulnerable to prototype pollution due to failure… wordfence
8d189baf-e0d4-4b23-91b8-0c802941b982
< 1.0.3
HIGH 8.8 The Breadcrumbs by menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and includin… wordfence
8cf1b234-862b-41a0-ab63-a986f8023613
< 1.6.8
HIGH 8.8 The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is… wordfence
8cd1b975-ac38-4393-9928-109db507828c
< 1.1.7
HIGH 8.8 The Booking Ultra Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including,… wordfence
8cc178d7-da99-4fbc-9277-52c6299f0417
< 4.1.6
HIGH 8.8 The Church Admin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all… wordfence
8ca2d48b-5fb6-4eb9-85ea-be5a21130039
< 3.5.5
HIGH 8.8 Deepwoods Software WebLibrarian 3.5.4 and earlier is affected by: SQL Injection. The impact is: Exposing the entire data… wordfence
8c9c3302-47cd-4dbe-b79e-5e6032928074
< 1.6.90
HIGH 8.8 The Mesmerize & Materialis themes for WordPress are vulnerable to authenticated options change in versions up to, and in… wordfence
8c93991e-9a71-4600-94a0-8c344ed6bc81
< 1.4.20
HIGH 8.8 The Xpro Addons β€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to missi… wordfence
8c7d208b-84e4-4759-8b61-3ef43c1d0732 HIGH 8.8 Remote Code Execution (RCE) in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPress via Cross-Site R… wordfence
8c78e14b-6925-4630-b19c-13b192f9fea3 HIGH 8.8 The SQL Shortcode plugin for WordPress is vulnerable to SQL Execution in versions up to, and including, 1.1. This is due… wordfence
8c71eb01-116b-4139-9a5e-6b890d7451bd
< 8.6.9.1
HIGH 8.8 The Soledad theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation… wordfence
8c5aa062-b9a2-4ddb-a5bf-4c8368218e85
< 2.8
HIGH 8.8 The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, an… wordfence
8c5a6fcb-72f0-4188-b883-d1dcaf1d13ff
< 1.5.11
HIGH 8.8 The Dynamic Widgets Plugin plugin for WordPress is vulnerable to SQL Injection via several parameters in all versions up… wordfence
8c13701e-424d-462f-b152-4dc5ad3ef197
< 5.8.9
HIGH 8.8 The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and inc… wordfence
8bf009f5-cf9e-4d38-9679-d3abb5817d30
< 2.4.1
HIGH 8.8 The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to Directory Traversal in all versions up to, an… wordfence
8bed0bb4-11d6-4533-a6e1-8e8986dd92d1
< 2.8.9
HIGH 8.8 The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to Remote Code Executio… wordfence
← Prev 152 153 154 155 156 157 158 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top