ðŸ›¡ï¸ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 157 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
89a7a717-dac3-490e-89dd-268be8eb7bf5
< 1.3.0
HIGH 8.8 The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insuffic… wordfence
89a44d42-a110-4f55-ad27-2be4ccb41a16
< 2.9.55.2
HIGH 8.8 The Ninja Forms Contact Form plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.5… wordfence
895f2db1-a2ed-4a17-a4f6-cd13ee8f84af
< 1.4.5
HIGH 8.8 The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin… wordfence
89218de3-7bb9-42f5-86d8-48d28c380231
< 2.0.32
HIGH 8.8 The bBlocks – Essential Gutenberg Blocks & Patterns Collection plugin for WordPress is vulnerable to privilege escalat… wordfence
89183a72-5b35-4c11-81d7-0a735ebce884
< 4.5.5
HIGH 8.8 The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to arbitrary file upl… wordfence
88dc08ff-3966-4606-855c-57c25552599e
< 2.2.0
HIGH 8.8 The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in al… wordfence
88d9f0b1-040d-4f95-95dd-021ceb0cdb39
< 1.4.4
HIGH 8.8 The Login As Users plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the g… wordfence
88d0d6b7-f33f-4c7b-9006-d54578fbe003
< 5.6.9
HIGH 8.8 The Image Map Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and excluding, 5.6… wordfence
88c496df-a5c0-4ac9-8fc1-37fcddfa13d3 HIGH 8.8 The Exclusive Content Password Protect plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t… wordfence
88508dbd-b7a0-441d-918b-f4cb7a7cd000
< 1.33.25
HIGH 8.8 The WordPress Webinar Plugin – WebinarPress plugin for WordPress is vulnerable to modification of data due to a missin… wordfence
8827f882-3c3b-4362-ac90-a1b61364f5c7
< 1.1.4
HIGH 8.8 The Dynamic Product Category Grid, Slider for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in … wordfence
87eaa518-44fb-48ae-b700-ac65141905b3
< 1.63
HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the options admin page in the WP-PostViews plugin before 1.63 for Wor… wordfence
87e3dd5e-0d77-4d78-8171-0beaf9482699
< 6.3
HIGH 8.8 The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o… wordfence
87b7bc4a-4d2f-4bcb-a9d5-72e31c95c09e
< 4.9
HIGH 8.8 The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8… wordfence
87b26fcf-d0b3-4ab3-92d8-8f1ba72af0a3
< 9.1.1
HIGH 8.8 The BuddyPress plugin for WordPress is vulnerable to information disclosure via REST API in versions up to, and includin… wordfence
879c0a85-ed94-430c-8e8e-6389294b432b
< 2.9.2
HIGH 8.8 The peters-login-redirect plugin before 2.9.2 for WordPress has CSRF. wordfence
878f27d3-bb57-46b4-aee4-03720d695504 HIGH 8.8 Wordpress Plugin Store / Mike Rooijackers Recall Products V0.8 fails to sanitize input from the 'Manufacturer[]' paramet… wordfence
8773fa6e-6e81-4565-a9be-36ad0ea6ac88
< 1.8.0.0
HIGH 8.8 The Corona Virus (COVID-19) Banner & Live Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in versi… wordfence
8731565f-4d8a-49e6-9c38-6d4f5e51d68c
< 5.39
HIGH 8.8 The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor… wordfence
871e5091-bb20-4a53-83e2-85ed6f26247a
< 6.4.2.1
HIGH 8.8 The Advanced Page Visit Counter plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 6.… wordfence
8714f5cc-56c7-4976-b021-956883a2bc73
< 1.2.2
HIGH 8.8 The BP Group Documents plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including… wordfence
8706c3f6-64e0-440e-a802-5c80d9cc3643
< 4.8.3
HIGH 8.8 The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8… wordfence
86ff2412-23c6-450e-b351-ba994d68aae6
< 7.4.2.2
HIGH 8.8 The Directorist plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including… wordfence
86ebb886-ad30-44e0-bed1-32d2ffefd50b
< 2.0.9
HIGH 8.8 The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is vulnerable to Remote Cod… wordfence
86dab8e6-b9fd-45ca-bdd1-8665f3bb75f2
< 1.2.1
HIGH 8.8 The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid… wordfence
← Prev 154 155 156 157 158 159 160 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top