πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 156 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
8be98cba-b891-42cf-8a6c-8fe05f27c9c3
< 4.3.0
HIGH 8.8 The Divi Torque Lite – Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to Cross-Site Request… wordfence
8bcf22c7-bea5-4108-8fb4-ff9ff566c618
< 3.1.4
HIGH 8.8 The responsive-menu plugin before 3.1.4 for WordPress has no CSRF protection mechanism for the admin interface. wordfence
8bc34490-66a1-4e43-83a4-b6e680237008
< 1.8.13
HIGH 8.8 The Simple SEO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.12… wordfence
8b9e3aaf-5182-4622-9b5b-d67af200e2b6
< 5.3.2
HIGH 8.8 The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` pa… wordfence
8b84cc59-3820-4aba-a2d7-fa884b46c5b4
< 3.1.3
HIGH 8.8 The Custom Content by Country plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and in… wordfence
8b81f965-9ade-477f-98f0-c0742a797298 HIGH 8.8 The Office Locator plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.3.0. T… wordfence
8b7321e8-153c-4586-8114-65583e06573e HIGH 8.8 The HTML5 MP3 Player with Folder Feedburner Playlist Free plugin for WordPress is vulnerable to PHP Object Injection in … wordfence
8b4bc525-a21f-46f2-895a-c8474f72eb92
< 1.6.7
HIGH 8.8 The User Role by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
8b4921c8-8e53-4f9d-be21-cf365869a435 HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the O2Tweet plugin 0.0.4 and earlier for WordPress allow r… wordfence
8b481631-effc-40e8-8be0-18a36ea1c081
< 4.22.0
HIGH 8.8 The Word Balloon plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.21.1… wordfence
8b11a4ce-9e11-4c4b-8c61-3de05750f568
< 1.3.1
HIGH 8.8 The Solace Extra plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the… wordfence
8b0140f2-ceaa-4589-b1ad-1daa244aa3cd
< 1.0.6
HIGH 8.8 The SeoSamba plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.5. T… wordfence
8afcb18c-71e6-4c77-b0f9-0700ee05966e
< 1.3.2
HIGH 8.8 wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests … wordfence
8af26db8-5cae-45ba-9573-2bc4e885de81
< 3.1.2
HIGH 8.8 The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Cross-Site Request… wordfence
8aa02b58-02af-46af-8a20-b94a125b6a12
< 12.40
HIGH 8.8 The DZS Video Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1… wordfence
8a955d4f-6609-4aa8-806c-48af0c6dbac1
< 2.8.2
HIGH 8.8 vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder cod… wordfence
8a7b4d0b-9845-4d0b-b255-a311076f5ca7
< 8.4.3
HIGH 8.8 The NEX-Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.2. … wordfence
8a6f7952-cb64-4cff-aae7-0f03692cd95f
< 3.2.4
HIGH 8.8 The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPre… wordfence
8a613e56-54c0-4bf5-b87f-0e4e507c1337
< 1.08
HIGH 8.8 The FormBuilder plugin for WordPress is vulnerable to blind SQL Injection via the 'fbid' parameter used in various funct… wordfence
8a377ac8-7ef2-4450-9987-4d5c66378023
< 1.5.3
HIGH 8.8 The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-i… wordfence
8a23622a-f217-4e66-b3aa-1a6a701ed925
< 1.10.0
HIGH 8.8 The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion i… wordfence
8a11c169-a232-49a9-80be-40d45d0c6dc0
< 3.6
HIGH 8.8 The Frontend File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati… wordfence
89f6d261-b815-49c6-b4d1-b0f3ff9904d6
< 2.4
HIGH 8.8 The WP SuperBackup plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.3 vi… wordfence
89e3cef3-c1aa-4df7-a9f9-1ca5837643e1
< 4.8
HIGH 8.8 The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t… wordfence
89afc78b-efd5-445e-884f-2345e08df705 HIGH 8.8 The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to p… wordfence
← Prev 153 154 155 156 157 158 159 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top