πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

39,409
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 13, 2026
Last Updated

39,409 vulnerabilities found (page 158 of 1577)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
86d2aa56-c543-4cb6-aa9f-715879c18f83
< 3.2
HIGH 8.8 The Lead Form Data Collection to CRM plugin for WordPress is vulnerable to unauthorized modification of data that can le… wordfence
86cdbfec-b1af-48ec-ae70-f97768694e44 HIGH 8.8 The WD WidgetTwitter plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, a… wordfence
86b4b0d6-bda2-47f3-a0b5-9733cb7a11f6
< 6.4.0
HIGH 8.8 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin for WordPress is vulnerable t… wordfence
86b2123f-9616-4dcc-904f-c7be802a8f8c
< 3.1.3
HIGH 8.8 wp-includes/taxonomy.php in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors relat… wordfence
8699142d-4ddd-4ca1-9886-9b2d905a36cd
< 5.6.0
HIGH 8.8 The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up… wordfence
86908097-a5b2-427a-85c9-fbe29b519883
< 1.6.5
HIGH 8.8 The Short URL plugin for WordPress is vulnerable to SQL Injection via the 'idLink' parameter of the reset_link() functio… wordfence
86566819-ec2e-4d56-87f6-4cd4b6de6192
< 2.0
HIGH 8.8 The Quasar Theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the rock_build… wordfence
8641aa6d-e865-46cd-91f5-faec81a7bb55 HIGH 8.8 The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in… wordfence
861da9ac-fd73-4bb5-bc39-baf9efe71899
< 3.1.3
HIGH 8.8 The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous… wordfence
85e68071-47e3-45a0-8c38-801f125331ba HIGH 8.8 The Rating by BestWebSoft plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1… wordfence
85d8bfaa-db94-4c15-8f55-eeefe5882f90 HIGH 8.8 The Backup Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, … wordfence
85cea6b5-d57b-495e-a504-a0c1ba691637
< 0.2.5.2
HIGH 8.8 The NewsBlogger theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the new… wordfence
85bd9922-3316-4fd0-b31e-c3ca5ab8a79d
< 1.8.2
HIGH 8.8 The Email Verification for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass due to insufficient v… wordfence
859fe629-701e-4d47-8e90-59860f7c6b82
< 0.9.5
HIGH 8.8 The WP Fastest Cache plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in versions before 0.9.5… wordfence
8593b14e-672d-43b8-b516-d068cbd735b7 HIGH 8.8 Cross-site request forgery (CSRF) vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPr… wordfence
85790564-811c-4087-ad36-345e443ae9f8 HIGH 8.8 Multiple cross-site request forgery (CSRF) vulnerabilities in the Private Only plugin 3.5.1 for WordPress allow remote a… wordfence
85730e9b-c5da-473c-a324-891c5c9f7ba3
< 3.4.12
HIGH 8.8 The WCFM Marketplace plugin for WordPress is vulnerable to unauthorized modification and access of data in versions up t… wordfence
856e3e77-d330-4fa0-9f07-f77a56dbb5bd
< 5.3.9
HIGH 8.8 The XStore Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.3.8. … wordfence
8564fc82-ff23-44b6-91b0-d63e6afb1a73
< 1.1.3
HIGH 8.8 The Icons Font Loader plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to… wordfence
8558cd96-3b2a-4282-950b-6d9753698291
< 1.4.5
HIGH 8.8 The Job Manager & Career – Manage job board listings, and recruitments plugin for WordPress is vulnerable to Cross-Sit… wordfence
8555b662-f1c8-418a-896e-1558e6e34c14
< 2.3.10
HIGH 8.8 The WP Google Map plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature. wordfence
8551ae2f-4be4-4dc6-952d-1d25ae127150
< 2.0.4
HIGH 8.8 The Jeeng Push Notifications plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and inc… wordfence
853516b2-ec50-4937-89d3-d16042a6f71c
< 2.3.3
HIGH 8.8 The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all … wordfence
8530affb-0b6e-4b71-acab-3561cccc1855
< 3.2.2
HIGH 8.8 The Advanced Access Manager plugin for WordPress does not use capability checks on any of its registered AJAX actions. T… wordfence
852959d1-f8e0-4c1f-8a5c-5923bedc4889 HIGH 8.8 The WP AUDIO GALLERY plugin for WordPress is vulnerable to Unauthorized Arbitrary File Read in all versions up to, and i… wordfence
← Prev 155 156 157 158 159 160 161 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top